1 of 32

NCDPI K-12 Cybersecurity Program ��Phishing Email Analysis for K-12

Digital Leaders Exchange 2024 �Data Privacy and Cybersecurity

Tim Wease, NCDPI

Samuel Carter, Friday Institute

September 2024

2 of 32

Phishing Email Analysis for K-12

Phishing is a type of social engineering in which threat actors attempt to acquire sensitive information, such as usernames, passwords, and credit card details, by masquerading as a trustworthy entity; intruders use techniques such as sending bulk emails and evading spam filters. This session will explore this attack vector, potential technical and human countermeasures, and include a specific focus on technical steps to analyze suspicious emails.

2

3 of 32

About Tim Wease

  • PSU IT Security Specialist at NCDPI�
  • One of the original founding members of the K-12 Cybersecurity Advisory Council (CAC) in 2021�
  • Leading NCDPI K-12 Cybersecurity Program and the core teams/partners who provide the various cybersecurity services and resources to the PSUs

  • 19 years experience (15 in PSU and 4 at DPI)�

3

4 of 32

About Samuel Carter

  • Systems Architect, Friday Institute
  • College of Education, N.C. State University
    • 13 years (10+3)�
  • Adjunct Professor, Computer Science
  • College of Engineering, N.C. State University
    • 19 years�
  • Planning, design, procure, implement, and support of large statewide technology services
    • e.g. NCVPS, NCEdCloud, K-12 Cybersecurity�
  • Extensive background in Cybersecurity with a specialization in Identity and Access management

4

5 of 32

Agenda

  • Introductions�
  • Background and Context
    • Phishing Threats
    • Email Security Protections
    • Human Countermeasures�
  • Steps to Analyze Suspicious Email�
  • Open Q&A

5

6 of 32

Background and Context

6

7 of 32

Phishing

  • Phishing is a type of social engineering in which threat actors attempt to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity using bulk email and evading spam filters.�
  • Some examples of different phishing types and techniques
    • Pretexting for Business Email Compromise
    • Spear Phishing and Whaling
    • Vishing (Voice Phishing) and Smishing (SMS Phishing) and Quishing (QR Code Phishing)
    • Watering Hole Phishing
    • See KnowBe4 Top-Clicked Phishing Tests Infographic (Q2 2023)
  • Note: Spam is unsolicited, unwanted email typically sent for marketing purposes. It is often trying to sell you something, such as unwanted goods or services, but it is not asking you to take specific action.

7

8 of 32

8

What are the origins of the terms “Phishing” and “SPAM?”

9 of 32

Phishing Threats

  • The 2024 Verizon Data Breach Report describes that 63% of breaches involved the human element. Whether it is the use of stolen credentials, phishing, misuse, or simply an error, people continue to play a very large role in incidents and breaches alike.

9

10 of 32

Motivation Factors

  • Authority - request from someone in (presumed) authority�
  • Urgency - humans want to people others by nature; want to be helpful�
  • Social Proof - FOMO, clicks/likes, herd mentality, crave social group interaction�
  • Scarcity - Sign up now for a special offer…supplies are limited�
  • Likeability - find common ground and shared interests�
  • Fear - If you don’t do _____ , then _______ will happen

10

11 of 32

Email Security Protections

  • Sender Policy Framework (SPF) is an email authentication standard that helps prevent email spoofing by verifying the authenticity of email senders. It allows domain owners to specify which mail servers are authorized to send emails on behalf of their domain.�
  • DomainKeys Identified Mail (DKIM) is a protocol for authenticating email messages by allowing the sender’s domain to sign the message with a digital signature. This signature is verified by the recipient’s email server using the sender’s public key, which is published in the DNS as a TXT record.�
  • Domain-based Message Authentication, Reporting & Conformance (DMARC) is an email authentication, policy, and reporting protocol. It builds on SPF and DKIM protocols, adding linkage to the author (“From:”) domain name, published policies for recipient handling of authentication failures, and reporting from receivers to senders, to improve and monitor protection of the domain from fraudulent email.

