Phishing is an attempt to obtain private/confidential information such as usernames, passwords, and financial details. It is often for malicious reasons by disguising as a trustworthy entity in an electronic communication such as email. The chances of obtaining confidential or personal information are higher when website medium combined with email medium in launching phishing attacks. Universiti Kebangsaan Malaysia (UKM) has experienced phishing emails attacks in 2016. Besides technology that focuses on email security, the safety awareness program that meant to provide education to the users especially UKM staffs needs to be enhanced to reduce the risk of thievery on personal data, university confidential information and research data. The simulation approach in a real environment can provide a true picture to the staffs about the serious impact of phishing attacks. The objectives of the simulation are to measure and to educate UKM staffs on the security awareness. We designed a spear phishing simulation procedure with collaboration between the Faculty of Information Science and Technology (FTSM), Information Technology Center, Bursary Department and Department of Registrar, UKM. The simulation was conducted from 11–13 January 2017 with 553 email addresses were identified from five different faculties. There were 209 respondents (38%) who have entered their official ids (captured) and password (not captured). The differences in the number of respondents between science and technology (S&T) faculties and non-S&T faculties indicated the security awareness is in the worrying level. A high percentage of responses among the management and professional group can also be classified as being in an alarming rate. This simulation is the first practice in UKM and it helps to increase awareness and provide education about cyber security.
[1]
Abhishek Singhal,et al.
A literature survey on social engineering attacks: Phishing attack
,
2016,
2016 International Conference on Computing, Communication and Automation (ICCCA).
[2]
Lorrie Faith Cranor,et al.
Lessons from a real world evaluation of anti-phishing training
,
2008,
2008 eCrime Researchers Summit.
[3]
Rui Chen,et al.
Research Article Phishing Susceptibility: An Investigation Into the Processing of a Targeted Spear Phishing Email
,
2012,
IEEE Transactions on Professional Communication.
[4]
Markus Jakobsson,et al.
Designing ethical phishing experiments
,
2007,
IEEE Technology and Society Magazine.
[5]
Shari Lawrence Pfleeger,et al.
Going Spear Phishing: Exploring Embedded Training and Awareness
,
2014,
IEEE Security & Privacy.
[6]
Edgar R. Weippl,et al.
Advanced social engineering attacks
,
2015,
J. Inf. Secur. Appl..