In the field of computer security,
phishing is the
criminally fraudulent process of attempting to acquire sensitive information such as usernames,
passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites (
YouTube,
Facebook,
MySpace), auction sites (
eBay),
online banks (
Wells Fargo,
Bank of America,
Chase), online payment processors (
PayPal), or IT Administrators (
Yahoo,
ISPs, corporate) are commonly used to lure the unsuspecting. Phishing is typically carried out by
e-mail or
instant messaging,<sup id="cite_ref-0" class="reference">
[1]</sup> and it often directs users to enter details at a fake website whose
look and feel are almost identical to the legitimate one. Even when using
server authentication it requires skill to detect that the website is fake. Phishing is an example of
social engineering techniques used to fool users <sup id="cite_ref-1" class="reference">
[2]</sup>, and exploits the poor usability of current web security technologies <sup id="cite_ref-Jos2007_2-0" class="reference">
[3]</sup>. Attempts to deal with the growing number of reported phishing incidents include
legislation, user training, public awareness, and technical security measures.