Skip to main content

Tej Patel

Page 1

AN INVESTIGATION INTO SMS PHISHING ATTACKS BYPASSING 2FA TO INCREASE CYBERSECURITY AWARENESS AMONG YOUNG PEOPLE • Designed a multi-stage user study to analyse the susceptibility and behavioural changes in young people towards SMS phishing, through the use of interactive teaching methods.

SMSishing Text Sent to Victims

The Attack Demonstration from Victim and Attackers Point of View

Interactive Phishing Detection Games (Using Mentimeter.com)


TOOLKIT USED – EVILGINX2

Evilginx2 acts as a proxy between a browser and the website which is going to be phished.

Hosts its own HTTP and DNS servers – these can be used on a domain hosting website (DigitalOcean)

One click download, emphasising the ease of anyone being able to conduct the attack but does require a bit of technical knowledge, such as commands on the CLI to be known

Provides signed certificates and YAML files for websites to be phished (configuration files)

If there is no valid token, the user is redirected to a spoof site of a YouTube video, which increases the uptime of successful campaigns (useful for my project in trial and error stages!)


FIRST THINGS TO CONSIDER

What type of people to use? – Non-technical ((i.e. not studying a computer science based course / work in a technology based field) / (Cain et al, 2018) researched that 18-24 year olds had the poorest cyber hygiene! Quantitative or Qualitative Data Collection – Quantitative so can use a pre-validated questionnaire from research paper “Developing a measure of Information Seeking about Phishing” Williams & Joinson, 2020). Allows reliability of testing, allows SPSS to be used to analyse results, allows comparison of results compared to original findings. How many people to use in the study – Based on existing literature (Okul et al., 2018) that suggests 30 people is sufficient for a quantitative study What toolkit to use? – Something opensource to demonstrate the motivations of an attacker so something that had a lot of existing literature / readily available guides – EvilGinx2 (Kuba Gretzy)


MOTIVATION In April 2022, cyber criminals targeted Microsoft 365 / Outlook through using static web applications to phish people.

Sent a realistic SMS link to victims -> Prompted SingleSignOn (SSO) logon -> Redirects to static landing page identical to Microsoft 365

I incorporated this idea exactly into my session, through allowing one person in the session to be phished live. Therefore, my motivation was based on the April 2022 story, as well as the rise of SMSishing attacks over covid specifically the royal mail attack and how it was just a university student from his bedroom, and finally the number of universities including Northumbria that were attacked potentially due to the lack of cyber hygiene in young people.


DATA COLLECTION AND ANALYSIS SMS DETECTION GAME • Designed by me (and not existing literature) and my own personal experience messages collected over COVID-19 as it would be interesting to use real life examples to see how people responded, lack of messages online too (could have hindered validity in respect to age-group of study through being off topic).

• Tried to match the couriers and message content in both games as close as possible to meet T-Test assumptions

• Incorporated Challenged Based Learning (Cheung & Lo, 2011) and Games Based Training (Jin et al., 2018) - Based on existing literature to see what methods motivate young people to learn in an interesting way and retain information in respect to security awareness.

• Promotion of healthy competition – Measured using Menti (similar to Kahoot but allowed a leadership board. 5 slides of games to be played for free, captured time of answers in seconds)


DATA COLLECTION AND ANALYSIS PHISHING INFORMATION SEEKING QUESTIONNAIRE • Allows a self-reported measure to be collected towards phishing information seeking using a pre-validated questionnaire (Emma Williams / Adam Joinson).

• Based on protection motivation theory (PMT) which is used to examine the impact of attitudes and behavioural changes through having several different variables such as response costs, perceived self-efficacy etc, after inducing fear (achieved through having a SMS detection game and attack demonstration before conducting medium/long term questionnaire).


FINDINGS • There was a behavioural change with the phishing detection games through increased time to respond but decreased accuracy. This suggests behaviour of young people has changed through introducing diligence and removing spontaneous behaviour when acting online due to lack of knowledge ((Handeli et al., 2018). Suggested hesitancy was introduced – not a bad thing!

• The MANOVA results were sustained or increased over the durations, suggesting attention spans were retained and interactive teaching methods were successful.

• Compared to original research findings – hours spent online were the same (6 hours), identical results in increase of PA, SE, RE and decrease in PV and RC. But fluctuation in my findings between medium and long term, which is something Emma did not do.

PERSONAL KEY FINDINGS • How easy it is for a hacker to be traced back but this isn’t public news!


LIMITATIONS SPSS was a bit tricky to use! Drop-outs weren’t accounted for which was risky – future work Website domain I purchased on GoDaddy was blocked for 48 hours pending investigation (purchased outlook-office.co.uk – real outlook.office.co.uk) Couldn’t prevent order effects of the phishing detection games through randomising the order of both games. Also, small number of games.


Turn static files into dynamic content formats.

Create a flipbook
Tej Patel by Northumbria University - Issuu