This document presents a theoretical model for evaluating phishing attacks based on the indistinguishability of natural and phishing message distributions. The model views a phishing attack as an attempt to generate messages that are indistinguishable from normal messages. It captures a phishing attack in terms of the statistical distance between the natural and phishing message probability distributions. The model also proposes metrics to analyze the success probability of phishing attacks and distinguisher algorithms. Finally, it discusses a new class of collaborative spear phishing attacks enabled by data breaches at large companies.
Related topics: