Business Email Compromise Phishing Detection Based on Machine Learning: A Systematic Literature Review
Journal article
Authors | Atlam, H. and Olayonu Oluwatimilehin |
---|---|
Abstract | The risk of cyberattacks against businesses has risen considerably, with Business Email Compromise (BEC) schemes taking the lead as one of the most common phishing attack methods. The daily evolution of this assault mechanism’s attack methods has shown a very high level of proficiency against organisations. Since the majority of BEC emails lack a payloader, they have become challenging for organisations to identify or detect using typical spam filtering and static feature extraction techniques. Hence, an efficient and effective BEC phishing detection approach is required to provide an effective solution to various organisations to protect against such attacks. This paper provides a systematic review and examination of the state of the art of BEC phishing detection techniques to provide a detailed understanding of the topic to allow researchers to identify the main principles of BEC phishing detection, the common Machine Learning (ML) algorithms used, the features used to detect BEC phishing, and the common datasets used. Based on the selected search strategy, 38 articles (of 950 articles) were chosen for closer examination. Out of these articles, the contributions of the selected articles were discussed and summarised to highlight their contributions as well as their limitations. In addition, the features of BEC phishing used for detection were provided, as well as the ML algorithms and datasets that were used in BEC phishing detection models were discussed. In the end, open issues and future research directions of BEC phishing detection based on ML were discussed |
Keywords | business email compromise (BEC); email phishing; phishing detection |
Year | 2022 |
Journal | Electronics |
Journal citation | 12 (1), pp. 1-28 |
Publisher | MDPI |
ISSN | 2079-9292 |
Digital Object Identifier (DOI) | https://doi.org/10.3390/electronics12010042 |
Web address (URL) | https://doi.org/10.3390/electronics12010042 |
Output status | Published |
Publication dates | 22 Dec 2022 |
Publication process dates | |
Accepted | 19 Dec 2022 |
Deposited | 10 Feb 2023 |
https://repository.derby.ac.uk/item/9wxy2/business-email-compromise-phishing-detection-based-on-machine-learning-a-systematic-literature-review
110
total views0
total downloads2
views this month0
downloads this month