PhishingAgent: an agentic workflow method for advanced phishing email detection

To address the increasing complexity of advanced persistent threat (APT) and phishing email attacks, an intelligent agentic workflow method for phishing email detection called PhishingAgent was proposed. PhishingAgent integrated multi-source knowledge bases and security tools to fully leverage the r...

Full description

Saved in:
Bibliographic Details
Main Authors: JIN Jiandong, HUANG Zheng, HU Zhanyu, ZOU Yuanxin, QIN Huidong, LAI Qingnan, YANG Jia, ZHOU Changling
Format: Article
Language:zho
Published: Editorial Department of Journal on Communications 2024-11-01
Series:Tongxin xuebao
Subjects:
Online Access:http://www.joconline.com.cn/zh/article/doi/10.11959/j.issn.1000-436x.2024243/
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:To address the increasing complexity of advanced persistent threat (APT) and phishing email attacks, an intelligent agentic workflow method for phishing email detection called PhishingAgent was proposed. PhishingAgent integrated multi-source knowledge bases and security tools to fully leverage the reasoning capabilities of large language model (LLM), enhancing the precision and depth of identifying complex phishing email attacks. The agentic workflow was built on a dual-system reasoning framework, a rapid detection system facilitates efficient preliminary threat identification, followed by a deep reasoning system that conducted detailed semantic analysis and contextual inference, significantly improving the interpretability of results. Experimental results demonstrate that the PhishingAgent increases detection efficiency without sacrificing accuracy and outperforms existing mainstream email security mechanisms in detecting APT-related phishing emails.
ISSN:1000-436X