<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <issn pub-type="ppub">1613-0073</issn>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Toward a phishing attack ontology</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>ÍtaloOliveir</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Rodrigo F.Calha u</string-name>
          <email>alhau@ifes.edu.b</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>GiancarloGuizzard</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Conceptual and Cognitive Modeling Research Group (CORE), Free University of Bozen-Bolzano</institution>
          ,
          <addr-line>Bolzano</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Ontology &amp; Conceptual Modeling Research Group (NEMO), Federal University of Espírito Santo</institution>
          ,
          <addr-line>Vitória</addr-line>
          ,
          <country country="BR">Brazil</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Project Exhibitions</institution>
          ,
          <addr-line>Posters and Demos, and Doctoral Consortium</addr-line>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Semantics, Cybersecurity &amp; Services Group, University of Twente</institution>
          ,
          <addr-line>Enschede</addr-line>
          ,
          <country country="NL">Netherlands</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Phishing attacks are the most common form of social engineering where attackers intend to deceive targeted people into revealing sensitive information or installing malware. To understand the dynamics of phishing attacks and design suitable countermeasures, particularly the promotion of phishing awareness, cybersecurity researchers have proposed several domain conceptual models and lightweight ontologies. Despite the growing literature in ontology engineering highlighting the advantages of employing upper and reference ontologies for domain modeling, current phishing attack models lack ontological foundations. As a result, they sufer from a number of shortcomings, such as false agreements, informality, and limited interoperability. To address this gap, we proPpohissehiang Attack Ontology (PHATO) grounded in thReeference Ontology for Security Engineering (ROSE) and theCommon Ontology of Value and Risk (COVER), which are both founded in tUhneified Foundational Ontology represented through the OntoUML ontology-driven conceptual modeling language, benefiting from its ecosystem of tools and domain ontologies. We also discuss some implications of PHATO for the design of anti-phishing countermeasures.</p>
      </abstract>
      <kwd-group>
        <kwd>phishing attack</kwd>
        <kwd>social engineering</kwd>
        <kwd>cybersecurity</kwd>
        <kwd>phishing attack ontology</kwd>
        <kwd>reference ontology for</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>CEUR
ceur-ws.org</p>
    </sec>
    <sec id="sec-2">
      <title>1. Introduction</title>
      <p>In cybersecurity, social engineering is a type of attack in which the attacker exploits human
vulnerabilities to breach security goals (confidentiality, integrity, availab1il].itPyh, iesthci.n)g[
attacks are the most common form of social engineering where attackers intend to deceive
targeted people into revealing sensitive information or installing2m].aIlnw2a0r2e2,[the
Internet Crime Complaint Center of FBI (Federal Bureau of Investigation) reported more incidents
of phishing than any other type of computer crime in the2U]..ST.h[e same report defines
phishing as “The use of unsolicited email, text messages, and telephone calls purportedly from
LGOBE
(G. Guizzardi)
https://people.utwente.nl/g.guizza(Grd.iGuizzardi)
CEUR
Workshop
Proceedings
https://people.utwente.nl/i.j.dasilvaoli(vÍ.eiOrlaiveira)h;ttps://people.utwente.nl/r.cal(hRa.Fu. Calhau);
© 2023 Copyright for this paper by its authors. Use permitted under Creative Commons License Attribution 4.0 International (CC BY 4.0).
a legitimate company requesting personal, financial, and/or login crede2n]t.iIatliss”c[lear that
phishing attacks involve diferent ways of combining technical and social elements.</p>
      <p>
        Because of that, to understand the dynamics of phishing attacks and design appropriate
countermeasures, such as phishing awareness training, cybersecurity researchers have proposed
several domain conceptual models, lightweight ontologies, and informal conceptualizations
of phishing 3[
        <xref ref-type="bibr" rid="ref4 ref5 ref6 ref7 ref8">, 4, 5, 6, 7, 8, 9, 10</xref>
        ]. Despite the growing literature in ontology engineering
highlighting the advantages of employing upper and reference ontologies for domain modeling,
all current phishing attack models lack explicit ontological foundations.
