PhishingAgent: an agentic workflow method for advanced phishing email detection

To address the increasing complexity of advanced persistent threat (APT) and phishing email attacks, an intelligent agentic workflow method for phishing email detection called PhishingAgent was proposed. PhishingAgent integrated multi-source knowledge bases and security tools to fully leverage the r...

Full description

Saved in:
Bibliographic Details
Main Authors: JIN Jiandong, HUANG Zheng, HU Zhanyu, ZOU Yuanxin, QIN Huidong, LAI Qingnan, YANG Jia, ZHOU Changling
Format: Article
Language:zho
Published: Editorial Department of Journal on Communications 2024-11-01
Series:Tongxin xuebao
Subjects:
Online Access:http://www.joconline.com.cn/zh/article/doi/10.11959/j.issn.1000-436x.2024243/
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1841537092138565632
author JIN Jiandong
HUANG Zheng
HU Zhanyu
ZOU Yuanxin
QIN Huidong
LAI Qingnan
YANG Jia
ZHOU Changling
author_facet JIN Jiandong
HUANG Zheng
HU Zhanyu
ZOU Yuanxin
QIN Huidong
LAI Qingnan
YANG Jia
ZHOU Changling
author_sort JIN Jiandong
collection DOAJ
description To address the increasing complexity of advanced persistent threat (APT) and phishing email attacks, an intelligent agentic workflow method for phishing email detection called PhishingAgent was proposed. PhishingAgent integrated multi-source knowledge bases and security tools to fully leverage the reasoning capabilities of large language model (LLM), enhancing the precision and depth of identifying complex phishing email attacks. The agentic workflow was built on a dual-system reasoning framework, a rapid detection system facilitates efficient preliminary threat identification, followed by a deep reasoning system that conducted detailed semantic analysis and contextual inference, significantly improving the interpretability of results. Experimental results demonstrate that the PhishingAgent increases detection efficiency without sacrificing accuracy and outperforms existing mainstream email security mechanisms in detecting APT-related phishing emails.
format Article
id doaj-art-294476d342f4433aace024e7c6783c88
institution Kabale University
issn 1000-436X
language zho
publishDate 2024-11-01
publisher Editorial Department of Journal on Communications
record_format Article
series Tongxin xuebao
spelling doaj-art-294476d342f4433aace024e7c6783c882025-01-14T08:46:33ZzhoEditorial Department of Journal on CommunicationsTongxin xuebao1000-436X2024-11-0145596879661322PhishingAgent: an agentic workflow method for advanced phishing email detectionJIN JiandongHUANG ZhengHU ZhanyuZOU YuanxinQIN HuidongLAI QingnanYANG JiaZHOU ChanglingTo address the increasing complexity of advanced persistent threat (APT) and phishing email attacks, an intelligent agentic workflow method for phishing email detection called PhishingAgent was proposed. PhishingAgent integrated multi-source knowledge bases and security tools to fully leverage the reasoning capabilities of large language model (LLM), enhancing the precision and depth of identifying complex phishing email attacks. The agentic workflow was built on a dual-system reasoning framework, a rapid detection system facilitates efficient preliminary threat identification, followed by a deep reasoning system that conducted detailed semantic analysis and contextual inference, significantly improving the interpretability of results. Experimental results demonstrate that the PhishingAgent increases detection efficiency without sacrificing accuracy and outperforms existing mainstream email security mechanisms in detecting APT-related phishing emails.http://www.joconline.com.cn/zh/article/doi/10.11959/j.issn.1000-436x.2024243/phishing emailLLMagentic workflowdual-system reasoning
spellingShingle JIN Jiandong
HUANG Zheng
HU Zhanyu
ZOU Yuanxin
QIN Huidong
LAI Qingnan
YANG Jia
ZHOU Changling
PhishingAgent: an agentic workflow method for advanced phishing email detection
Tongxin xuebao
phishing email
LLM
agentic workflow
dual-system reasoning
title PhishingAgent: an agentic workflow method for advanced phishing email detection
title_full PhishingAgent: an agentic workflow method for advanced phishing email detection
title_fullStr PhishingAgent: an agentic workflow method for advanced phishing email detection
title_full_unstemmed PhishingAgent: an agentic workflow method for advanced phishing email detection
title_short PhishingAgent: an agentic workflow method for advanced phishing email detection
title_sort phishingagent an agentic workflow method for advanced phishing email detection
topic phishing email
LLM
agentic workflow
dual-system reasoning
url http://www.joconline.com.cn/zh/article/doi/10.11959/j.issn.1000-436x.2024243/
work_keys_str_mv AT jinjiandong phishingagentanagenticworkflowmethodforadvancedphishingemaildetection
AT huangzheng phishingagentanagenticworkflowmethodforadvancedphishingemaildetection
AT huzhanyu phishingagentanagenticworkflowmethodforadvancedphishingemaildetection
AT zouyuanxin phishingagentanagenticworkflowmethodforadvancedphishingemaildetection
AT qinhuidong phishingagentanagenticworkflowmethodforadvancedphishingemaildetection
AT laiqingnan phishingagentanagenticworkflowmethodforadvancedphishingemaildetection
AT yangjia phishingagentanagenticworkflowmethodforadvancedphishingemaildetection
AT zhouchangling phishingagentanagenticworkflowmethodforadvancedphishingemaildetection