Phishing jako služba: Analýza, implementace, simulace a návrh bezpečnostních opatření
| dc.contributor.advisor | Řezáč, Filip | |
| dc.contributor.author | Karp, Ondřej | |
| dc.contributor.referee | Kapičák, Lukáš | |
| dc.date.accepted | 2026-06-03 | |
| dc.date.accessioned | 2026-09-02T14:41:18Z | |
| dc.date.available | 2026-09-02T14:41:18Z | |
| dc.date.issued | 2026 | |
| dc.description.abstract | Diplomová práce se zabývá problematikou phishingových útoků se zaměřením na moderní koncept Phishing jako služba (Phishing as a Service, PhaaS), který v současnosti představuje jednu z nejrychleji se rozvíjejících hrozeb v oblasti kybernetické bezpečnosti. Tento model umožňuje realizaci sofistikovaných phishingových kampaní i aktérům bez hlubších technických znalostí, čímž výrazně zvyšuje dostupnost a škálovatelnost útoků. Teoretická část práce se věnuje analýze phishingu v kontextu sociálního inženýrství, jeho historickému vývoji a současným trendům, včetně automatizace útoků a využití pokročilých technologií. Důraz je kladen na charakteristické vlastnosti PhaaS platforem a jejich roli v ekosystému kybernetické kriminality. Praktická část práce se zaměřuje na návrh a implementaci uzavřeného testovacího prostředí pro simulaci phishingových útoků typu PhaaS. V tomto prostředí jsou realizovány modelové scénáře útoků, jejichž cílem je analyzovat chování obětí, identifikovat klíčová bezpečnostní rizika a vyhodnotit dopady těchto útoků. Na základě provedené bezpečnostní analýzy jsou následně formulována doporučení a bezpečnostní zásady směřující ke zvýšení odolnosti jednotlivců i organizací vůči phishingovým hrozbám. Výsledky práce poukazují na vysokou účinnost phishingových útoků v modelu PhaaS a potvrzují nutnost kombinace technických opatření, organizačních procesů a systematického vzdělávání uživatelů jako základního pilíře moderní kybernetické bezpečnosti. | cs |
| dc.description.abstract | This Master’s thesis addresses the issue of phishing attacks, with a specific focus on the modern concept of Phishing as a Service (PhaaS), which currently represents one of the fastest-growing threats in the field of cybersecurity. This model enables even actors without profound technical knowledge to execute sophisticated phishing campaigns, significantly increasing the accessibility and scalability of such attacks. The theoretical part of the thesis analyzes phishing within the context of social engineering, its historical development, and current trends, including attack automation and the use of advanced technologies. Emphasis is placed on the characteristic features of PhaaS platforms and their role within the cybercrime ecosystem. The practical part focuses on the design and implementation of a closed testing environment for simulating PhaaS-type phishing attacks. Model attack scenarios are conducted within this environment to analyze victim behavior, identify key security risks, and evaluate the impact of these attacks. Based on the conducted security analysis, recommendations and security principles are subsequently formulated to increase the resilience of individuals and organizations against phishing threats. The results of the thesis highlight the high effectiveness of phishing attacks under the PhaaS model and confirm the necessity of combining technical measures, organizational processes, and systematic user education as a fundamental pillar of modern cybersecurity. | en |
| dc.description.department | 460 - Katedra informatiky | cs |
| dc.description.result | výborně | cs |
| dc.format.extent | 2771375 bytes | |
| dc.format.mimetype | application/pdf | |
| dc.identifier.other | OSD002 | |
| dc.identifier.sender | S2724 | |
| dc.identifier.thesis | KAR0326_FEI_N0612A140004_2026 | |
| dc.identifier.uri | http://hdl.handle.net/10084/160818 | |
| dc.language.iso | cs | |
| dc.publisher | Vysoká škola báňská – Technická univerzita Ostrava | cs |
| dc.rights.access | openAccess | |
| dc.subject | Phishing | cs |
| dc.subject | Phishing jako služba | cs |
| dc.subject | PhaaS | cs |
| dc.subject | sociální inženýrství | cs |
| dc.subject | kybernetická bezpečnost | cs |
| dc.subject | simulace útoků | cs |
| dc.subject | bezpečnostní analýza | cs |
| dc.subject | vícefaktorová autentizace | cs |
| dc.subject | útok vprostřed | cs |
| dc.subject | Evilginx | cs |
| dc.subject | Gophish | cs |
| dc.subject | Zphisher | cs |
| dc.subject | FIDO2 | cs |
| dc.subject | nulová důvěra. | cs |
| dc.subject | Phishing | en |
| dc.subject | Phishing as a Service | en |
| dc.subject | PhaaS | en |
| dc.subject | social engineering | en |
| dc.subject | cybersecurity | en |
| dc.subject | attack simulation | en |
| dc.subject | security analysis | en |
| dc.subject | multi-factor authentication | en |
| dc.subject | man-in-the-middle | en |
| dc.subject | Evilginx | en |
| dc.subject | Gophish | en |
| dc.subject | Zphisher | en |
| dc.subject | FIDO2 | en |
| dc.subject | zero trust. | en |
| dc.thesis.degree-grantor | Vysoká škola báňská – Technická univerzita Ostrava. Fakulta elektrotechniky a informatiky | cs |
| dc.thesis.degree-level | Magisterský studijní program | cs |
| dc.thesis.degree-name | Ing. | |
| dc.thesis.degree-program | Informační a komunikační bezpečnost | cs |
| dc.title | Phishing jako služba: Analýza, implementace, simulace a návrh bezpečnostních opatření | cs |
| dc.title.alternative | Phishing as a Service: Analysis, Implementation, Simulation and Design of Security Measures | en |
| dc.type | Diplomová práce | cs |
| local.files.count | 6 | |
| local.files.size | 3324769 | |
| local.has.files | yes |
Files
Original bundle
1 - 5 out of 6 results
Loading...
- Name:
- KAR0326_FEI_N0612A140004_2026.pdf
- Size:
- 2.64 MB
- Format:
- Adobe Portable Document Format
- Description:
- Text práce
Loading...
- Name:
- KAR0326_FEI_N0612A140004_2026_zadani.pdf
- Size:
- 154.78 KB
- Format:
- Adobe Portable Document Format
- Description:
- Zadání
Loading...
- Name:
- KAR0326_FEI_N0612A140004_2026_priloha.zip
- Size:
- 1.16 KB
- Format:
- ZIP
- Description:
- Příloha
Loading...
- Name:
- KAR0326_FEI_N0612A140004_2026_posudek_vedouci_Rezac_Filip.pdf
- Size:
- 161.86 KB
- Format:
- Adobe Portable Document Format
- Description:
- Posudek vedoucího – Řezáč, Filip
Loading...
- Name:
- KAR0326_FEI_N0612A140004_2026_posudek_oponent_Kapicak_Lukas.pdf
- Size:
- 160.5 KB
- Format:
- Adobe Portable Document Format
- Description:
- Posudek oponenta – Kapičák, Lukáš