Email remains a central communication medium, yet its long-standing design and interface conventions continue to enable deceptive attacks. This research note presents a structured list of 42 email-based deception techniques, documented with 64 concrete example implementations, organized around the sender, link, and attachment security indicators as well as techniques targeting the email rendering environment. Building on a prior systematic literature review, we consolidate previously reported techniques with newly developed example implementations and introduce novel deception techniques identified through our own examination. Rather than assessing effectiveness or real-world severity, each entry explains the underlying mechanism in isolation, separating the high-level deception goal from its concrete technical implementation. The documented techniques serve as modular building blocks and a structured reference for future work on countermeasures across infrastructure, email client design, and security awareness, supporting researchers as well as developers, operators, and designers working in these areas.
翻译:电子邮件依然是核心的通信媒介,但其长期的设计和界面惯例持续助长着欺骗性攻击。本研究笔记提出了一份包含42种基于电子邮件的欺骗技术的结构化清单,并记录了64个具体的实施示例,这些技术围绕发件人、链接和附件安全指标,以及针对电子邮件渲染环境的技术进行组织。在先前系统性文献综述的基础上,我们整合了先前报告的技术与新开发的示例实施,并引入了通过自身审查发现的新型欺骗技术。每项条目未评估有效性或现实世界中的严重性,而是单独解释了其底层机制,将高层欺骗目标与其具体技术实施区分开来。所记录的技术作为模块化构建块和结构化参考,服务于基础设施、电子邮件客户端设计及安全认知领域的未来对抗措施工作,为研究人员以及从事这些领域的开发人员、运营人员和设计师提供支持。