      </p>
      <p>A foundational (top-level or upper) ontology is a specific consistent set of ontological theories,
capable of providing support to the tasks of domain analysis, conceptual clarification, and
meaning negotiation — that are critical when one has to build an ontology as a computational
artifact11[]. There is evidence that top-level ontologies help with the development of
highquality core and domain ontologies, improving their consistency and interop1e2r]a.bAility [
(well-founded) core ontology specifies, under a foundational ontology, the central concepts and
relations of a given domain (e.g., Risk, Value, Trust, Security, etc.). Upper ontologies efectively
contribute to detecting and preventing ontology design m1is3t],aeknehsa[ncing the quality and
interoperability of domain and core ontolo1g4i]e.sT[he following analogy helps to clarify this
point: foundational ontologies and reference domain ontologiesowntoorlokgyasengineering
frameworks, by accelerating and improving the practice of ontology engineering, just like web
development frameworks (e.g., React, Angular, Django, etc.) accelerate and improve the practice
of web development.</p>
      <p>As a result of that lack of explicit foundations, existing phishing ontologies may sufer from a
number of known shortcomings, such as false agreements, informality, limited interoperability,
and unintended instances. At minimum, the guidance provided by a foundational ontology can
improve domain ontologies in these respects as shown, for instan1c5e], ibny r[elation to a
popular cybersecurity ontology written in OWL. To address this gap, we prPohpisohsienga
Attack Ontology (PHATO)1, a well-founded phishing model, grounded inRtehfeerence Ontology
for Security Engineering (ROSE) [16] and theCommon Ontology of Value and Risk (COVER)
[17], which are both founded in tUhneified Foundational Ontology (UFO) [18]. Our proposal is
represented through the OntoUML ontology-driven conceptual modeling language, benefiting
from its ecosystem of tools and domain ontologies. We also discuss some implications of PHATO
for the design of anti-phishing countermeasures.</p>
      <p>The remainder of this paper is structured as follows: S2ecptrieosnents several common
elements about phishing attacks that will be helpful to support our proposa3lp.rSeescetnitosn
our ontological foundations with regard to the domains of value, risk, and security. Section
4 presents the main contributionPsh:iashing Attack Ontology (PHATO). The same Section4
briefly discusses some implications for the design of anti-phishing countermeasures. S5ection
debates related work. Sect6i ofinnishes with limitations and future work.
1The acronym plays with two related ideas: in Portuguese, “phato” - when the ‘ph’ is pronouned like an ‘f’ - sounds
like “fato”fa(ct, in English); when it is pronounced or like a ‘p’, it sounds like “dpuactko),” w(hich is a brazilian
slang for gullible. Both senses come together in the idea that phishing involves lying about facts to deceive a target.</p>
    </sec>
    <sec id="sec-3">
      <title>2. Elements of phishing attacks in cybersecurity</title>
      <p>Phishing is a form of social engineering attack, along with baiting, pretexting, tailgating,
ransomware, impersonation on the help desk, diversion theft, dumpster diving, shoulder surfing,
Quid Pro Quo, pop-up windows, robocalls, reserve social engineering, online social engineering,
phone social engineering, stealing important documents, fake software, pharming, SMSishing,
whitelisting flow1[9], and potentially others.</p>
      <p>
        The word “phishing” is a variation of the term “fishing” where the act of phishing resembles
that of fishing in the following sense: the attacker lures a victim by using a sort of bait, then
ifshes for personal or confidential information from the vic2t0im]. [Jakobsson 2[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] describes it
as the “marriage of technology and social engineering”, remarking that successful attacks use
both of these components in a strategic manner. Because of that, to prevent phishing attempts
and their consequences, one should understand both elements.
      </p>
      <p>There are many definitions of phishing in the literature (for a list with 113 distinct definitions,
see [10]). According to this study, phishing can be defined as a “scalable act of deception
whereby impersonation is used to obtain information from a ta1r0]g.eTt”he[ attacker can
utilize various channels (emails, instant messages, voice calls, etc.) to either deceive the victim
directly by a scam or to deliver payload through an indirect manner with the goal of obtaining
personal or confidential information (login, passwords, bank account number, etc.) from the
victim [20]. Sometimes, phishing involves tricking people into making them install malware,
such as ransomware, which, then, will enable the stealing of confidential information or other
asset. The damage caused by successful phishing attacks includes not only financial loss but
also loss of reputation, fines from regulations, reduced productivity, intellectual property theft,
and national security risk, afecting individuals, companies, and states.</p>
      <p>Because phishing attacks cleverly exphluomitan vulnerabilities, they can circumvent the vast
majority of an organization’s or individual’s security measures. As 2p2u]t, ibtyd[oesn’t matter
how many firewalls, encryption software, certificates, or two-factor authentication mechanisms
an organization has if the person behind the keyboard falls for a phish.23W, 5a]negnsu[merates
(non-exhaustively) many vulnerabilities according to the following classification:
• Cognition and Knowledge: Ignorance, inexperience, thinking set and stereotyping,
prejudice or bias, conformity, intuitive judgment, low level of need for cognition, heuristics,
and mental shortcuts.
• Behavior and Habit: Laziness, carelessness and thoughtlessness, fixed-action patterns,
habitual behaviors.
• Emotions and Feelings: Fear, curiosity, anger, excitement, tension, happiness, sadness,
disgust, surprise, guilt, impulsion, fluke mind.
• Human nature: Self-love, sympathy, helpfulness, greed, gluttony, lust.
• Personality traits: Conscientiousness, extraversion, agreeableness, openness,
neuroticism.
• Individual characters: Credulity, friendliness, kindness and charity, courtesy, humility,
difidence, apathy, hubris, envy.</p>
      <p>
        According to2[
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], the most common form of phishing attacks includes three key components:
thelure, thehook, and thecatch. The lure consists of a phisher spamming a large number of
users with an email message that appears to be from some legitimate institution that has a
presence on the Internet. The message often uses a convincing story to encourage the user
to follow a URL hyperlink embedded in the email to a website controlled by the phisher and
to provide it with certain requested information. The social engineering aspect of phishing
attacks typically makes itself known in the lure, as the spam ofers some plausible reason for
the user to provide confidential information to the website that is hyperlinked by the spam.
The hook commonly consists of a website that imitates the appearance of a reputable agent
(say, a famous company’s website). The goal of the hook is for victims to be directed to it via
the lure portion of the attack and for the victims to disclose confidential information to the site.
The catch involves the phisher making use of the collected information for some illegal purpose
such as fraud or identity theft.
      </p>
      <p>Phishing attacks can be classified in diferent ways (see, for insta9n]c).e,F[requently, the
literature mentions “spear phishing” when the decoy is personalized to trick a specific individual
or organization; “whaling phishing” when the attacker targets specifically senior executives or
high-profile individuals; “vishing phishing” occurs if the attacks are performed via voice over
the internet protocol (VoIP); “interactive voice response phishing” is performed by using an
interactive voice response system to make the target enter the private information as if it is
from a legitimate business or bank. “Business Email Compromise Phishing” mimics the whaling
by targeting big “fishes” in corporate businesses in order to get access to their business emails,
calendars, payments, accounting, or other private inform1a9t]ion. [</p>
    </sec>
    <sec id="sec-4">
      <title>3. Background: value, risk, and security</title>
      <p>The Unified Foundational Ontology (UFO) is a domain-independent axiomatic theory developed
to contribute to the foundations of Conceptual Mo2d5e,l1i8n]g. I[t is one of the most used
foundational ontologies in conceptual mode2l6i]n,gan[d it has been successfully employed in
many projects in diferent countries, by academic, government, and industrial institutions in the
development of core and domain ontologies in diferent domains (e.g., Trust, legal relations and
Constitutional Law, Risk and Value, Service, Software Requirements and Anomalies, Discrete
Event Simulation, etc2.)5[]. For our purposes, it sufices to say ontological distinctions of UFO
are built-in OntoUML general-purpose modeling language. This means that OntoUML models
are created by the iterative instantiation of ontology design patterns, each of which represents
a UFO micro-theory.</p>
      <p>
        Taking into consideration risk treatment options defined by ISO 3100R0e,fterheence Ontology
for Security Engineering (ROSE) [16] describes the general entities and relations of the security
engineering domain, making use of an adapted version oCfotmhemon Ontology of Value and
Risk (COVER) to capture the value and risk-related n2o. tRiOonSEs understands the domain of
security as thientersection between the domain of value and risk, understood under the terms
of the COVER 1[
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], and the dispositional theory of prevention present2e7d]. iTnh[e latter
extends UFO to explain how certain types of events are prevented or interrupted due to the
occurrence of other events of specific types. From this perspectivSee,caunrity Mechanism is
anObject (of any kind) purposely designed to create value by preveRnitsikngEvents.
