Commercial Anti-Smishing Tools and Their Comparative Effectiveness Against Modern Threats

09/14/2023
by   Daniel Timko, et al.
0

Smishing, also known as SMS phishing, is a type of fraudulent communication in which an attacker disguises SMS communications to deceive a target into providing their sensitive data. Smishing attacks use a variety of tactics; however, they have a similar goal of stealing money or personally identifying information (PII) from a victim. In response to these attacks, a wide variety of anti-smishing tools have been developed to block or filter these communications. Despite this, the number of phishing attacks continue to rise. In this paper, we developed a test bed for measuring the effectiveness of popular anti-smishing tools against fresh smishing attacks. To collect fresh smishing data, we introduce Smishtank.com, a collaborative online resource for reporting and collecting smishing data sets. The SMS messages were validated by a security expert and an in-depth qualitative analysis was performed on the collected messages to provide further insights. To compare tool effectiveness, we experimented with 20 smishing and benign messages across 3 key segments of the SMS messaging delivery ecosystem. Our results revealed significant room for improvement in all 3 areas against our smishing set. Most anti-phishing apps and bulk messaging services didn't filter smishing messages beyond the carrier blocking. The 2 apps that blocked the most smish also blocked 85-100% of benign messages. Finally, while carriers did not block any benign messages, they were only able to reach a 25-35% blocking rate for smishing messages. Our work provides insights into the performance of anti-smishing tools and the roles they play in the message blocking process. This paper would enable the research community and industry to be better informed on the current state of anti-smishing technology on the SMS platform.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/04/2022

Clues in Tweets: Twitter-Guided Discovery and Analysis of SMS Spam

With its critical role in business and service delivery through mobile d...
research
06/28/2021

Doing good by fighting fraud: Ethical anti-fraud systems for mobile payments

App builders commonly use security challenges, a form of step-up authent...
research
01/10/2023

Hate Raids on Twitch: Echoes of the Past, New Modalities, and Implications for Platform Governance

In the summer of 2021, users on the livestreaming platform Twitch were t...
research
01/13/2020

DeepQuarantine for Suspicious Mail

In this paper, we introduce DeepQuarantine (DQ), a cloud technology to d...
research
05/29/2019

Anti-efficient encoding in emergent communication

Despite renewed interest in emergent language simulations with neural ne...
research
07/01/2020

Understanding phishers' strategies of mimicking uniform resource locators to leverage phishing attacks: A machine learning approach

Phishing is a type of social engineering attack with an intention to ste...
research
04/02/2020

Typosquatting for Fun and Profit: Cross-Country Analysis of Pop-Up Scam

Today, many different types of scams can be found on the internet. Onlin...

Please sign up or login with your details

Forgot password? Click here to reset