Quantifying Psychological Sophistication of Malicious Emails
Theodore Longtchi, Rosana Monta\~nez Rodriguez, Kora Gwartney, Ekzhin, Ear, David P. Azari, Christopher P. Kelley, Shouhuai Xu

TL;DR
This paper introduces a novel framework to quantify the psychological sophistication of malicious emails, revealing their complex techniques and tactics, which can inform better defense strategies against cyber social engineering attacks.
Contribution
The paper proposes a new framework with metrics and grading rules to assess the psychological sophistication of malicious emails, including a case study with expert assessments.
Findings
Malicious emails are highly psychologically sophisticated.
Common patterns include Attention Grabbing and Impersonation.
Social events are frequently exploited by attackers.
Abstract
Malicious emails including Phishing, Spam, and Scam are one significant class of cyber social engineering attacks. Despite numerous defenses to counter them, the problem remains largely open. The ineffectiveness of current defenses can be attributed to our superficial understanding of the psychological properties that make these attacks successful. This problem motivates us to investigate the psychological sophistication, or sophistication for short, of malicious emails. We propose an innovative framework that accommodates two important and complementary aspects of sophistication, dubbed Psychological Techniques, PTechs, and Psychological Tactics, PTacs. We propose metrics and grading rules for human experts to assess the sophistication of malicious emails via the lens of these PTechs and PTacs. To demonstrate the usefulness of the framework, we conduct a case study based on 1,036…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPersonal Information Management and User Behavior · Misinformation and Its Impacts · Spam and Phishing Detection
