错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Novel Framework to Detect Business Email Compromise Through Unconsented Email Autoforwards

  • Priti Kulkarni,
  • Jatinderkumar R. Saini

摘要

Contemporary business heavily relies on email communication as the official communication in the business. However, this pivotal communication medium has become a prime target by the attackers to find a way to enter into the organisation's network. Phishing is an email-based attack where an attacker sends a fraudulent email in such a way that it looks like the original email. This phishing email aims to get the victim's credentials. The attacks are known as Business Email Compromise (BEC). The most common BEC scams are ‘CEO fraud’ and ‘man-in-middle’ scams. The BEC attacks are fast growing attacks and it is necessary to control it. There are numerous papers addressing BEC attacks. The BEC attackers are using new approaches to mail scams. One of the techniques used by attackers is to set email auto forward rules to redirect emails to malicious email account. It is required to continuously monitor the email auto forward rules. But the traditional approach of manual control is difficult and attacks may go undetected. So, in this paper we are presenting an approach of automatic control by presenting a novel theoretical Email Auto forward Security Framework (EASF). The paper attempts to address an email auto forward, a new technique used by attackers for BEC which is the most dangerous threat. The EASF presents an automated approach to counter the increasing threat of BEC. The implementation of this framework will help the business to detect and mitigate BEC attacks through email auto forward, thus ensuring security and integrity of the communication. The paper also discusses the precautions and challenges for BEC.