Skip to main content
Research Paper Undergraduate 3,644 words

Computer Forensics Techniques for Preventing Email Phishing

~19 min read 6 sections Technology · Computer Forensic
Abstract

This paper examines computer forensics techniques applied to the detection and prevention of email phishing attacks. Beginning with a legal and conceptual definition of fraud, the paper traces the evolution of phishing from early AOL scams to sophisticated modern schemes. It surveys twelve distinct categories of phishing attacks, reviews the limitations of common defenses such as anti-phishing toolbars, and analyzes advanced forensic countermeasures including the Humboldt distributed disruption system and the Gajek-Sadeghi forensic tracing framework. The paper concludes that effective anti-phishing systems must generate indistinguishable fraudulent submissions, operate without user intervention, and avoid disrupting innocent parties.

Key Takeaways
  • Introduction to Email Phishing and Fraud: Legal definitions of fraud and phishing overview
  • Project Scope and Research Methodology: Research objectives and information sources
  • Phishing Attack Types and Forensic Trends: Twelve phishing categories and industry trend analysis
  • Computer Forensics Methods and Anti-Phishing Systems: Forensic tools and defense mechanism categories
  • The Humboldt Distributed Phishing Disruption System: Technical architecture of Humboldt data-poisoning system
  • Summary and Conclusion: Synthesis of forensic anti-phishing recommendations
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • Grounds the technical discussion in a precise legal definition of fraud from the U.S. Supreme Court, giving the paper authoritative framing before moving into cybersecurity specifics.
  • Systematically enumerates twelve distinct phishing attack categories with clear, concise descriptions, making the taxonomy easy to follow and reference.
  • Balances breadth (survey of attack types, trends, and defense categories) with depth (detailed technical analysis of the Humboldt system and its distributed architecture).
  • Uses multiple cited sources across industry reports, academic studies, and technical white papers, demonstrating research diversity.

Key academic technique demonstrated

The paper demonstrates effective synthesis of heterogeneous sources — industry reports (Frost and Sullivan), peer-reviewed conference papers (Abu-Nimeh et al.), and technical white papers (Knickerbocker et al.) — weaving them into a coherent argument about the inadequacy of passive defenses and the superiority of active forensic countermeasures. This comparative approach, culminating in the detailed Humboldt case study, is a strong model for literature-based technical analysis.

Structure breakdown

The paper follows a logical progression: (1) conceptual and legal grounding in fraud and phishing definitions; (2) a stated research scope; (3) a broad taxonomy of phishing types and short-to-long-term trends; (4) a survey of forensic detection and defense mechanisms; (5) an in-depth technical analysis of the Humboldt system; and (6) a conclusion tying findings back to the central thesis about proactive forensic defense.

Essay 3,644 words

Introduction to Email Phishing and Fraud

It is no secret that white-collar crime has experienced rapid growth since the advent of the Internet. Reports indicate that white-collar crime costs approximately twenty times more than the costs associated with street crime annually. Fraud is a "generic term" that "embraces all multifarious means which human ingenuity can devise, which are resorted to by one individual to get an advantage over another by false representations" (Singleton, Singleton, and Bologna, 2006). This may include "surprise, trick, cunning and unfair ways by which another is cheated" (Singleton, Singleton, and Bologna, 2006).

Fraud, according to the U.S. Supreme Court, involves the following elements:

(1) That the individual has made a representation regarding a material fact; (2) that such representation is false; (3) that such representation was not actually believed by the defendant, on reasonable grounds, to be true; (4) that it was made with the intent that it should be acted on; (5) that it was acted on by the complainant to his damage; and (6) that in so acting on it, the complainant was ignorant of its falsity and reasonably believed it to be true (Singleton, Singleton, and Bologna, 2006).

Email phishing is one form of fraud as described above. Email phishing involves the sending of emails that are misrepresentative in some way for the purpose of cheating the recipient. Phishing emails have cost individuals and companies both in monetary terms and in terms of privacy violations. Watson, Holz, and Mueller (2005) state that email phishing is "the practice of sending out fake emails, or spam, written to appear as if they have been sent by banks or other reputable organizations, with the intent of luring the recipient into revealing sensitive information such as usernames, passwords, account IDs, ATM PINs or credit card details. Typically, phishing attacks will direct the recipient to a web page designed to mimic a target organization's own visual identity and to harvest the user's personal information, often leaving the victim unaware of the attack."

