Phishing jako služba: Analýza, implementace, simulace a návrh bezpečnostních opatření

Abstract

This Master’s thesis addresses the issue of phishing attacks, with a specific focus on the modern concept of Phishing as a Service (PhaaS), which currently represents one of the fastest-growing threats in the field of cybersecurity. This model enables even actors without profound technical knowledge to execute sophisticated phishing campaigns, significantly increasing the accessibility and scalability of such attacks. The theoretical part of the thesis analyzes phishing within the context of social engineering, its historical development, and current trends, including attack automation and the use of advanced technologies. Emphasis is placed on the characteristic features of PhaaS platforms and their role within the cybercrime ecosystem. The practical part focuses on the design and implementation of a closed testing environment for simulating PhaaS-type phishing attacks. Model attack scenarios are conducted within this environment to analyze victim behavior, identify key security risks, and evaluate the impact of these attacks. Based on the conducted security analysis, recommendations and security principles are subsequently formulated to increase the resilience of individuals and organizations against phishing threats. The results of the thesis highlight the high effectiveness of phishing attacks under the PhaaS model and confirm the necessity of combining technical measures, organizational processes, and systematic user education as a fundamental pillar of modern cybersecurity.

Description

Delayed publication

Available after

Subject(s)

Phishing, Phishing as a Service, PhaaS, social engineering, cybersecurity, attack simulation, security analysis, multi-factor authentication, man-in-the-middle, Evilginx, Gophish, Zphisher, FIDO2, zero trust.

Citation