2Files related to ROSE can be found in the following public repohstitopsr:y//:purl.org/security-onto.logy
      </p>
      <p>In COVER3, whose fragment is depicted in Figu1r,evalue is a relational mode that emerges
from the relations between the capacDitiisepso(sitions) of certain objects and tInhteentions
of anAgent. The manifestations of these capacitiesEavreents thatbring about a Situation
thatimpacts or satisfies theIntention of a givenAgent (a Value Subject)–in UFC-C, a goal is
understood as the propositional contentInotfeanntion [28], which is an internal commitment
that inheres in aAngent, which specializeOsbject. Risk is the anti-valuRei:sk Events are the
manifestations of certaDiinspositions (namely,Threat Capabilities andVulnerabilities),
and, sometimes,Intentions that inhere in aAngent; theseEvents bring about a Situation
thathurts theIntention of a givenAgent (a Risk Subject), as shown by Figure2. Analogous
to value, security (Figu3r)eis also a relational mode that emerges from the relations between
the (control) capabilitieOs bojfects and theIntentions of anAgent, particularlyParotected
Subject; however, manifestations of these capabilbirtiinegs about a Situation thatimpacts
theIntention of anAgent in a very specific way: preventing Risk events [16].</p>
      <p>Using the prevention theory described27i]n, R[OSE understands thTahtreat Capability,
Vulnerability, and, sometimes,Intention are dispositions associated with types whose
instances maintainmautual activation partnership to each oth4e.rThis means that Tahreat
3The OntoUML stereotype connects types and relations in these models to ontological categories of monadic and
relational universals in UFO, respectively. For their ontological justification and semantics, one sho1u8l].d refer to [
Moreover, the colors in these diagrams represent a color convention used by the OntoUML community: object
types are represented in pink, intrinsic aspect types in blue, situation types in orange, event types in yellow, and
higher-order types in darker blue.
4For simplicity, the diagram of Figu2roemits the mutual activation partnership relations bTehtrweeaetnCapability</p>
      <p>Object can only manifest itTshreat Capability if a Vulnerability can be exploited; if
theThreat Object participates in aAnttack (an Action, an intentionaElvent), then the
Intention is also required. AnalogouslVy,ualnerability is only manifested in the presence of
a Threat Capability. From a security point of view, the importance ofgtenheirsic dependence
relation among these entities is that it determines multiple ways by which security measures can
work: the removal of any of them from the situation that could activate them all together implies
the prevention of the associaRtiesdk Event. In general, mutual activation partners compose
the conditions of activation ofDainspyosition, as shown by Figure1. This relation generalizes
the role of enabler objecVtasl(ue Enabler, Risk Enabler, Threat Enabler, and so on), which
aggregate ancillaDriyspositions with regard tTohreat Capability, Vulnerability, etc.</p>
      <p>A Security Mechanism is always designed by aAngent called thSeecurity Designer
to be acountermeasure to events of a particular tyRpiesk( Event Type) [27, 16]. When an
Object is made to be a countermeasure to certain types of events, it aggregates capabilities
whose manifestations ultimately prevent tEhvesnet Types in a systematic fashion. The
Agent creating aSecurity Mechanism is not necessarily the one protected by its proper
functioning, i.e., thPerotected Subject. However, both agents haIvnetentions that are
positively impacted by this proper functioning. For example, the government designs policies
for public safety, and the functioning of such policies satisfies some goals the government had
when designing them but also satisfies the goal of people who want to be safe. Sometimes,
theProtected Subject is the sameAgent as theSecurity Designer, such as when a person
places an electric fence surrounding their own house.</p>
      <p>As shown in Figure3, a Security Mechanism is anObject, which may be a simple physical
object like a wall, a high-tech air defense systeAmg,eannt like a policeman, a social entity like
a security standard or anti-COVID-19 rules, that bears capabilitCieosnctarloleldCapabilities.
