From Victims to Defenders: An Exploration of the Phishing Attack Reporting Ecosystem

Zhibo Sun, Faris Bugra Kokulu, Penghui Zhang, Adam Oest, Gianluca Stringhini, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doupé, Gail Joon Ahn

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Reporting phishing attacks can significantly shorten the time required to take down their operations and deter further victimization by the same phishing websites. However, little research has been conducted to understand the phishing reporting ecosystem and its effectiveness. In this paper, we comprehensively evaluate the phishing reporting ecosystem to identify the critical challenges people face and their concerns when reporting smishing, vishing, and phishing email attacks. First, we analyze the existing security advice and channels for reporting phishing attacks in both the public and private sectors. Then, we conduct a scenario-based experiment involving 89 participants to investigate what factors affect a participant’s decision to report a phishing attack and what challenges they face in preparing the report. Third, we report phishing attacks ourselves and monitor the status of the reported phishing websites to empirically measure how reports are acted upon and how that affects the reported phishing websites. Finally, we propose approaches under five major concern categories to mitigate the challenges that we discover in the phishing reporting ecosystem.

Original languageEnglish (US)
Title of host publicationProceedings of 27th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2024
PublisherAssociation for Computing Machinery
Pages49-64
Number of pages16
ISBN (Electronic)9798400709593
DOIs
StatePublished - Sep 30 2024
Event27th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2024 - Padua, Italy
Duration: Sep 30 2024Oct 2 2024

Publication series

NameACM International Conference Proceeding Series

Conference

Conference27th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2024
Country/TerritoryItaly
CityPadua
Period9/30/2410/2/24

Keywords

  • Anti-phishing Strategies
  • Phishing Attack Reporting
  • Phishing Reporting Challenges
  • Smishing
  • Vishing

ASJC Scopus subject areas

  • Human-Computer Interaction
  • Computer Networks and Communications
  • Computer Vision and Pattern Recognition
  • Software

Fingerprint

Dive into the research topics of 'From Victims to Defenders: An Exploration of the Phishing Attack Reporting Ecosystem'. Together they form a unique fingerprint.

Cite this