Phishing jako služba: Analýza, implementace, simulace a návrh bezpečnostních opatření

dc.contributor.advisorŘezáč, Filip
dc.contributor.authorKarp, Ondřej
dc.contributor.refereeKapičák, Lukáš
dc.date.accepted2026-06-03
dc.date.accessioned2026-09-02T14:41:18Z
dc.date.available2026-09-02T14:41:18Z
dc.date.issued2026
dc.description.abstractDiplomová práce se zabývá problematikou phishingových útoků se zaměřením na moderní koncept Phishing jako služba (Phishing as a Service, PhaaS), který v současnosti představuje jednu z nejrychleji se rozvíjejících hrozeb v oblasti kybernetické bezpečnosti. Tento model umožňuje realizaci sofistikovaných phishingových kampaní i aktérům bez hlubších technických znalostí, čímž výrazně zvyšuje dostupnost a škálovatelnost útoků. Teoretická část práce se věnuje analýze phishingu v kontextu sociálního inženýrství, jeho historickému vývoji a současným trendům, včetně automatizace útoků a využití pokročilých technologií. Důraz je kladen na charakteristické vlastnosti PhaaS platforem a jejich roli v ekosystému kybernetické kriminality. Praktická část práce se zaměřuje na návrh a implementaci uzavřeného testovacího prostředí pro simulaci phishingových útoků typu PhaaS. V tomto prostředí jsou realizovány modelové scénáře útoků, jejichž cílem je analyzovat chování obětí, identifikovat klíčová bezpečnostní rizika a vyhodnotit dopady těchto útoků. Na základě provedené bezpečnostní analýzy jsou následně formulována doporučení a bezpečnostní zásady směřující ke zvýšení odolnosti jednotlivců i organizací vůči phishingovým hrozbám. Výsledky práce poukazují na vysokou účinnost phishingových útoků v modelu PhaaS a potvrzují nutnost kombinace technických opatření, organizačních procesů a systematického vzdělávání uživatelů jako základního pilíře moderní kybernetické bezpečnosti.cs
dc.description.abstractThis Master’s thesis addresses the issue of phishing attacks, with a specific focus on the modern concept of Phishing as a Service (PhaaS), which currently represents one of the fastest-growing threats in the field of cybersecurity. This model enables even actors without profound technical knowledge to execute sophisticated phishing campaigns, significantly increasing the accessibility and scalability of such attacks. The theoretical part of the thesis analyzes phishing within the context of social engineering, its historical development, and current trends, including attack automation and the use of advanced technologies. Emphasis is placed on the characteristic features of PhaaS platforms and their role within the cybercrime ecosystem. The practical part focuses on the design and implementation of a closed testing environment for simulating PhaaS-type phishing attacks. Model attack scenarios are conducted within this environment to analyze victim behavior, identify key security risks, and evaluate the impact of these attacks. Based on the conducted security analysis, recommendations and security principles are subsequently formulated to increase the resilience of individuals and organizations against phishing threats. The results of the thesis highlight the high effectiveness of phishing attacks under the PhaaS model and confirm the necessity of combining technical measures, organizational processes, and systematic user education as a fundamental pillar of modern cybersecurity.en
dc.description.department460 - Katedra informatikycs
dc.description.resultvýborněcs
dc.format.extent2771375 bytes
dc.format.mimetypeapplication/pdf
dc.identifier.otherOSD002
dc.identifier.senderS2724
dc.identifier.thesisKAR0326_FEI_N0612A140004_2026
dc.identifier.urihttp://hdl.handle.net/10084/160818
dc.language.isocs
dc.publisherVysoká škola báňská – Technická univerzita Ostravacs
dc.rights.accessopenAccess
dc.subjectPhishingcs
dc.subjectPhishing jako službacs
dc.subjectPhaaScs
dc.subjectsociální inženýrstvícs
dc.subjectkybernetická bezpečnostcs
dc.subjectsimulace útokůcs
dc.subjectbezpečnostní analýzacs
dc.subjectvícefaktorová autentizacecs
dc.subjectútok vprostředcs
dc.subjectEvilginxcs
dc.subjectGophishcs
dc.subjectZphishercs
dc.subjectFIDO2cs
dc.subjectnulová důvěra.cs
dc.subjectPhishingen
dc.subjectPhishing as a Serviceen
dc.subjectPhaaSen
dc.subjectsocial engineeringen
dc.subjectcybersecurityen
dc.subjectattack simulationen
dc.subjectsecurity analysisen
dc.subjectmulti-factor authenticationen
dc.subjectman-in-the-middleen
dc.subjectEvilginxen
dc.subjectGophishen
dc.subjectZphisheren
dc.subjectFIDO2en
dc.subjectzero trust.en
dc.thesis.degree-grantorVysoká škola báňská – Technická univerzita Ostrava. Fakulta elektrotechniky a informatikycs
dc.thesis.degree-levelMagisterský studijní programcs
dc.thesis.degree-nameIng.
dc.thesis.degree-programInformační a komunikační bezpečnostcs
dc.titlePhishing jako služba: Analýza, implementace, simulace a návrh bezpečnostních opatřenícs
dc.title.alternativePhishing as a Service: Analysis, Implementation, Simulation and Design of Security Measuresen
dc.typeDiplomová prácecs
local.files.count6
local.files.size3324769
local.has.filesyes

Files

Original bundle

Now showing 1 - 5 out of 6 results
Loading...
Thumbnail Image
Name:
KAR0326_FEI_N0612A140004_2026.pdf
Size:
2.64 MB
Format:
Adobe Portable Document Format
Description:
Text práce
Loading...
Thumbnail Image
Name:
KAR0326_FEI_N0612A140004_2026_zadani.pdf
Size:
154.78 KB
Format:
Adobe Portable Document Format
Description:
Zadání
Loading...
Thumbnail Image
Name:
KAR0326_FEI_N0612A140004_2026_priloha.zip
Size:
1.16 KB
Format:
ZIP
Description:
Příloha
Loading...
Thumbnail Image
Name:
KAR0326_FEI_N0612A140004_2026_posudek_vedouci_Rezac_Filip.pdf
Size:
161.86 KB
Format:
Adobe Portable Document Format
Description:
Posudek vedoucího – Řezáč, Filip
Loading...
Thumbnail Image
Name:
KAR0326_FEI_N0612A140004_2026_posudek_oponent_Kapicak_Lukas.pdf
Size:
160.5 KB
Format:
Adobe Portable Document Format
Description:
Posudek oponenta – Kapičák, Lukáš