11

12 of 32

Email Security Protections

Email Provider Configurations

  • Google Advanced phishing and malware protection
    • Protect against attachment types that are uncommon for domain
    • Identify links behind short URLs
    • Scan linked images for malicious content
    • Display a question mark next to unauthenticated sender’s names
    • https://support.google.com/a/answer/9157861?hl=en/��
  • Anti-phishing protection in Microsoft 365

12

13 of 32

Advanced Email Security Protections

  • Mimecast - Mimecast is an AI-powered, API-enabled connected Human Risk Management platform, purpose-built to protect organizations from the spectrum of cyber threats.�
  • Proofpoint - Proofpoint, Inc. is a leading cybersecurity and compliance company that protects organizations’ greatest assets and biggest risks: their people.�
  • CloudFlare - Cloudflare's connectivity cloud protects entire corporate networks, helps customers build Internet-scale applications efficiently, accelerates any website or Internet application, wards off DDoS attacks, keeps hackers at bay, and can help you on your journey to Zero Trust.

13

14 of 32

Email Security Protections

SPF, DKIM, DMARC Demo

Additional Webinar Resource - June 12, 2024 (Recording) (Slides)

https://sci.fi.ncsu.edu/cybersecurity/ncdpi-k-12-webinar-series/

14

15 of 32

Email Security Protections Layers

15

16 of 32

16

There is no such thing as a perfect security system and we need to have the “human firewall”

17 of 32

Human Countermeasures

Human countermeasures include various security awareness and skills training effort

  • Cybersecurity Awareness is the general awareness about cybersecurity threats to an organization and the importance of each stakeholder in keeping it secure�
  • Cybersecurity Training are the skills to do my job in a more secure manner�
  • Cybersecurity Education gives individuals more cybersecurity experience to better manage security programs within an organization

17

18 of 32

Scenario

You have been brought in to investigate an email that one of your staff members thinks is suspicious. What steps do you take to analyze the message?

18

19 of 32

General Steps to Analyze Suspicious Emails

19

20 of 32

General Steps Overview

  1. Initial Inspection
  2. Header Analysis
  3. Context Analysis
  4. Sender Verification
  5. Timing and Frequency
  6. User Feedback
  7. Clustering and Categorization
  8. Remediation

20

21 of 32

1. Initial Inspection

  • Examine the email’s subject line, sender’s address, and recipient’s address for any red flags�
  • Check for spelling and grammar errors, as well as unusual formatting or syntax

21

22 of 32

2. Header Analysis

  • Unusual sender IP addresses or domains�
  • Multiple hops or relayed emails�
  • Lack of authentication or encryption�
  • X-Distribution: bulk/spam email indicators�
  • X-Mailer: unusual or suspicious email clients

22

23 of 32

3. Content Analysis

  • Suspicious attachments (e.g., executable files, ZIP archives)�
  • Links to unfamiliar or suspicious domains�
  • Urgent or threatening language�
  • Requests for sensitive information (e.g., passwords, credit card numbers)�
  • Unusual or generic greetings (e.g., “Dear Customer”)

23

24 of 32

4. Sender Verification

  • Is the sender’s domain and IP address legitimate and registered?�
  • Is the IP address is associated with known spam or phishing activity?�
  • Is the sender’s email address is spoofed or fake?

24

25 of 32

5. Timing and Frequency

  • Is it an unusual time of day or day of the week for the recipient to receive emails?�
  • Are there multiple emails from the same sender or domain?

25

26 of 32

6. User Feedback

  • Encourage users to report suspicious emails and �provide feedback on whether they opened the email �or interacted with it�
  • Did they take any subsequent actions (e.g., clicked links, downloaded attachments)

26

27 of 32

7. Clustering and Categorization

  • Group similar emails together based on similar sender domains or IP addresses�
  • Identical or similar content�
  • Similar attachment types or links�
  • Categorize emails as malicious, suspicious, or benign

27

28 of 32

8. Remediation

  • Quarantining or deleting the email�
  • Blocking the sender’s domain or IP address�
  • Providing users with education and awareness on the identified threats

28

29 of 32

KnowBe4

29

30 of 32

KnowBe4

  • KnowBe4 is the world’s largest integrated platform for security awareness training combined with simulated phishing attacks.�
  • The world's largest library of security awareness training content; including interactive modules, videos, games, posters and newsletters. �
  • Freely available to ALL PSUs in NC via the NCDPI K-12 Cybersecurity Program

30

31 of 32

KnowBe4 Features

  • QR Code
  • USB
  • Callback Phishing
  • PAB Button
  • AIDA
  • PST
  • Awareness Training

31

32 of 32

Questions?

Samuel Carter

North Carolina State University

swcarter@ncsu.edu

Timothy Wease

NCDPI

timothy.wease@dpi.nc.us