{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T10:04:28Z","timestamp":1767261868351},"reference-count":64,"publisher":"Elsevier","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2007]]},"DOI":"10.1016\/s0065-2458(06)70005-5","type":"book-chapter","created":{"date-parts":[[2011,1,19]],"date-time":"2011-01-19T05:56:21Z","timestamp":1295416581000},"page":"223-268","source":"Crossref","is-referenced-by-count":9,"title":["Phish Phactors: Offensive and Defensive Strategies"],"prefix":"10.1016","author":[{"given":"Hal","family":"Berghel","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"James","family":"Carpinter","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ju-Yeon","family":"Jo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/S0065-2458(06)70005-5_bib001","unstructured":"Anti-Phishing Working Group, \u201cProposed solutions to address the threat of email spoofing scams\u201d, 2003"},{"key":"10.1016\/S0065-2458(06)70005-5_bib002","unstructured":"Anti-Phishing Working Group, \u201cOrigins of the Word \u201cPhishing\u201d\u2009\", 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib003","unstructured":"Anti-Phishing Working Group, \u201cPhishing activity trends report\u201d, May 2006"},{"key":"10.1016\/S0065-2458(06)70005-5_bib004","unstructured":"Anti-Phishing Working Group, \u201cPhishing archive\u201d, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib005","author":"Anti-Phishing Working Group"},{"issue":"12","key":"10.1016\/S0065-2458(06)70005-5_bib006","doi-asserted-by":"crossref","first-page":"144","DOI":"10.1145\/1035134.1035159","article-title":"Spamming, phishing, authentication, and privacy","volume":"47","author":"Bellovin","year":"2004","journal-title":"Commun. ACM"},{"issue":"4","key":"10.1016\/S0065-2458(06)70005-5_bib007","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1145\/1121949.1121968","article-title":"Phishing mongers and posers","volume":"48","author":"Berghel","year":"2006","journal-title":"Commun. ACM"},{"issue":"4","key":"10.1016\/S0065-2458(06)70005-5_bib008","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1145\/975817.975836","article-title":"Wading into alternate data streams","volume":"47","author":"Berghel","year":"2004","journal-title":"Commun. ACM"},{"issue":"2","key":"10.1016\/S0065-2458(06)70005-5_bib009","doi-asserted-by":"crossref","first-page":"9","DOI":"10.1145\/1042091.1042101","article-title":"News track","volume":"48","author":"CACM Staff","year":"2005","journal-title":"Commun. ACM"},{"key":"10.1016\/S0065-2458(06)70005-5_bib010","unstructured":"Chandrasekaran M., et al., \u201cPHONEY: Mimicking user response to detect phishing attacks\u201d, in: Proc. 2006 Int. Symposium of World of Wireless, Mobile and Multimedia"},{"key":"10.1016\/S0065-2458(06)70005-5_bib011","unstructured":"Chou N., Ledesma R., Teraguchi Y., Mitchell J.C., \u201cClient-side defense against web-based identity theft\u201d, in: 11th Annual Network and Distributed System Security Symposium, 2004"},{"key":"10.1016\/S0065-2458(06)70005-5_bib012","author":"CipherTrust"},{"key":"10.1016\/S0065-2458(06)70005-5_bib013","unstructured":"Clayton R., \u201cInsecure real-world authentication protocols (or why phishing is so profitable)\u201d, in: Thirteenth Cambridge Protocols Workshop, Sidney, Sussex, UK, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib014","author":"Cloudmark"},{"key":"10.1016\/S0065-2458(06)70005-5_bib015","unstructured":"Deepnet Explorer Browser, http:\/\/www.deepnetexplorer.com"},{"key":"10.1016\/S0065-2458(06)70005-5_bib016","unstructured":"Dhamija R., \u201cDetecting phishing attacks: A user task analysis\u201d, in: Authentication for Humans: Designing and Evaluating Usable Security Systems, PhD dissertation, School of Management Information Systems, UC Berkeley, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib017","doi-asserted-by":"crossref","unstructured":"Dhamija R., Tygar J.D., \u201cThe battle against phishing: Dynamic security skins\u201d, in: ACM Symposium on Usable Security and Privacy, 2005","DOI":"10.1145\/1073001.1073009"},{"key":"10.1016\/S0065-2458(06)70005-5_bib018","doi-asserted-by":"crossref","unstructured":"Dhamija R., Tygar J.D., Hearst M., \u201cWhy phishing works\u201d, in: CHI 2006, April 22\u201327, 2006","DOI":"10.1145\/1124772.1124861"},{"key":"10.1016\/S0065-2458(06)70005-5_bib019","doi-asserted-by":"crossref","unstructured":"Downs J., Holbrook M., Cranor L.F., \u201cDecision strategies and susceptibility to phishing\u201d, in: Symposium on Usable Privacy and Security (SOUPS), July 12\u201314, 2006, pp. 