Grants and Contributions:

Title:
Identity and behavior - based secure personalized message classification systems: Market Assessment
Agreement Number:
I2IPJ
Agreement Value:
$15,000.00
Agreement Date:
Mar 7, 2018 -
Organization:
Natural Sciences and Engineering Research Council of Canada
Location:
British Columbia, CA
Reference Number:
GC-2017-Q4-01789
Agreement Type:
Grant
Report Type:
Grants and Contributions
Additional Information:

Grant or Award spanning more than one fiscal year (2017-2018 to 2018-2019).

Recipient's Legal Name:
Traore, Issa (University of Victoria)
Program:
Idea to Innovation
Program Purpose:

Phishing is still currently one of the most impactful forms of attacks delivered through electronic messages (i.e. emails, short messages, tweets). Targeted spearheaded phishing poses even more challenges as it relies on intimate knowledge of the victim gathered from online data dumps (e.g. in the dark web) or by hijacking online accounts. Recent high-profile hacking incidents have shown the limits of traditional anti-phishing solutions, such as spam filters and anti-virus systems. Those methods are heavily focused on analyzing the "message" and not the "messenger". As such it is easy to evade them by crafting the "message" to fit expected messaging standard (e.g. by removing spam idiosyncrasies and keywords, proof-reading the message, and using familiar terms and names). We have developed a new approach to protect against targeted spearheaded phishing attacks based on verifying the genuineness of the messenger's identity, and checking whether key message characteristics match the messaging behavior of the claimed messenger identity with respect to the recipient. The genuineness of the messenger's identity is established through stylometric authorship verification, which is known to be very challenging when dealing with short unstructured text. Messaging behavior is based on message origin location patterns (i.e. typical locations from where genuine messages were sent by this messenger), file attachment pattern (i.e. likelihood for the messenger to attach files of certain characteristics), and embedded URLs pattern (i.e. likelihood for the messenger to embed URLs, and validity of such URLs). The proposed model is used to verify both incoming and outgoing messages. Checking outgoing messages allows determining whether a legitimate account has been hijacked and is being leveraged to send out phishing messages to victims known by the account owner. Checking incoming messages protects against phishing attacks by establishing whether the sender is genuine and known by the recipient. The goal of the project is to conduct a market study for the proposed technology. The focus of the market study will be to assess the market potential of the technology in anticipation of transferring it to existing cybersecurity companies.x000D
x000D