REVIEW 4 major objections 6 minor 101 references
Detection and Prevention of Smishing Attacks
T0 review · 4 major / 6 minor · reviewed 2026-08-10 · deepseek-v4-flash
Pith's one-line read This paper argues that replacing SMS slang, abbreviations, and short forms with standard words before classification is the key to detecting smishing, and that this preprocessing step lifts Naive Bayes accuracy on its custom dataset from…
desk verdict A competent student dissertation whose headline 96.2% accuracy is inflated by silently dropping all non-smishing spam from the evaluation, leaving a smishing-vs-ham test that does not transfer to real SMS traffic. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing mechanism is the preprocessing and normalization pipeline of Phase 1, centered on lookup in the NoSlang lingo dictionary, an online slang and abbreviation-to-standard dictionary. Every token is lowercased; if it appears in the dictionary it is expanded to its standard form, otherwise kept as is; stop words are removed using the NLTK stop-word list; and stemming merges inflected variants. Phase 2 then computes word-level ham and smishing probabilities from the normalized training corpus and classifies a message with the Naive Bayes posterior rule, choosing smishing whenever the smishing probability exceeds the ham probability. The paper reports that normalization raises the smishing probability of terms such as 'call' from 0.443425 to 0.464832, illustrating the mechanism by which standardization concentrates probability mass on discriminative words.
What would settle it
Train and test the exact Phase 1-to-Phase 2 pipeline on an independently labeled corpus of current real smishing messages and recent ham SMS, using the same 90/10 split. If overall accuracy does not approach 96.20%, or if the normalization stage fails to reproduce the eight-point gain over the no-normalization baseline, the central claim fails. A cheaper check is to have two independent annotators relabel the 362 smishing messages in the paper's dataset and measure label agreement; low agreement would mean the accuracy numbers are not trustworthy.
Extended reading notes
Core claim
The paper's central discovery is that normalizing noisy SMS text before classification is what drives detection performance. Trained without preprocessing and normalization, the Naive Bayes classifier achieves 88.20% accuracy; with the normalization stage it achieves 96.20% accuracy, with a true positive rate of 97.14% and a true negative rate of 96.12%. The improvement happens because terms like 'call', 'claim', and 'offer' acquire sharper smishing-versus-ham probability estimates after slang and short forms are expanded to standard forms. The paper further claims that this normalization component is what distinguishes its model from earlier content-based smishing detectors in its comparison table.
Load-bearing premise
The entire result rests on the manually built smishing label set: 362 messages called smishing were chosen by one person from a public spam corpus plus 71 Pinterest images, with no stated labeling rule or cross-check, so the 96.20% accuracy could reflect how well the model learns those particular labels rather than smishing in general.
Editorial extensions
If this is right
- If the claimed numbers hold, a content-only pipeline with no URL analysis, no blacklists, and no access to sender identity can block smishing messages with 96.20% accuracy and a 97.14% smishing detection rate.
- The eight-point gain from 88.20% to 96.20% implies that slang normalization, not just feature selection or classifier choice, is the main driver of performance on this dataset.
- Because classification uses only the message text after local preprocessing, the scheme can run on-device and preserve user privacy, consistent with the paper's stated privacy objective.
- With 96.12% ham accuracy, roughly 3.88% of legitimate messages are flagged as smishing, so a phone with heavy legitimate SMS traffic would see about 1 in 26 ham messages blocked or quarantined.
- Since the paper treats smishing as a subset of spam, the same normalized Naive Bayes pipeline should apply to general SMS spam filtering, though the paper does not test that extension.
Reading between the lines
- Beyond the paper: the labeling protocol is unspecified, so if the 362 smishing labels were built from obviously fraudulent spam plus Pinterest examples, the model may be learning a dated and narrow dialect of smishing language rather than a general one.
- Beyond the paper: a testable extension is to run the same pipeline on an independently labeled corpus of current real-world smishing messages; the claim would be much stronger if the eight-point normalization gain reproduces there.
- Beyond the paper: an adversarial consequence the author does not explore is that attackers can evade the classifier by writing smishing messages in normalized, ham-like language, since the classifier relies on content words alone.
- Beyond the paper: the dataset is class-imbalanced with 4,807 ham versus 362 smishing messages, so a trivial ham-only classifier already scores about 93% accuracy; the metrics that matter are smishing recall and the gain over that ham-only baseline.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript, a Master's dissertation, proposes a content-based smishing detection model. The pipeline first tokenizes, lowercases, normalizes slang/abbreviations via the NoSlang dictionary, removes stop words, and stems, then applies a Naive Bayes classifier to label messages as smishing or ham. Experiments on a custom dataset built from the SMS Spam Collection v.1 plus 71 Pinterest smishing messages report an overall accuracy of 96.20%, a smishing true positive rate of 97.14%, a ham true negative rate of 96.12%, and an 8% accuracy improvement attributable to preprocessing and normalization. The dissertation also contains a broad survey of mobile phishing attacks and defense mechanisms.
Significance. If the experimental result is valid, the paper would offer a simple, privacy-preserving preprocessing contribution to smishing detection and one of the few dedicated smishing datasets. The approach is falsifiable and uses an external dictionary and a held-out test split, so there is no circular derivation. However, the evaluation design has a missing-class problem, the smishing label set is not auditable, and the performance estimate rests on a single small test split; these issues must be resolved before the claimed accuracy can be considered established. The comprehensive survey is a useful reference for researchers entering the area, but the experimental contribution is the central element that needs strengthening.
major comments (4)
- [Section 4.2, Dataset Used] The dataset arithmetic is inconsistent with the evaluation. Starting from 4,827 ham and 747 spam messages and adding 71 Pinterest smishing messages, the paper reports a final dataset of 4,807 ham and 362 smishing messages (5,169 total). This implies that 456 original spam messages that were not manually labeled as smishing, and 20 original ham messages, were removed from the evaluation without any stated reason. Because the paper defines smishing as a subset of spam (Sections 1.1 and 1.3), ordinary spam is the closest non-target class in real SMS traffic and the most likely source of false alarms. By deleting those 456 messages, the evaluation reduces the problem to smishing-versus-ham rather than smishing-versus-everything-else, so the reported 96.20% accuracy does not support the abstract's claim that the model detects smishing in a real message stream. Please report the exact dataset construction steps, state what happened to the excluded messages, and evaluate the model on a test set that includes ordinary spam as a negative class.
- [Section 4.3, Results and Discussions] The experimental protocol is fragile: a single 90/10 split produces a test set with only 35 smishing messages (362 × 0.10), so the reported TPR of 97.14% corresponds to 34 correct classifications out of 35. One misclassification changes the TPR by roughly 2.9 percentage points, and the claimed 8% normalization gain (88.20% to 96.20%) is based on this single split with no cross-validation, no repeated runs, and no error bars. Please provide K-fold cross-validation or repeated random splits with confidence intervals, and report the raw confusion matrix counts.
- [Section 4.2, Dataset Used] The smishing labels were created manually by the author from the SMS Spam Collection's spam messages and Pinterest images, but no labeling criteria, annotation guidelines, or inter-annotator agreement are provided, and the labeled dataset is not released. Without an explicit and reproducible labeling rule, the 362 smishing messages cannot be audited, and the reported TPR/TNR may not transfer to other SMS corpora. Please state the labeling rule (e.g., presence of a request to disclose credentials or click a link combined with a sense of urgency), and consider releasing the labeled data or a random sample for independent inspection.
- [Table 4.8 and Section 5.1] The statement that the proposed model achieves the 'highest classification accuracy and True positive rate among all the schemes discussed' is not supported by the comparison in Table 4.8, because the accuracy numbers are drawn from different datasets and experimental setups, such as S-Detector on a Korean dataset and SMSAssassin on a crowdsourced 4,318-message corpus. Accuracy values across different test sets are not directly comparable; the table should be either restricted to re-implementations on the same data or clearly labeled as indicative only and excluded from the conclusion.
minor comments (6)
- [Section 3.1.2, Algorithm 2] The word probability estimates use unsmoothed counts (w_ham divided by total ham messages), which can assign zero probability to unseen words and destabilize classification with a small smishing vocabulary; consider adding Laplace smoothing and discussing its effect.
- [Title and Section 3.1] The title promises 'prevention,' but the proposed model only classifies messages as smishing or ham; no blocking, alerting, or quarantine mechanism is described or evaluated. Please adjust the title or add a prevention component to match the stated scope.
- [Section 2.4.1.2] The claim that 'Vishing has a comparatively higher success rate than other mobile phishing methodologies' is presented without a supporting citation; please add a reference for this assertion.
- [Tables 4.3–4.6] The tables report only word probabilities without the underlying raw counts, so the reader cannot assess the stability of the probability estimates or the effect of the 90/10 split; please include the count information or specify the number of documents containing each term.
- [Section 4.2, Dataset Used] The paper does not explain why the number of ham messages decreased from 4,827 in the original corpus to 4,807 in the final dataset; please clarify whether 20 ham messages were removed and, if so, why.
- [Chapter 2] The literature review is disproportionately long relative to the experimental contribution, and it contains many reproduced statistics without recent sources; condensing this material and focusing on directly related smishing detection works would improve the manuscript's focus.
