The NCSC research problem book
Pages
Page 6 of 21
CC4 - How do we make phishing a thing of the past?
How do we make phishing a thing of the past?
For years cyber security practitioners have been asking users to try and spot phishing emails and to not ‘click the link’ or open an attachment. But we know that with enough research, or a big enough sample size, an attacker will always succeed in tricking the user. This is not the user’s fault – we shouldn't expect a user to be able to detect a suspicious message when a computer can’t. We need to reduce the burden on users and make computers do the heavy lifting.
Strands or sub-problems
-
Keep phishing away from users
Although open messaging systems like email and SMS support innovation, interoperability and competition, they’re also open to abuse. Developing new mitigations for open systems would result in fewer malicious messages reaching users. This could include reputation-scoring different properties in messages, and mechanisms to transfer intelligence between service providers. What other techniques can we develop to automatically detect malicious messages, so the user doesn’t have to?
-
Mitigating successful phishing
Adopting technologies and standards like FIDO2 which enable authentication without using passwords should reduce phishing to steal credentials, but take-up of these new technologies is slow, so how can we accelerate and broaden this? For other types of phishing (to collect payment or financial details, for example), what equivalent approaches could be adopted? And more broadly, how can we make web browsers better at spotting when legitimate brands are impersonated, so we can better protect users?
-
User experience design
This strand relates to research in user interface design to understand which designs help users make better security decisions when they are about to take a significant risk. Is there scope for standardisation in this space to support users working across different applications, services or devices?
-
Security architecture
This is about developing infrastructure and application security patterns that assume users will be tricked, to limit the further impact of a breach. What are the effective mechanisms to do this and the operational impacts? What architectural patterns should organisations adopt to confidently mitigate the risk?
-
Mitigating misuse of technology advances
It's important that we understand the next generation of phishing attacks and that our current mitigation methodologies still apply. For example, how do we automatically detect AI-generated phishing emails or the use of ‘deep fakes’ in social engineering attacks? How do we develop new methodologies where current ones fail?
Why this is important
“Although phishing has been around for a long time, it's still one of the primary vectors used by threat actors of all capability levels. Users are either tricked into disclosing sensitive information, clicking a link, or opening an attachment, which then results in their device being exploited, and gives the attacker a foothold to build from. Even the savviest users can be duped by well-crafted phishing emails, which is why we need much more work to address this problem and make phishing a thing of the past.”
Harry W, NCSC Technical Director for Incident Management