TRUST: Threat Reduction via Understanding Subjective Treatment
ID: e615bdfd-6b34-5c19-a4c4-f32b9b7330e6
STIX ID: report--e615bdfd-6b34-5c19-a4c4-f32b9b7330e6
Feed Name: Security Ledger
This article argues that defenses should shift from solely identifying deceptive email content to modeling what is familiar and truthful for an organization (a "TRUST" model). It proposes baselining legitimate email headers, classifying mail types and attachment behavior, and applying file-behavior analysis (fuzzy hashing, entropy, temporal/frequency measures) to detect phishing and malware more effectively, while noting existing technologies like SPF/DKIM/DMARC are insufficient alone.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