Circularity Check
No significant circularity: the classifier is trained and evaluated on disjoint splits using an external dictionary, so the reported accuracy is an empirical result rather than a reduction to the paper's own inputs.
full rationale
The paper's central claim is that Naive Bayes classification, combined with preprocessing and normalization using the external NoSlang dictionary, achieves 96.20% accuracy in separating smishing from ham messages. This claim is supported by a standard experimental procedure: Algorithm 2 selects 90% of the normalized dataset for training and evaluates on the remaining 10% (Section 3.1.2), so word probabilities are estimated on the training split and the reported accuracy is computed on held-out messages. The normalization dictionary is an external resource (Ref. [113]), not a parameter fitted to the target labels, so the improvement from 88.20% to 96.20% is not circular. The author-built smishing label set described in Section 4.2 is a data-construction and labeling-validity concern, not a circular derivation: the labels are ground truth for evaluation, not outputs derived from the classifier. Similarly, the arithmetic discrepancy in Section 4.2, whereby roughly 456 original spam messages are not accounted for in the final 5,169-message dataset, is an evaluation-design and generalizability issue (the omitted non-smishing spam is the closest non-target class), but it does not make the reported accuracy equivalent to an input by construction. The only self-citation, Ref. [14], is used for background statements about smishing being a subset of spam and about attacker targeting; it is not load-bearing for the experimental derivation. Accordingly, no quoted step reduces to its own inputs, and the appropriate finding is no significant circularity.
Assumptions & free parameters
free parameters (1)
- Naive Bayes word likelihood estimates =
Estimated from training split; example given: p(call|smishing)=0.464832
assumptions (3)
- domain assumption Naive Bayes conditional independence assumption
- domain assumption NoSlang dictionary covers abbreviations and slang in real SMS messages
- domain assumption The SMS Spam Collection v.1 ham/spam labels are accurate and the author's smishing extraction is correct
Cite this review
Pith. "Pith review of Detection and Prevention of Smishing Attacks." pith.science (2026). https://pith.science/paper/4OBF27JG
@misc{pith2026250100260,
author = {Pith},
title = {Pith review of: Detection and Prevention of Smishing Attacks},
year = {2026},
howpublished = {\url{https://pith.science/paper/4OBF27JG}},
note = {Machine review of arXiv:2501.00260}
}
read the original abstract
Phishing is an online identity theft technique where attackers steal users personal information, leading to financial losses for individuals and organizations. With the increasing adoption of smartphones, which provide functionalities similar to desktop computers, attackers are targeting mobile users. Smishing, a phishing attack carried out through Short Messaging Service (SMS), has become prevalent due to the widespread use of SMS-based services. It involves deceptive messages designed to extract sensitive information. Despite the growing number of smishing attacks, limited research focuses on detecting these threats. This work presents a smishing detection model using a content-based analysis approach. To address the challenge posed by slang, abbreviations, and short forms in text communication, the model normalizes these into standard forms. A machine learning classifier is employed to classify messages as smishing or ham. Experimental results demonstrate the model effectiveness, achieving classification accuracies of 97.14% for smishing and 96.12% for ham messages, with an overall accuracy of 96.20%.
Figures
Figures from the paper (10 more)
Reference graph
Works this paper leans on
-
[1]
Khonji, M., Iraqi, Y., & Jones, A. (2013). Phishing detection: a literature survey. IEEE Communications Surveys & Tutorials, 15(4), 2091-2121
2013
-
[2]
Available at http://docs.apwg.org/reports/apwg_trends_report_q1_2016.pdf
Anti-Phishing Working Group (APWG), Phishing activity trends report – first quarter 2016. Available at http://docs.apwg.org/reports/apwg_trends_report_q1_2016.pdf. Accessed June 2017
2016
-
[3]
Available at http://docs.apwg.org/reports/apwg_trends_report_q2_2016.pdf
Anti-Phishing Working Group (APWG), Phishing activity trends report – second quarter 2016. Available at http://docs.apwg.org/reports/apwg_trends_report_q2_2016.pdf. Accessed June 2017
2016
-
[4]
Available at http://docs.apwg.org/reports/apwg_trends_report_q3_2016.pdf
Anti-Phishing Working Group (APWG), Phishing activity trends report – third quarter 2016. Available at http://docs.apwg.org/reports/apwg_trends_report_q3_2016.pdf. Accessed June 2017
2016
-
[5]
Available at http://docs.apwg.org/reports/apwg_trends_report_q4_2016.pdf
Anti-Phishing Working Group (APWG), Phishing activity trends report – fourth quarter 2016. Available at http://docs.apwg.org/reports/apwg_trends_report_q4_2016.pdf. Accessed June 2017
2016
-
[6]
Foozy, C. F. M., Ahmad, R., & Abdollah, M. F. (2013). Phishing detection taxonomy for mobile device. International Journal of Computer Science Issues (IJCSI), 10(1), 338-344
2013
-
[7]
W., Moon, S
Joo, J. W., Moon, S. Y., Singh, S., & Park, J. H. (2017). S-Detector: an enhanced security model for detecting Smishing attack for mobile computing. Telecommunication Systems, 1-10
2017
-
[8]
L., & Chun, Y
Choi, K., Lee, J. L., & Chun, Y. T. (2017). Voice phishing fraud and its modus operandi. Security Journal, 30(2), 454-466
2017
Show all 101 references
-
[9]
(2017, October)
Şentürk, Ş., Yerli, E., & Soğukpınar, İ. (2017, October). Email phishing detection and prevention by using data mining techniques. In Computer Science and Engineering (UBMK), 2017 International Conference on (pp. 707-712). IEEE
2017
-
[10]
S., & Traynor, P
Amrutkar, C., Kim, Y. S., & Traynor, P. (2017). Detecting mobile malicious webpages in real time. IEEE Transactions on Mobile Computing, 16(8), 2184-2197
2017
-
[11]
D., Kadobayashi, Y., & Fall, D
Ndibwile, J. D., Kadobayashi, Y., & Fall, D. (2017, August). UnPhishMe: Phishing Attack Detection by Deceptive Login Simulation through an Android Mobile App. In Information Security (AsiaJCIS), 2017 12th Asia Joint Conference on (pp. 38-47). IEEE
2017
-
[12]
S., & Sharma, P
Kunwar, R. S., & Sharma, P. (2017, March). Framework to detect malicious codes embedded with JPEG images over social networking sites. In Innovations in Information, Embedded and Communication Systems (ICIIECS), 2017 International Conference on (pp. 1-4). IEEE
2017
-
[13]
Available at https://www.scmagazine.com/from-ransomware-to-social-media-to-the-cloud-the-top-5- phishing-challenges-for-2018/article/742252/
SC MEDIA, From ransomware to social media to the cloud: The Top 5 phishing challenges for 2018. Available at https://www.scmagazine.com/from-ransomware-to-social-media-to-the-cloud-the-top-5- phishing-challenges-for-2018/article/742252/. Accessed February 2018
2018
-
[14]
Goel, D., & Jain, A. K. (2017). Mobile phishing attacks and defence mechanisms: state of art and open research challenges. Computers & Security
2017
-
[15]
Phinding phish: Evaluating anti-phishing tools,
L. F. Cranor, S. Egelman, J. I. Hong, and Y. Zhang, “Phinding phish: Evaluating anti-phishing tools,” In Proceedings of The 14th Annual Network and Distributed System Security Symposium (NDSS ’07), February, 2007. 57
2007
-
[16]
Choudhary, N., & Jain, A. K. (2017, March). Comparative Analysis of Mobile Phishing Detection and Prevention Approaches. In International Conference on Information and Communication Technology for Intelligent Systems (pp. 349-356). Springer, Cham
2017
-
[17]
K., & Gupta, B
Tewari, A., Jain, A. K., & Gupta, B. B. (2016). Recent survey of various defense mechanisms against phishing attacks. Journal of Information Privacy and Security, 12(1), 3-13
2016
-
[19]
B., Tewari, A., Jain, A
Gupta, B. B., Tewari, A., Jain, A. K., & Agrawal, D. P. (2017). Fighting against phishing attacks: state of the art and future challenges. Neural Computing and Applications, 28(12), 3629-3654
2017
-
[20]
Available at https://www.statista.com/statistics/330695/number-of-smartphone-users-worldwide/
Number of Smartphone users worldwide from 2014 to 2020. Available at https://www.statista.com/statistics/330695/number-of-smartphone-users-worldwide/. Accessed March 2018
2014
-
[21]
Available at https://blogs.rsa.com/rogue-mobile-apps- phishing-malware-and-fraud
Rogue Mobile Apps, Phishing, Malware and Fraud. Available at https://blogs.rsa.com/rogue-mobile-apps- phishing-malware-and-fraud. Accessed July 2017
2017
-
[23]
Available at https://www.wombatsecurity.com/hubfs/2018%20State%20of%20the%20Phish/Wombat- StateofPhish2018.pdf?submissionGuid=2f8a7968-4f1e-4578-ba7c-127516efa6fb
State of the Phish. Available at https://www.wombatsecurity.com/hubfs/2018%20State%20of%20the%20Phish/Wombat- StateofPhish2018.pdf?submissionGuid=2f8a7968-4f1e-4578-ba7c-127516efa6fb. Accessed March 2018
2018
-
[24]
Available at https://www.statista.com/statistics/485153/a2p-sms- market-size-worldwide/
Worldwide A2P SMS Markets 2014-2017. Available at https://www.statista.com/statistics/485153/a2p-sms- market-size-worldwide/. Accessed March 2018
2014
-
[25]
Available at http://resources.infosecinstitute.com/category/enterprise/phishing/phishing-variations/phishing-variations- smishing/#gref
Infosec Institute, Smishing. Available at http://resources.infosecinstitute.com/category/enterprise/phishing/phishing-variations/phishing-variations- smishing/#gref. Accessed February 2018
2018
-
[26]
K., & Gupta, B