Jakobsson and Soghoian (2009) report that social engineering is a term "used to describe psychological tricks aimed at making victims agree to things they would not have done normally. Phishing is the theft of user credentials, such as passwords, social security numbers, PINs and answers to security questions." Social engineering is stated to have "become prevalent around 2003" and is "a crime that is on everybody's lips" (Jakobsson and Soghoian, 2009). In fact, many online crimes rely on inducing the victim to take action by "convincing him to do so" (Jakobsson and Soghoian, 2009).

It is necessary to understand the risks faced by consumers with respect to deception, and for this a proactive approach is needed — one "in which the expected vulnerabilities are minimized by the selection and deployment of appropriate email and web templates and the use of appropriate manners of interaction" (Jakobsson and Soghoian, 2009).

Those who are specifically knowledgeable in technical and technological applications often fail to grasp that the average consumer cannot be protected through the same security measures they themselves use. The average consumer is much more susceptible to social engineering attacks. A study involving 2,500 subjects reported by Fogg et al. (2001, 2003) "investigated how different elements of websites affect people's perception of web sites" (Jakobsson and Soghoian, 2009). Findings show that 23% of individuals in the study overlooked browser-based security clues such as the address bar, the status bar, and the SSL lock icon, and 40% of subjects made the wrong security decision (Jakobsson and Soghoian, 2009).

Project Scope and Research Methodology

The purpose of this study is to review and examine techniques of computer forensics as applied to email phishing. Toward this end, the work reviews publicly available information located online via the Internet, including company reports, news reports, journal articles, and other such materials. Included is any information relevant to assurance risk analyses that considers legitimate, known threats pertaining to the subject area. Based on the research gathered, presumed process strengths and vulnerabilities of organizational computing and networking infrastructure are identified in depth.

Phishing Attack Types and Forensic Trends

According to the Frost and Sullivan report entitled "Key Challenges in Fighting Phishing and Pharming," phishers use several Flash-based website methods to hide multimedia objects, thereby avoiding anti-phishing text scanning systems. Additionally, "phishers are using images instead of text to make it harder to detect text commonly used in phishing emails. A user facing a phishing site should be able to differentiate what text is and what an image is" (Frost and Sullivan, n.d.). New and improved telecommunications infrastructure also gives phishers the ability to control and access systems in new ways. Large Internet-based companies, including AOL, MySpace, and PayPal, as well as retailers such as TJX Companies, have been victims and have had to spend large amounts of capital — and have jeopardized their branding — due to phishing attacks (Frost and Sullivan, n.d.).

The specific incidents reported in the Frost and Sullivan report include:

1. Early phishing on AOL (1990): Posing as an AOL staff member sending an instant message to a potential victim, phishers asked users to reveal passwords in order to "verify your account" or "confirm billing information," thereby obtaining legitimate AOL accounts.

2. PayPal (2005): Users were redirected to a fake site in an attempt to collect password details.

3. MySpace (2006): A computer worm altered links to redirect visitors to specially designed websites, stealing login details.

4. Banamex (2006): Despite preventive measures including OTP tokens (One-Time Passwords), phishers attacked the Banamex OTP token (named NetKey), using confusion about the token system itself to ask users to provide passwords.

5. Banco Chile (2008): A phishing email bearing the bank's logo stated: "During our regular maintenance and verification processes, we have detected an error in the information we have associated with your account." The email specified factors that could have caused the error and contained a phishing link at the bottom.

6. Twitter (2009): A phishing scam spread quickly via direct message — "Hi, this you on here?" — providing a phishing link capable of capturing personal information and hijacking accounts (Frost and Sullivan, n.d.).

A Symantec blog article (Forzieri, 2008) identifies specific dilution strategies classified by the type of data provided to a phishing site:

(1) Random Data: A large amount of random, unformatted data is submitted in an attempt to fill up the collection point. A drawback is that fraudsters can easily identify the fake data.

(2) Properly Formatted Data: A large amount of properly formatted data is submitted. This avoids the drawback of the first type while still filling up the collection point.

(3) Tag Data: The fake data submitted is valid and accepted by the institution's website. The injection of this data allows financial institutions to more easily track criminals and gain additional forensic information (Forzieri, 2008).

