Detecting Phishing Campaigns Through Behavioral Analysis of Email Metadata

Авторы

Ключевые слова:

phishing detection, email security, behavioral analysis, metadata analysis, cybersecurity

Аннотация

Phishing campaigns increasingly evade content-based detection filters by varying message text while preserving underlying sending infrastructure and behavioral patterns, motivating detection approaches that examine metadata rather than message content alone. This study develops a behavioral detection framework analyzing email metadata features, including sending time patterns, header inconsistencies, and relay path irregularities, to identify coordinated phishing campaigns across an organizational email corpus. Rather than classifying individual messages in isolation, the approach clusters messages exhibiting correlated metadata signatures to identify campaign-level patterns that individual message classifiers frequently miss, particularly for low-volume targeted campaigns designed to avoid triggering volume-based anomaly thresholds. We evaluate the framework against a labeled dataset combining confirmed phishing incidents with legitimate email traffic, comparing detection performance against a content-based baseline classifier under conditions simulating adversarial message text variation. Results show that the behavioral metadata approach maintained substantially more stable detection performance under text variation conditions where the content-based baseline degraded considerably, indicating greater robustness to evasion attempts targeting message content specifically. We discuss deployment considerations for integrating metadata-based campaign detection alongside existing content filtering within enterprise email security pipelines without introducing excessive false positive burden for security analysts.

##plugins.generic.certificates.share##

Опубликован

2026-07-20

Выпуск

Раздел

Cybersecurity

Как цитировать

Detecting Phishing Campaigns Through Behavioral Analysis of Email Metadata. (2026). Krakow International Conference on Computer Science and Cybersecurity, 1(1), 3-10. https://vistulaconf.org/index.php/kiccs/article/view/10