Jain, A. K., & Gupta, B. B. (2017). Phishing Detection: Analysis of Visual Similarity Based Approaches. Security and Communication Networks, 2017
2017
-
[27]
Carroll, A., & Heiser, G. (2010). An analysis of power consumption in a smartphone
2010
-
[28]
Available at https://www.statista.com/statistics/330695/number-of-smartphone-users-worldwide/
Number of Smartphone users worldwide from 2014 to 2020. Available at https://www.statista.com/statistics/330695/number-of-smartphone-users-worldwide/. Accessed July 2017
2014
-
[29]
Available at https://mobileecosystemforum.com//wpcontent/uploads/2016/09/Fraud_Report_2016.pdf
MEF mobile messaging fraud report 2016. Available at https://mobileecosystemforum.com//wpcontent/uploads/2016/09/Fraud_Report_2016.pdf. Accessed June 2017
2016
-
[30]
Available at https://www.mobilexco.com/blog/18-stats-to-help-you-plan-your-mobile-marketing-strategy-in-2018
Mobile x co., 18 mobile stats to consider for your 2018 marketing strategy. Available at https://www.mobilexco.com/blog/18-stats-to-help-you-plan-your-mobile-marketing-strategy-in-2018. Accessed March 2018. 58
2018
-
[31]
Available at https://blogs.constantcontact.com/use-sms-to-grow-business-2018/#
Constant contact, How (and Why) to Use SMS to Grow Your Business in 2018. Available at https://blogs.constantcontact.com/use-sms-to-grow-business-2018/#. Accessed March 2018
2018
-
[32]
D., Kang, W
Kang, A., Lee, J. D., Kang, W. M., Barolli, L., & Park, J. H. (2014). Security considerations for smart phone smishing attacks. In Advances in Computer Science and its Applications (pp. 467-473). Springer, Berlin, Heidelberg
2014
-
[33]
Available at https://www.social-engineer.org/framework/attack- vectors/smishing/
The Social Engineering Framework. Available at https://www.social-engineer.org/framework/attack- vectors/smishing/. Accessed March 2018
2018
-
[34]
Available at http://www.phishingpro.com/
Phishingpro. Available at http://www.phishingpro.com/. Accessed July 2017
2017
-
[35]
Available at http://go.wandera.com/rs/988-EGM- 040/images/Phishing%20%282%29.pdf
Wandera Mobile data report: focus on Phishing. Available at http://go.wandera.com/rs/988-EGM- 040/images/Phishing%20%282%29.pdf. Accessed June 2017
2017
-
[36]
O., & Amanor, P
Yeboah-Boateng, E. O., & Amanor, P. M. (2014). Phishing, SMiShing & Vishing: an assessment of threats against mobile devices. Journal of Emerging Trends in Computing and Information Sciences, 5(4), 297-307
2014
-
[37]
Krombholz, K., Hobel, H., Huber, M., &Weippl, E. (2015). Advanced social engineering attacks. Journal of Information Security and applications, 22, 113-122
2015
-
[38]
Available at https://www.fireeye.com/current-threats/best- defense-against-spear-phishing-attacks.html
FireEye Best Defense against Spear Phishing. Available at https://www.fireeye.com/current-threats/best- defense-against-spear-phishing-attacks.html. Accessed July 2017
2017
-
[39]
Available at http://resources.infosecinstitute.com/category/enterprise/phishing/phishing- variations/phishing-variations-vishing/what-is-vishing/#gref
What is Vishing. Available at http://resources.infosecinstitute.com/category/enterprise/phishing/phishing- variations/phishing-variations-vishing/what-is-vishing/#gref. Accessed July 2017
2017
-
[40]
Available at https://www.lifewire.com/voip-phishing-3426534
Lifewire VoIP Phishing - What is VoIP Phishing and How Does It Work. Available at https://www.lifewire.com/voip-phishing-3426534. Accessed July 2017
2017
-
[41]
B., Atawneh, S., Meulenberg, A., & Almomani, E
Almomani, A., Gupta, B. B., Atawneh, S., Meulenberg, A., & Almomani, E. (2013). A survey of phishing email filtering techniques. IEEE communications surveys & tutorials, 15(4), 2070-2090
2013
-
[42]
Hong, J. (2012). The state of phishing attacks. Communications of the ACM, 55(1), 74-81
2012
-
[43]
Available at http://searchsecurity.techtarget.com/definition/spear-phishing
Search security spear phishing. Available at http://searchsecurity.techtarget.com/definition/spear-phishing. Accessed July 2017
2017
-
[44]
Available at https://www.mimecast.com/content/whaling-attack/
Mimecast Whaling attack. Available at https://www.mimecast.com/content/whaling-attack/. Accessed July 2017
2017
-
[45]
Available at https://digitalguardian.com/blog/what-whaling- attack-defining-and-identifying-whaling-attacks
Digital Guardian What is whaling attack. Available at https://digitalguardian.com/blog/what-whaling- attack-defining-and-identifying-whaling-attacks. Accessed July 2017
2017
-
[46]
Khurana, P., Sharma, A., & Singh, P. K. (2016). A systematic analysis on mobile application software vulnerabilities: Issues and challenges. Indian Journal of Science and Technology, 9(32)
2016
-
[47]
Wu, L., Du, X., & Wu, J. (2016). Effective defense schemes for phishing attacks on mobile computing platforms. IEEE Transactions on Vehicular Technology, 65(8), 6678-6691
2016
-
[48]
Available at https://proofpoint.com/us
The Human Factor Report. Available at https://proofpoint.com/us. Accessed June 2017
2017
-
[49]
J., Soriente, C., Kostiainen, K., & Capkun, S
Marforio, C., Masti, R. J., Soriente, C., Kostiainen, K., & Capkun, S. (2015). Personalized security indicators to detect application phishing attacks in mobile platforms. arXiv preprint arXiv:1502.06824. 59
2015 arXiv
-
[50]
P., Finifter, M., Chin, E., Hanna, S., & Wagner, D
Felt, A. P., Finifter, M., Chin, E., Hanna, S., & Wagner, D. (2011, October). A survey of mobile malware in the wild. In Proceedings of the 1st ACM workshop on Security and privacy in smartphones and mobile devices (pp. 3-14). ACM
2011
-
[51]
Symantec Internet Security Threat Report 2014, Vol. 19. Available at http://www.symantec.com/content/en/us/enterprise/other_resources/b-istr_main_report_v19_21291018.en- us.pdf. Accessed July 2017
2014
-
[52]
(2011, May)
Delac, G., Silic, M., & Krolo, J. (2011, May). Emerging security threats for mobile platforms. In MIPRO, 2011 Proceedings of the 34th International Convention (pp. 1468-1473). IEEE
2011
-
[53]
Dunham, K. (2008). Mobile malware attacks and defense. Syngress
2008
-
[54]
(2010, October)
Landman, M. (2010, October). Managing smart phone security risks. In 2010 Information Security Curriculum Development Conference (pp. 145-155). ACM
2010
-
[55]
Accessed July 2017
What is rootkit virus? http://www.pctools.com/security-news/what-is-a-rootkit-virus/. Accessed July 2017
2017
-
[56]
Richardson, R., & North, M. (2017). Ransomware: Evolution, Mitigation and Prevention. International Management Review, 13(1), 10
2017
-
[57]
He, D., Chan, S., & Guizani, M. (2015). Mobile application security: malware threats and defenses. IEEE Wireless Communications, 22(1), 138-144
2015
-
[58]
Available at https://www.symantec.com/content/en/us/enterprise/media/security_response/ whitepapers/the_risks_of_social_networking.pdf
Symantec security response The Risks of Social Networking. Available at https://www.symantec.com/content/en/us/enterprise/media/security_response/ whitepapers/the_risks_of_social_networking.pdf. Accessed June 2017
2017
-
[59]
Available at https://www.advantiscu.org/fraud- prevention/beware-of-phishing-scams-in-social-media.html
Advantis Beware of Phishing Scams in Social Media. Available at https://www.advantiscu.org/fraud- prevention/beware-of-phishing-scams-in-social-media.html. Accessed July 2017
2017
-
[60]
Available at http://resources.infosecinstitute.com/category/enterprise/phishing/the-phishing-landscape/phishing-attacks- by-demographic/social-networks/#gref
Infosec institute Phishing on Social Networks – Gathering information. Available at http://resources.infosecinstitute.com/category/enterprise/phishing/the-phishing-landscape/phishing-attacks- by-demographic/social-networks/#gref. Accessed July 2017
2017
-
[61]
Available at https://www.incapsula.com/web-application-security/cross-site- scripting-xss-attacks.html
Cross site scripting attacks. Available at https://www.incapsula.com/web-application-security/cross-site- scripting-xss-attacks.html. Accessed June 2017
2017
-
[62]
Available at https://blog.aujas.com/2015/08/27/mobile-phishing-thief-right-in-your-pockets/
Information Risk management blog, mobile phishing: theif right in your pocket. Available at https://blog.aujas.com/2015/08/27/mobile-phishing-thief-right-in-your-pockets/. Accessed July 2017
2015
-
[63]
B., Arachchilage, N
Gupta, B. B., Arachchilage, N. A., & Psannis, K. E. (2017). Defending against phishing attacks: taxonomy of methods, current issues and future directions. Telecommunication Systems, 1-21
2017
-
[64]
Available at http://www.pcworld.com/article/135293/article.html
PCWorldTypes of Phishing Attacks. Available at http://www.pcworld.com/article/135293/article.html. Accessed July 2017
2017
-
[65]
Available at http://www.phishing.org/phishing-techniques
PHISHING.org Phishing techniques. Available at http://www.phishing.org/phishing-techniques. Accessed July 2017
2017
-
[66]
Available at https://www.honeynet.org/node/90
The Honeynet Project Phishing Technique One - Phishing through Compromised Web Servers (2008). Available at https://www.honeynet.org/node/90. Accessed July 2017. 60
2008
-
[67]
Examining the impact of website take-down on phishing,
T. Moore and R. Clayton, “Examining the impact of website take-down on phishing,” in eCrime ’07: Proceedings of the anti-phishing working group 2nd annual eCrime researchers summit. New York, NY, USA: ACM, 2007, pp. 1–13
2007
-
[68]
Bicakci, K., Unal, D., Ascioglu, N., & Adalier, O. (2014). Mobile authentication secure against man-in-the- middle attacks. Procedia Computer Science, 34, 323-329
2014
-
[69]
(2010, June)
Shahriar, H., & Zulkernine, M. (2010, June). PhishTester: automatic testing of phishing attacks. In Secure Software Integration and Reliability Improvement (SSIRI), 2010 Fourth International Conference on (pp. 198-207). IEEE
