A recent review of conventional vs. automated cybersecurity anti-phishing techniques

dc.cclicenceCC-BY-NC-NDen
dc.contributor.authorQabajeh, Issaen
dc.contributor.authorThabtah, Fadien
dc.contributor.authorChiclana, Franciscoen
dc.date.acceptance2018-05-28en
dc.date.accessioned2018-06-26T11:51:02Z
dc.date.available2018-06-26T11:51:02Z
dc.date.issued2018-06-28
dc.descriptionThe file attached to this record is the author's final peer reviewed version. The Publisher's final version can be found by following the DOI link.en
dc.description.abstract"In the era of electronic and mobile commerce, massive numbers of financial transactions are conducted online on daily basis, which created potential fraudulent opportunities. A common fraudulent activity that involves creating a replica of a trustful website to deceive users and illegally obtain their credentials is website phishing. Website phishing is a serious online fraud, costing banks, online users, governments, and other organisations severe financial damages. One conventional approach to combat phishing is to raise awareness and educate novice users on the different tactics utilised by phishers by conducting periodic training or workshops. However, this approach has been criticised of being not cost effective as phishing tactics are constantly changing besides it may require high operational cost. Another anti- phishing approach is to legislate or amend existing cyber security laws that persecute online fraudsters without minimising its severity. A more promising anti-phishing approach is to prevent phishing attacks using intelligent machine learning (ML) technology. Using this technology, a classification system is integrated in the browser in which it will detect phishing activities and communicate these with the end user. This paper reviews and critically analyses legal, training, educational and intelligent anti-phishing approaches. More importantly, ways to combat phishing by intelligent and conventional are highlighted, besides revealing these approaches differences, similarities and positive and negative aspects from the user and performance prospective. Different stakeholders such as computer security experts, researchers in web security as well as business owners may likely benefit from this review on website phishing."en
dc.funderN/Aen
dc.identifier.citationQabajeh, I., Thabtah, F., Chiclana, F. (2018) A recent review of conventional vs. automated cybersecurity anti-phishing techniques. Computer Science Review, 29, pp. 44–55.en
dc.identifier.doihttps://doi.org/10.1016/j.cosrev.2018.05.003
dc.identifier.issn1574-0137
dc.identifier.urihttp://hdl.handle.net/2086/16295
dc.language.isoenen
dc.peerreviewedYesen
dc.projectidN/Aen
dc.publisherElsevieren
dc.researchgroupCentre for Computational Intelligenceen
dc.researchinstituteInstitute of Artificial Intelligence (IAI)en
dc.subjectClassificationen
dc.subjectComputer securityen
dc.subjectPhishingen
dc.subjectMachine learningen
dc.subjectWeb securityen
dc.subjectSecurity awarenessen
dc.titleA recent review of conventional vs. automated cybersecurity anti-phishing techniquesen
dc.typeArticleen

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Computer-Science-Review-2018.pdf
Size:
844.25 KB
Format:
Adobe Portable Document Format
Description:
Author's copy of accepted paper.
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
4.2 KB
Format:
Item-specific license agreed upon to submission
Description: