Talk With an Expert

Phishing Detecton and Remediation

Phishing Detecton and Remediation (PDF, 2.22MB)Published: 21 Jan, 2013
Created by
Rich Graves

This paper surveys common techniques for battling phishing attacks, especially those targeting Internet-accessible webmail servers, and introduces some lesser known countermeasures. We discuss automating the retroactive eradication of phishing messages from user mailboxes, image referrer analysis, phishing your own users as an awareness- raising exercise, and the identification of compromised webmail accounts by monitoring user behavior. Examples focus on open source software, including SpamAssassin and Zimbra, as implemented at colleges and universities. Some lessons may be applicable to proprietary technologies and non-webmail situations, such as financial site and enterprise spear phishing.

Phishing Detecton and Remediation