2010
-
[70]
Available at http://resources.infosecinstitute.com/session- hijacking-cheat-sheet/
Infosec institute session hijacking cheat sheet. Available at http://resources.infosecinstitute.com/session- hijacking-cheat-sheet/. Accessed July 2017
2017
-
[71]
(2008, November)
Abu-Nimeh, S., & Nair, S. (2008, November). Bypassing security toolbars and phishing filters via DNS poisoning. In Global Telecommunications Conference, 2008. IEEE GLOBECOM 2008. IEEE (pp. 1-6). IEEE
2008
-
[72]
Available at https://www.howtogeek.com/161808/htg-explains-what-is-dns-cache- poisoning/
What is DNS poisoning. Available at https://www.howtogeek.com/161808/htg-explains-what-is-dns-cache- poisoning/. Accessed July 2017
2017
-
[73]
Asanka, N., Love, S., & Scott, M. (2012). Designing a mobile game to teach conceptual knowledge of avoiding'phishing attacks'. International Journal for e-Learning Security, 2(1), 127-132
2012
-
[74]
Arachchilage, N. A. G., & Love, S. (2013). A game design framework for avoiding phishing attacks. Computers in Human Behavior, 29(3), 706-714
2013
-
[75]
Arachchilage, N. A. G., & Hameed, M. A. (2017). Integrating self-efficacy into a gamified approach to thwart phishing attacks. arXiv preprint arXiv:1706.07748
2017 arXiv
-
[76]
Arachchilage, N. A. G., & Cole, M. (2016). Designing a mobile game for home computer users to protect against phishing attacks. arXiv preprint arXiv:1602.03929
2016 arXiv
-
[77]
phishing attacks
Arachchilage, N. A. G., & Cole, M. (2011, June). Design a mobile game for home computer users to prevent from “phishing attacks”. In Information Society (i-Society), 2011 International Conference on (pp. 485-489). IEEE
2011
-
[78]
Arachchilage, N. A. G., Tarhini, A., & Love, S. (2015). Designing a mobile game to thwarts malicious IT threats: A phishing threat avoidance perspective. arXiv preprint arXiv:1511.07093
2015 arXiv
-
[79]
W., & Li, N
Yang, W., Xiong, A., Chen, J., Proctor, R. W., & Li, N. (2017, April). Use of Phishing Training to Improve Security Warning Compliance: Evidence from a Field Experiment. In Proceedings of the Hot Topics in Science of Security: Symposium and Bootcamp (pp. 52-61). ACM
2017
-
[80]
(2011, March)
Yadav, K., Kumaraguru, P., Goyal, A., Gupta, A., & Naik, V. (2011, March). Smsassassin: Crowdsourcing driven mobile-based system for sms spam filtering. In Proceedings of the 12th Workshop on Mobile Computing Systems and Applications (pp. 1-6). ACM
2011
-
[81]
El-Alfy, E. S. M., & AlHasan, A. A. (2016). Spam filtering framework for multimodal mobile communication based on dendritic cell algorithm. Future Generation Computer Systems, 64, 98-107. 61
2016
-
[82]
S., Anuar, N
Adewole, K. S., Anuar, N. B., Kamsin, A., & Sangaiah, A. K. (2017). SMSAD: a framework for spam message and spam account detection. Multimedia Tools and Applications, 1-36
2017
-
[83]
A., Silva, T
Almeida, T. A., Silva, T. P., Santos, I., & Hidalgo, J. M. G. (2016). Text normalization and semantic indexing to enhance Instant Messaging and SMS spam filtering. Knowledge-Based Systems, 108, 25-32
2016
-
[84]
Karami, A., & Zhou, L. (2014). Improving static SMS spam detection by using new content-based features
2014
-
[85]
Available at http://www.hauri.co.kr/support/hauriNews_view.html?intSeq=303&page=7&keyfield=&key
Smishing Defender. Available at http://www.hauri.co.kr/support/hauriNews_view.html?intSeq=303&page=7&keyfield=&key. Accessed July 2017
2017
-
[86]
M., Almeida, T
Silva, R. M., Almeida, T. A., & Yamakami, A. (2017). MDLText: An efficient and lightweight text classifier. Knowledge-Based Systems, 118, 152-164
2017
-
[87]
Lee, A., Kim, K., Lee, H., & Jun, M. (2016). A Study on Realtime Detecting Smishing on Cloud Computing Environments. In Advanced Multimedia and Ubiquitous Engineering (pp. 495-501). Springer, Berlin, Heidelberg
2016
-
[88]
K., Gunal, S., Ergin, S., & Gunal, E
Uysal, A. K., Gunal, S., Ergin, S., & Gunal, E. S. (2012, July). A novel framework for SMS spam filtering. In Innovations in Intelligent Systems and Applications (INISTA), 2012 International Symposium on (pp. 1- 4). IEEE
2012
-
[89]
(2014, August)
Wu, L., Du, X., & Wu, J. (2014, August). MobiFish: A lightweight anti-phishing scheme for mobile phones. In Computer Communication and Networks (ICCCN), 2014 23rd International Conference on (pp. 1-8). IEEE
2014
-
[90]
J., & Gangwani, V
Tripathi, S. J., & Gangwani, V. S. (2017). Design the Framework for Detecting Malicious Mobile Webpages in Real Time. International Journal of Engineering Science, 11884
2017
-
[91]
Bottazzi, G., Casalicchio, E., Cingolani, D., Marturana, F., Piu, M.: MP-Shield: A Framework for Phishing Detection in Mobile Devices. In: IEEE International Conference on Computer and Information Technology; Ubiquitous Computing and Communications; Dependable, Autonomic and S...
