NCDPI K-12 Cybersecurity Program ��Phishing Email Analysis for K-12
Digital Leaders Exchange 2024 �Data Privacy and Cybersecurity
Tim Wease, NCDPI
Samuel Carter, Friday Institute
September 2024
Phishing Email Analysis for K-12
Phishing is a type of social engineering in which threat actors attempt to acquire sensitive information, such as usernames, passwords, and credit card details, by masquerading as a trustworthy entity; intruders use techniques such as sending bulk emails and evading spam filters. This session will explore this attack vector, potential technical and human countermeasures, and include a specific focus on technical steps to analyze suspicious emails.
2
About Tim Wease
3
About Samuel Carter
4
Agenda
5
Background and Context
6
Phishing
7
8
What are the origins of the terms “Phishing” and “SPAM?”
Phishing Threats
9
Motivation Factors
10
Email Security Protections
11
Email Security Protections
Email Provider Configurations
12
Advanced Email Security Protections
13
Email Security Protections
SPF, DKIM, DMARC Demo
Additional Webinar Resource - June 12, 2024 (Recording) (Slides)
https://sci.fi.ncsu.edu/cybersecurity/ncdpi-k-12-webinar-series/
14
Email Security Protections Layers
15
16
There is no such thing as a perfect security system and we need to have the “human firewall”
Human Countermeasures
Human countermeasures include various security awareness and skills training effort
17
Scenario
You have been brought in to investigate an email that one of your staff members thinks is suspicious. What steps do you take to analyze the message?
18
General Steps to Analyze Suspicious Emails
19
General Steps Overview
20
1. Initial Inspection
21
2. Header Analysis
22
3. Content Analysis
23
4. Sender Verification
24
5. Timing and Frequency
25
6. User Feedback
26
7. Clustering and Categorization
27
8. Remediation
28
KnowBe4
29
KnowBe4
30
KnowBe4 Features
31
Questions?
Samuel Carter
North Carolina State University
swcarter@ncsu.edu
Timothy Wease
NCDPI
timothy.wease@dpi.nc.us