High Precision Detection of Business Email Compromise

被引:0
|
作者
Cidon, Asaf [1 ,2 ]
Gavish, Lior
Bleier, Itay
Korshun, Nadia
Schweighauser, Marco
Tsitkin, Alexey [1 ]
机构
[1] Barracuda Networks, Campbell, CA 95008 USA
[2] Columbia Univ, New York, NY 10027 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Business email compromise (BEC) and employee impersonation have become one of the most costly cyber-security threats, causing over $12 billion in reported losses. Impersonation emails take several forms: for example, some ask for a wire transfer to the attacker's account, while others lead the recipient to following a link, which compromises their credentials. Email security systems are not effective in detecting these attacks, because the attacks do not contain a clearly malicious payload, and are personalized to the recipient. We present BEC-Guard, a detector used at Barracuda Networks that prevents business email compromise attacks in real-time using supervised learning. BEC-Guard has been in production since July 2017, and is part of the Barracuda Sentinel email security product. BEC-Guard detects attacks by relying on statistics about the historical email patterns that can be accessed via cloud email provider APIs. The two main challenges when designing BEC-Guard are the need to label millions of emails to train its classifiers, and to properly train the classifiers when the occurrence of employee impersonation emails is very rare, which can bias the classification. Our key insight is to split the classification problem into two parts, one analyzing the header of the email, and the second applying natural language processing to detect phrases associated with BEC or suspicious links in the email body. BEC-Guard utilizes the public APIs of cloud email providers both to automatically learn the historical communication patterns of each organization, and to quarantine emails in real-time. We evaluated BEC-Guard on a commercial dataset containing more than 4,000 attacks, and show it achieves a precision of 98.2% and a false positive rate of less than one in five million emails.
引用
收藏
页码:1291 / 1307
页数:17
相关论文
共 50 条
  • [41] EMAIL SUBJECT LINES ANALYSIS FOR HIGH OPEN RATE IN EMAIL MARKETING
    Teiu, Codrin
    2020 BASIQ INTERNATIONAL CONFERENCE: NEW TRENDS IN SUSTAINABLE BUSINESS AND CONSUMPTION, 2020, : 835 - 840
  • [42] A hybrid approach to extract business process models with high fitness and precision
    Cheng, Hsin-Jung
    Chao Ou-Yang
    Juan, Yeh-Chun
    JOURNAL OF INDUSTRIAL AND PRODUCTION ENGINEERING, 2015, 32 (06) : 351 - 359
  • [43] Multi-Task Romanian Email Classification in a Business Context
    Dima, Alexandru
    Ruseti, Stefan
    Iorga, Denis
    Banica, Cosmin Karl
    Dascalu, Mihai
    INFORMATION, 2023, 14 (06)
  • [44] Enabling Email-Based Conversational Interface to Business Applications
    Bhat, Shefali
    Anantaram, C.
    Jain, Hemant
    IMETI 2008: INTERNATIONAL MULTI-CONFERENCE ON ENGINEERING AND TECHNOLOGICAL INNOVATION, VOL I, PROCEEDINGS, 2008, : 168 - 173
  • [45] Identifying business tasks and commitments from email and chat conversations
    Kalia, Anup
    Nezhad, Hamid Reza Motahari
    Bartolini, Claudio
    Singh, Munindar
    HP Laboratories Technical Report, 2013, (04):
  • [46] STRIPPING VOLTAMMETRIC DETECTION IN HIGH-PRECISION TITRIMETRY
    GRUNDLER, P
    ANALYTICA CHIMICA ACTA, 1988, 206 (1-2) : 153 - 160
  • [47] High Precision Edge Detection Algorithm for Mechanical Parts
    Duan, Zhenyun
    Wang, Ning
    Fu, Jingshun
    Zhao, Wenhui
    Duan, Boqiang
    Zhao, Jungui
    MEASUREMENT SCIENCE REVIEW, 2018, 18 (02): : 65 - 71
  • [48] PET/CT for movement detection in high precision radiotherapy
    Ernst, I.
    Buether, F.
    Dawood, M.
    Kraxner, P.
    Moustakis, C.
    Boelling, T.
    Schober, O.
    Schaefers, K.
    Willich, N.
    STRAHLENTHERAPIE UND ONKOLOGIE, 2009, 185 : 35 - 36
  • [49] A High-precision Detection Circuit for Capacitive Sensor
    Ge, Jun
    Ying, Zhihua
    Pan, Ying
    Qin, HuiBin
    Zheng, Liang
    2015 IEEE 16TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY (ICCT), 2015, : 158 - 161
  • [50] High precision detection system for automotive paint defects
    Lu Y.-K.
    Yuan S.-K.
    Xiong S.-S.
    Zhu S.-P.
    Zhang N.
    Jilin Daxue Xuebao (Gongxueban)/Journal of Jilin University (Engineering and Technology Edition), 2024, 54 (05): : 1205 - 1213