Commercial Anti-Smishing Tools and Their Comparative Effectiveness Against Modern Threats
Daniel Timko, Muhammad Lutfor Rahman

TL;DR
This study evaluates the effectiveness of various anti-smishing tools in blocking SMS phishing attacks, revealing significant gaps and highlighting the need for improved detection methods in the SMS ecosystem.
Contribution
The paper introduces Smishtank.com for collecting fresh smishing data and provides a comprehensive comparison of anti-smishing tools' performance across different SMS delivery segments.
Findings
Most tools only blocked messages at the carrier level.
Two apps blocked 85-100% of smishing but also blocked benign messages.
Carriers blocked 25-35% of smishing messages without affecting benign messages.
Abstract
Smishing, also known as SMS phishing, is a type of fraudulent communication in which an attacker disguises SMS communications to deceive a target into providing their sensitive data. Smishing attacks use a variety of tactics; however, they have a similar goal of stealing money or personally identifying information (PII) from a victim. In response to these attacks, a wide variety of anti-smishing tools have been developed to block or filter these communications. Despite this, the number of phishing attacks continue to rise. In this paper, we developed a test bed for measuring the effectiveness of popular anti-smishing tools against fresh smishing attacks. To collect fresh smishing data, we introduce Smishtank.com, a collaborative online resource for reporting and collecting smishing data sets. The SMS messages were validated by a security expert and an in-depth qualitative analysis was…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSpam and Phishing Detection · Cybercrime and Law Enforcement Studies · Advanced Malware Detection Techniques