79\u201390","DOI":"10.1145\/1143120.1143131"},{"key":"10.1016\/S0065-2458(06)70005-5_bib020","unstructured":"Drake C.E., Oliver J.J., Koontz E.J., \u201cAnatomy of a phishing email\u201d, in: Conference on Email and Anti-Spam, Mountain View, CA, USA, 2004"},{"key":"10.1016\/S0065-2458(06)70005-5_bib021","author":"eBay Toolbar and Account Guard"},{"key":"10.1016\/S0065-2458(06)70005-5_bib022","unstructured":"Federal Trade Commission, \u201cHow not to get hooked by a \u2018phishing\u2019 scam\u201d, 2005"},{"issue":"4","key":"10.1016\/S0065-2458(06)70005-5_bib023","first-page":"315","article-title":"Computer forensics: a critical need in computer science programs","volume":"20","author":"Fernandez","year":"2005","journal-title":"J. Comput. Small Coll."},{"key":"10.1016\/S0065-2458(06)70005-5_bib024","series-title":"Proceedings of the 2004 workshop on New security paradigms","first-page":"97","article-title":"Omnivore: Risk management through bidirectional transparency","author":"Flinn","year":"2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib025","doi-asserted-by":"crossref","unstructured":"Friedman B., et al., \u201cUsers' conceptions of web security: A comparative study\u201d, in: ACM CHI: Conference on Human Factors in Computer Systems, 2002","DOI":"10.1145\/506558.506577"},{"key":"10.1016\/S0065-2458(06)70005-5_bib026","doi-asserted-by":"crossref","unstructured":"Fu A., et al., \u201cThe methodology and an application to fight against Unicode attacks\u201d, in: Proc. SOUPS, 2006","DOI":"10.1145\/1143120.1143132"},{"issue":"6","key":"10.1016\/S0065-2458(06)70005-5_bib027","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/MC.2005.201","article-title":"Security technologies go phishing","volume":"38","author":"Geer","year":"2005","journal-title":"Computer"},{"key":"10.1016\/S0065-2458(06)70005-5_bib028","doi-asserted-by":"crossref","unstructured":"Good N., et al., \u201cStopping spyware at the gate: A user study of privacy, notice and spyware\u201d, in: Symposium on Usable Security and Privacy, 2005","DOI":"10.1145\/1073001.1073006"},{"issue":"1","key":"10.1016\/S0065-2458(06)70005-5_bib029","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1109\/MSP.2005.21","article-title":"Phishing attacks rising, but dollar losses down","volume":"3","author":"Goth","year":"2005","journal-title":"Security & Privacy Magazine, IEEE"},{"key":"10.1016\/S0065-2458(06)70005-5_bib030","author":"Grant Gross"},{"key":"10.1016\/S0065-2458(06)70005-5_bib031","series-title":"Proceedings of the 14th International Conference on World Wide Web","first-page":"471","article-title":"A convenient method for securely managing passwords","author":"Halderman","year":"2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib032","author":"Haskins"},{"key":"10.1016\/S0065-2458(06)70005-5_bib033","author":"Herzberg"},{"key":"10.1016\/S0065-2458(06)70005-5_bib034","series-title":"Know Your Enemy: Phishing","author":"The Honeynet Project & Research Alliance","year":"2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib035","unstructured":"Inomata A., Rahman S., Okamoto T., Okamoto E., \u201cA novel mail filtering method against phishing\u201d, in: PACRIM, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib036","unstructured":"Internet Security Systems, \u201cProtect your business from phishing\u201d, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib037","doi-asserted-by":"crossref","unstructured":"Jakobsson M., \u201cModeling and preventing phishing attacks\u201d, in: Financial Cryptography '05, 2005","DOI":"10.1007\/11507840_9"},{"key":"10.1016\/S0065-2458(06)70005-5_bib038","unstructured":"Keizer G., \u201cPhishing costs nearly $1 billion\u201d, InformationWeek, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib039","unstructured":"Kerstein P., \u201cHow can we stop phishing and pharming scams?\u201d, in: CSO, July 19, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib040","unstructured":"Kirda E., Kruegel C., \u201cProtecting users against phishing attacks with antiphishing\u201d, in: COMPSAC, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib041","author":"Kuchinskas"},{"issue":"2","key":"10.1016\/S0065-2458(06)70005-5_bib042","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1109\/MSECP.2004.1281250","article-title":"Criminals become tech savvy","volume":"2","author":"Levy","year":"2004","journal-title":"Security & Privacy Magazine, IEEE"},{"issue":"6","key":"10.1016\/S0065-2458(06)70005-5_bib043","doi-asserted-by":"crossref","first-page":"66","DOI":"10.1109\/MSP.2004.104","article-title":"Interface illusions","volume":"2","author":"Levy","year":"2004","journal-title":"Security & Privacy Magazine, IEEE"},{"key":"10.1016\/S0065-2458(06)70005-5_bib044","unstructured":"Merwe A.v.d., Looc M., Dabrowski M., \u201cCharacteristics and responsibilities involved in a Phishing attack\u201d, in: Proc. of the 4th International Symposium on Information and Communication Technologies, Trinity College Dublin, Cape Town, South Africa, 2005, pp. 249\u2013254"},{"key":"10.1016\/S0065-2458(06)70005-5_bib045","unstructured":"Netcraft Toolbar, http:\/\/toolbar.netcraft.com"},{"key":"10.1016\/S0065-2458(06)70005-5_bib046","unstructured":"Ollmann G., \u201cThe phishing guide\u201d, NGS Software Insight Security Research, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib047","author":"Roberts"},{"key":"10.1016\/S0065-2458(06)70005-5_bib048","doi-asserted-by":"crossref","unstructured":"Robia S., Ragucci J., \u201cDon't be a phish: Steps in user education\u201d, in: ITiCSE '06, June 26\u201328, 2006","DOI":"10.1145\/1140124.1140187"},{"key":"10.1016\/S0065-2458(06)70005-5_bib049","series-title":"An Analysis of Phishing and Possible Mitigation Strategies","author":"Rudd","year":"2004"},{"issue":"4","key":"10.1016\/S0065-2458(06)70005-5_bib050","doi-asserted-by":"crossref","first-page":"136","DOI":"10.1145\/1053291.1053327","article-title":"Two-factor authentication: Too little, too late","volume":"48","author":"Schneier","year":"2005","journal-title":"Commun. ACM"},{"issue":"4","key":"10.1016\/S0065-2458(06)70005-5_bib051","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1109\/MSP.2005.109","article-title":"The TIPPI point: Toward trustworthy interfaces","volume":"3","author":"Sinclair","year":"2005","journal-title":"Security & Privacy Magazine, IEEE"},{"key":"10.1016\/S0065-2458(06)70005-5_bib052","unstructured":"Spoofstick, http:\/\/www.spoofstick.com"},{"issue":"3","key":"10.1016\/S0065-2458(06)70005-5_bib053","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1145\/1016961.1016971","article-title":"The state of security on the internet","volume":"8","author":"Treese","year":"2004","journal-title":"netWorker"},{"key":"10.1016\/S0065-2458(06)70005-5_bib054","series-title":"The Future of Phishing","author":"Tuliani","year":"2004"},{"key":"10.1016\/S0065-2458(06)70005-5_bib055","series-title":"Using Digital Signatures to Secure Email and Stop Phishing Attacks (White Paper)","author":"Tumbleweed","year":"2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib056","unstructured":"Varghese S., \u201cKorgo worm takes phishing to a new level\u201d, Sydney Morning Herald, Sydney, 2004"},{"key":"10.1016\/S0065-2458(06)70005-5_bib057","author":"Wagner"},{"key":"10.1016\/S0065-2458(06)70005-5_bib058","series-title":"Special Interest Tracks and Posters of the 14th International Conference on World Wide Web","first-page":"1060","article-title":"Detection of phishing webpages based on visual similarity","author":"Wenyin","year":"2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib059","unstructured":"Wikipedia, \u201cIdentity theft\u201d, Wikipedia, the free encyclopedia, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib060","unstructured":"Wikipedia, \u201cPhishing\u201d, Wikipedia, the free encyclopedia, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib061","unstructured":"Wikipedia, \u201cSocial engineering (computer security)\u201d, Wikipedia, the free encyclopedia, 2005"},{"key":"10.1016\/S0065-2458(06)70005-5_bib062","doi-asserted-by":"crossref","unstructured":"Wu M., et al., \u201cDo security toolbars actually prevent phishing attacks?\u201d, in: Proc. CHI, 2006","DOI":"10.1145\/1124772.1124863"},{"key":"10.1016\/S0065-2458(06)70005-5_bib063","doi-asserted-by":"crossref","unstructured":"Wu M., et al., \u201cWeb wallet: Preventing phishing attacks by revealing user intentions\u201d, in: SOUPS, 2006","DOI":"10.1145\/1143120.1143133"},{"issue":"2","key":"10.1016\/S0065-2458(06)70005-5_bib064","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1145\/1065545.1065546","article-title":"Trusted paths for browsers","volume":"8","author":"Ye","year":"2005","journal-title":"ACM Trans. Inform. System Security"}],"container-title":["Advances in Computers"],"original-title":[],"deposited":{"date-parts":[[2019,6,7]],"date-time":"2019-06-07T23:45:34Z","timestamp":1559951134000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0065245806700055"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007]]},"references-count":64,"URL":"https:\/\/doi.org\/10.1016\/s0065-2458(06)70005-5","relation":{},"ISSN":["0065-2458"],"issn-type":[{"value":"0065-2458","type":"print"}],"subject":[],"published":{"date-parts":[[2007]]}}}