2015
-
[92]
P., & Shekokar, N
Chorghe, S. P., & Shekokar, N. (2016). A Solution to Detect Phishing in Android Devices. In Information Systems Security (pp. 461-470). Springer International Publishing
2016
-
[93]
Sharifi, M., & Siadati, S. H. (2008, March). A phishing sites blacklist generator. In Computer Systems and Applications, 2008. AICCSA 2008. IEEE/ACS International Conference on (pp. 840-843). IEEE
2008
-
[94]
(2008, October)
Cao, Y., Han, W., & Le, Y. (2008, October). Anti-phishing based on automated individual white-list. In Proceedings of the 4th ACM workshop on Digital identity management (pp. 51-60). ACM
2008
-
[95]
(2012, October)
Li, L., Helenius, M., & Berki, E. (2012, October). A usability test of whitelist and blacklist-based anti- phishing application. In Proceeding of the 16th International Academic MindTrek Conference (pp. 195-202). ACM
2012
-
[96]
K., & Gupta, B
Jain, A. K., & Gupta, B. B. (2016). A novel approach to protect against phishing attacks at client side using auto-updated white-list. EURASIP Journal on Information Security, 2016(1), 9. 62
2016
-
[97]
(2007, September)
Han, W., Wang, Y., Cao, Y., Zhou, J., & Wang, L. (2007, September). Anti-phishing by smart mobile device. In Network and Parallel Computing Workshops, 2007. NPC Workshops. IFIP International Conference on (pp. 295-302). IEEE
2007
-
[98]
K., & Gupta, B
Jain, A. K., & Gupta, B. B. (2017). Two-level authentication approach to protect from phishing attacks in real time. Journal of Ambient Intelligence and Humanized Computing, 1-14
2017
-
[99]
Andromaly
Liu, D., & Cox, L. P. (2014, February). Veriui: Attested login for mobile devices. In Proceedings of the 15th Workshop on Mobile Computing Systems and Applications (p. 7). ACM. [100]Kim, D., Park, C., & Ryou, J. (2015, July). StopBankun: Countermeasure of app replacement attac...
2012
-
[100]
Mobile phishing attacks and defence mechanisms: state of art and open research challenges
Diksha Goel and Ankit Kumar Jain, (2018). Mobile phishing attacks and defence mechanisms: state of art and open research challenges. Computers & Security, Elsevier, vol 73, pp. 519-544, DOI: 10.1016/j.cose.2017.12.006. (SCI- Indexed) (Impact Factor: 2.849)
2018 doi
-
[101]
Smishing-Classifier: A Novel Framework for detection of Smishing Attack in Mobile Environment
Diksha Goel and Ankit Kumar Jain, (2017). Smishing-Classifier: A Novel Framework for detection of Smishing Attack in Mobile Environment. In proceedings of International Conference on Next Generation Computing Technologies, Dehradun, India, pp. 502-512. DOI: 10.1007/978-981-10-...
2017 doi
-
[102]
Overview of Smartphone Security- Attack and Defence Techniques
Diksha Goel and Ankit Kumar Jain, (2017). Overview of Smartphone Security- Attack and Defence Techniques. Computer and Cyber Security: Principles, Algorithm, Applications and Perspectives, CRC Press, Taylor & Francis. (Accepted, In press) (Book Chapter)
2017
-
[103]
A Content based Approach for Detecting Smishing Attack in Mobile Environment
Diksha Goel and Ankit Kumar Jain, (2018). A Content based Approach for Detecting Smishing Attack in Mobile Environment. Journal of Ambient Intelligence & Humanized Computing (AIHC), Springer. (Under Review) (SCI- Indexed) (Impact Factor: 1.588)
2018
Reviewed August 10, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.