Anti-Phishing
Anti-Phishing: Technical and organizational measures against fraudulent messages and websites. Defense requires robust preventionPreventionMeasures intended to stop security incidents or attacks before they occur., meaningful loggingLoggingThe recording of security-relevant events so activity can be monitored, investigated, and audited., timely detectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time., and clearly defined response measures.
How it works and where it fits
Anti-Phishing is a preventive, detective, or corrective security control. Its effect depends on where it sits in the architecture, which data and decisions it processes, and how it might be bypassed. A control reduces a defined risk but rarely removes it completely, so it should be combined with additional layers of protection.
Practical security relevance
Before deployment, the objective, ownership, coverage, and expected behavior should be defined. Secure defaults, controlled exceptions, logging, and periodic effectiveness tests matter more than installation alone. Operational metrics should expose both blocked or detected activity and gaps, false alerts, and effects on legitimate business processes.
Related concepts
- PhishingPhishingAttempts to induce users to disclose data or perform malicious actions.: Attempts to induce users to disclose data or perform malicious actions.
- Spear PhishingSpear PhishingPersonalized phishing attack targeting specific individuals or organizations.: Personalized phishing attack targeting specific individuals or organizations.
- Social EngineeringSocial EngineeringManipulates people to bypass security controls or obtain information.: Manipulates people to bypass security controls or obtain information.
- Detection EngineeringDetection EngineeringSystematic development, testing, and maintenance of rules for attack detection.: Systematic development, testing, and maintenance of rules for attack detection.