Frost and Sullivan further report several classifications of phishing attacks:

1. Deceptive Phishing: The most common type. Consists of a deceptive email masquerading as a trusted company. The recipient clicks on a link in the message and is unknowingly redirected to a fraudulent website.

2. Malware-Based Phishing: Involves the execution of malicious software on the user's computer. The user must perform some action — opening an attachment, visiting a website and downloading a program, etc. — that allows the malware to execute.

3. Keyloggers / Screen Loggers: Keyloggers are programs that record keystrokes when installed on the computer, capturing data when the user accesses a registered website. Screen loggers perform the same function but capture screen images instead.

4. Session Hijacking: An assault that occurs after the user has accessed a website monitored by the software. These programs are often disguised as browser components.

5. Web Trojans: Programs that display pop-up screens over legitimate web page validation forms. The user may believe they are entering details on a real website, when in reality the data is being entered into malware.

6. System Reconfiguration Attacks: The attack takes place by changing the configuration parameters of the user's PC — for example, by modifying the domain name system.

7. DNS-Based Phishing ("Pharming"): This offense is based on interference in the domain name search process by modifying domain name resolution, thereby sending the user to a different IP address.

8. Content-Injection Phishing: The phisher introduces fraudulent content into a legitimate website.

9. Data Theft: Malicious code that collects sensitive information stored on the machines in which it is installed.

10. Man-in-the-Middle Phishing: The phisher positions themselves between the user's PC and the server, filtering, reading, and modifying information.

11. Hosts File Poisoning: Another pharming variant in which the attack is carried out by manipulating the host file index on DNS servers.

12. Spear Phishing: One of the newest phishing strategies, targeting a specific company and using emails to deceive individuals at various locations within it (Frost and Sullivan, n.d.).

The general method of attack is carried out through an email or instant message persuading users to enter personal details at a fraudulent website designed to look legitimate. The majority of phishing attacks use misspelled URLs or subdomains provided in emails that appear to belong to a legitimate organization. Another form of phishing, known as IDN spoofing, involves the use of URLs and internationalized domain names in web browsers that appear identical to those of a trusted organization; open URL redirectors are used to disguise malicious URLs with a trusted domain. Certificates fail to address this problem since a phisher can purchase a valid certificate and then modify it to spoof a real website.

Other attacks include cross-site scripting, described as "a type of attack which is very difficult to spot without a specialist's knowledge; this is when phishers use errors in a trusted website's own scripts against the victim. The script directs the user to sign in at their own web page — the web address and security certificates appear to be correct — but in reality the link to the website is crafted to carry out the attack" (Frost and Sullivan, n.d.). Another technique involves popup windows that request an individual's credentials "on top of the legitimate website, in a way that seems that the website is requesting this sensitive information" (Frost and Sullivan, n.d.), a technique reported to be used primarily against banks.

Frost and Sullivan identify the following key challenges in fighting phishing: (1) lack of knowledge in differentiating threats; (2) perception of high prices; (3) lack of quantifiable ROI; and (4) fear of outsourcing security.

Trends and technologies reported by Frost and Sullivan relate to the evolution of phishing attacks in the short, medium, and long term. In the short term, the "increasing volume and degree of vulnerabilities and attacks is turning electronic security into an increasingly complex and broad issue, so the need for specialized professionals and solutions reinforcing network and electronic security is becoming clearer to companies" (Frost and Sullivan, n.d.). Another driver of growth in the Internet security market is the "pressure of regulatory acts, such as the Sarbanes-Oxley Act, Basel II, and compliance with payment card industry international regulations (PCI)" (Frost and Sullivan, n.d.). Additionally, the "enterprise scope turns virtual by incorporating mobile workers, remote sites, home offices, and even vendors and partners within the same corporate network," making security solutions a strategic tool for reliable and efficient network operation (Frost and Sullivan, n.d.). ISPs, banking and finance, and retail are identified as the industries most attacked by security threats since the economic crisis.

In the medium term (2011–2012) and long term (2013–2014), security threats "are expected to present increasingly growing patterns, mainly leveraged by new and improved telecommunications infrastructure and due to new market entrants" (Frost and Sullivan, n.d.). In the long term, changes in pricing that are "inevitable…will redefine segmentation" (Frost and Sullivan, n.d.).

