Digitala Vetenskapliga Arkivet

Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Texted into Trouble: A Qualitative Case Study of Smishing Attacks and Countermeasures in a Swedish Public Authority
Högskolan i Skövde, Institutionen för informationsteknologi.
2025 (engelsk)Independent thesis Advanced level (degree of Master (Two Years)), 20 poäng / 30 hpOppgave
Abstract [en]

Smishing, which is SMS phishing, exploits the immediacy and presumed trust of mobile communication and is therefore a significant and emerging cyber threat. It is of specific concern to public-sector organisations that are using the Short Message Service (SMS) channel to engage with citizens more frequently. The SMS channel also possesses inherent vulnerabilities, such as weak sender authentication procedures and an almost complete dependence on telecommunication operators to filter appropriately. They are security controls difficult for organisations to implement on their own with technical countermeasures, in contrast to their potential for email security. This research examines current smishing attack methods and potential countermeasures via a mixed-methods approach, involving a systematic literature review (SLR) and a qualitative case study of a Swedish public authority. SLR showed advanced attack methods taking advantage of user psychology and system weaknesses and a high number of theoretical technical countermeasures such as machine learning classifiers and human-centred ones. In spite of them, semi-structured interviews with five security professionals in the authority under the investigation showed a wide gap between such theoretical solutions and actual deployment. Findings show the authority uses mostly generalised user awareness campaigns and incident reporting mechanisms. Although the authority is aware of intrinsic SMS vulnerabilities, there is limited adoption by the authority of advanced technical defences or smishing-specific training. This seems primarily because of perceived technical constraints in safeguarding the SMS channel as opposed to email, a deficiency of telecom operators' defined role in channel security, possible under-reporting of attacks, and a persistent challenge with keeping up with the speedy evolution of smishing techniques. This research highlights the essential importance of a multi-stranded approach that actively accepts the inherent limitations of SMS security. In order to provide a sufficient level of protection of communications channels and preserve public trust, this approach will need to combine reasonable technical controls (frequently operator-specific), organisational policies that are explicit, and frequent intensive user education on both the particular vulnerabilities of SMS and human vulnerabilities being used by these threats in the public arena.

sted, utgiver, år, opplag, sider
2025. , s. 37
Emneord [en]
Smishing, SMS Security, Public Sector, Cybersecurity, Operator Dependency, User Awareness
HSV kategori
Identifikatorer
URN: urn:nbn:se:his:diva-25262OAI: oai:DiVA.org:his-25262DiVA, id: diva2:1972379
Fag / kurs
Informationsteknologi
Utdanningsprogram
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Examiner
Tilgjengelig fra: 2025-06-18 Laget: 2025-06-18 Sist oppdatert: 2025-09-29bibliografisk kontrollert

Open Access i DiVA

Fulltekst mangler i DiVA

Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric

urn-nbn
Totalt: 81 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf