social engineering methods that attackers have mastered to perfection allow an email to be prepared in such a way that it is sometimes impossible for a non-specialist to distinguish it from a legitimate one."
Dmitry Kostin said that there was a time when system administrators used DNS records "PTR", "SPF" as protection for the mail system. "Now, along with these records, the use taiwan whatsapp resourceof technologies such as "DKIM" and "DMARC" is considered standard. But even these methods and technologies do not guarantee that an intruder will not overcome the protection means. To increase the security of the mail system, it is now mandatory to use intermediate mail servers, gateways, which are the first - even before the letter is transferred to the mail system - to receive such a letter, check it for threats and, if there are none, transfer it to the mail system for processing," he commented.
Leading case analyst of JSC Infowatch Elix Smirnov told a ComNews correspondent that modern technical means are effective and they must be used, but it is important to understand that it is difficult to protect against such attacks with their help alone - the human factor plays too big a role: "When a user receives a letter from an unknown address with an offer to follow a link and, moreover, to log in there using a password from a corporate account, it is he who decides whether to open an unknown site or not. Regular training and training for employees, which at first glance do not look like high-tech means of protection, are in fact capable of closing a significant part of the risks."
Maxim Andreev said that technical means of protection serve as a serious aid in combating phishing and can provide significant assistance in detecting and neutralizing such attacks: "However, they do not provide 100% protection on their own: it is necessary to work comprehensively, raising users' awareness of the methods of such attacks. As for popular schemes, phishing emails on behalf of counterparties or under the guise of messages from technical support remain frequently used. You can also often see mailings under the guise of messages from government agencies and messages with current news."
Read also
Human awareness as one of the tools for protection against phishing
-
- Posts: 575
- Joined: Thu Jan 02, 2025 7:18 am