Computer Forensics Methods and Anti-Phishing Systems

Frost and Sullivan report several forensic applications that can be used for detecting phishing:

(1) Detect Monitoring Service: Works through identification accuracy checking and is used to address phishing issues. This real-time connection monitoring service receives transactional data on the client side, with the client's information "correlated with data obtained from malicious activity in the industry" (Frost and Sullivan, n.d.).

(2) Early Notification: A proprietary methodology with the capacity to identify "specific patterns and behaviors that typically occur at the early stages of a phishing attack, providing a way to stop an attack even before it becomes a real threat" (Frost and Sullivan, n.d.).

(3) Malware Monitoring Services: Monitors hundreds of samples of new financially motivated malware on a daily basis, enabling companies to proactively and quickly implement an action plan when malicious code is attacking clients (Frost and Sullivan, n.d.).

(4) Phishing Alerts: Prevents, detects, and enables recovery from phishing and malware attacks. The solution addresses the entire lifecycle of an alert, providing timely help when clients need it most (Frost and Sullivan, n.d.).

Abu-Nimeh, Nappa, Wang, and Nair (2007) report that there are three main categories of phishing and fraud defense mechanisms: (1) detective; (2) preventive; and (3) corrective. Solutions include anti-phishing toolbars, which are used to attempt to alleviate phishing. However, Abu-Nimeh et al. note that "although these toolbars help mitigate the problem, many research studies have demonstrated the ineffectiveness of such techniques" (2007). Two primary problems with this approach are: (1) the spoofed link is often tested without consideration of the context in which it was presented to the user, reducing accuracy; and (2) once the user enters the address of the phishing site in the browser address bar, the user is immediately exposed to any attack carried by the site (Abu-Nimeh et al., 2007).

Wu et al. (2006) conducted an evaluation of the effectiveness of security toolbars in preventing phishing attacks, performing experiments on three security toolbars as well as the browser's address bar and status bar. The study of 30 individuals showed that all tested toolbars were "ineffective in preventing phishing attacks. Users were spoofed 34% of the time. 20 out of 30 users were spoofed by at least one phishing attack. 85% of the spoofed users thought that websites looked legitimate or exactly the same as ones they had visited before. 40% of the spoofed users were tricked because of poorly designed websites, especially when using improper redirections" (Abu-Nimeh et al., 2007). Two primary reasons users fell victim to these attacks were: (1) users disregarded the toolbar display because the content of the web pages looked legitimate or professional; and (2) companies do not follow good practices in designing their websites, and the toolbar cannot help users distinguish poorly designed websites from malicious phishing attacks (Abu-Nimeh et al., 2007).

Knickerbocker, Yu, and Li (2009) state that conventional techniques "for combating phishing have focused primarily on detecting phishing websites and preventing users from revealing their passwords to such sites." This type of protection is described as inherently "incomplete and does nothing to protect users that do not reveal their passwords. Combating the phishing threat requires more than simple avoidance — it requires a more active approach to disrupting even successful phishing operations" (Knickerbocker, Yu, and Li, 2009).

2 Sections Hidden · 910 words
The Humboldt Distributed Phishing Disruption System750 words
The anti-phishing system introduced by Knickerbocker, Yu, and Li (2009) is called "Humboldt," which is similar to another system, "BogusBiter," that "poisons the data that phishers obtain en masse in order to actively disrupt phishing activity." Specifically, Humboldt "takes a different approach to injecting fraudulent submissions into the phishing site's collected data. It relies on Humboldt clients distributed over the Internet to submit…
Summary and Conclusion160 words
This paper has conducted an in-depth examination of phishing forensic information and has set out the methods found to be the most effective in mitigating the risks associated with online phishing schemes. Protection from phishing involves the adoption of a submission pattern that…
Key Concepts in This Paper
Email Phishing Computer Forensics Social Engineering Data Poisoning Humboldt System Pharming Malware Detection Anti-Phishing Toolbars Fraud Defense Spear Phishing
Cite This Paper
PaperDue. (2026). Computer Forensics Techniques for Preventing Email Phishing. PaperDue. https://www.paperdue.com/study-guide/computer-forensics-email-phishing-prevention-9855

Always verify citation format against your institution’s current style guide requirements.