The manifestation of this kind of capabilityCoisnatrol Event, which may come in the form
of a chain of events that ultimately causCesotnhterol Event. The Control Event is of a
Type, Vulnerability Type, andIntention Type but Figure1 clearly states that types of dispositions hold that
relationship with each other.
type (Control Event Type) that prevents, directly or indirectly, events of a certaRiinsktype (
Event Type). This is so because thCeontrol Events bring about Caontrolled Situation,
which is of a type thatiniscompatible with the types ofSituations (Risk Trigger Type) that
triggerRisk Events of certain types.</p>
      <p>Notice thaCtontrol Capabilities may characterize not onlSyeacurity Mechanism but
also other objects. This means thaCtonatrol Event can be, for instance, a single action
that prevents certain typeRsioskf Events, although not in a systematic fashion. For instance,
when someone puts herself away from dangerous machines in a factory, she is manifesting
herControl Capabilities by avoiding the danger and, therefore, generating value for herself,
even though she is notSeacurity Mechanism. This is important to draw a distinction between
a Security Mechanism whose actions are systematic anCdoantrol Event that may be the
manifestation ofCaontrol Capability that does not inhere iSneacurity Mechanism.</p>
    </sec>
    <sec id="sec-5">
      <title>4. A phishing attack ontology (PHATO)</title>
      <p>Given the elements of phishing attacks described in Se2catniodnour ontological foundations
of Section3, we propose aPhishing Attack Ontology (PHATO)5 by specializing the concepts of
ROSE. Following this principle, we saSycaammer specializes anAttacker (a specialization of
Threat Object) andimpersonates anImpersonated Reputable Agent (a person, a company,
an organization, etc.).SAcammer has anIntention to Phish and the capability to do so,
anImpersonation Capability to Deceive Target, which specializeTshreat Capability.
It is clear that both intrinsic aspects are necessary for the manifestation of an event called
Impersonation of Reputable Agent to Deceive Target wherein aLure participates (a given</p>
      <sec id="sec-5-1">
        <title>5All related files of PHATO can be found aht:tps://github.com/utwente-scs/phishing-ontology</title>
        <p>email or SMS message, for example). Moreover, a third element must bSeitinuaation that can
trigger aPhishing Contribution: anExposure of an ancillary entity caPllheidshing Enabler
(for instance, the target’s phone number, email address, or computer network). In other words,
there is amutual activation partnership relation amonIgntention to Phish, Impersonation
Capability to Deceive Target, andExposure. They are ultimately manifested by a complex
event: aPhishing Attack, a specialization ofTahreat Event.</p>
        <p>At this point, human vulnerabilities usually do not play a major role yet. However, they are
essential for the manifestation oAfsasnet Catch, an event whereinHaook and, naturally,
anAsset participate. A number oTfarget’s Fragilities may be present in aVulnerability
Condition that triggerAssset Catches, i.e., anyone can fall for a phish under the right
conditionsA.sset Catches areLoss Events thathurt Target’s Intentions to preserve her
Assets (Value Objects, Object at Risk). A Target is clearly aRisk Subject.</p>
        <p>As described in Sectio2n, there are many human mental attitudes that can play the role of
a Target’s Fragilities, such asInnocence, Fear, Complacency, Desire to please, Greed,
Ignorance, Curiosity, Urgency, Distraction, Loneliness, just to cite a few. Figu5rdeisplays
a non-exhaustive list of them, whereas Fig4uprreesents the core elements of PHATO. Our
ontology is rich enough to allow the specialization of several important concepts to achieve a
better classification of the entities within the domain. For example, Ltuyprescoafn correspond
to diferent strategies or messages employed bSycaammer. Phishing Attack can be classified
intoSpear Phishing Attack, Whaling Phishing Attack, etc. The role oAfsset can be played
by Password, Login, etc. Instances oHfook can be phishing websites. The rich scheme of
PHATO may support the design of datasets or their integration for, e.g., machine learning tasks
in this area.</p>
        <p>With the support of ROSE and COVER, it is possible to assign a given likelihood that instances
of a type ofVulnerability Condition triggerAsset Catch events of a particular type. We
can say, for instance, that the more fragilities a person bears, the higher the chances of their
falling for a phishing attack. Phishing awareness training, from this perspective, is a sort
of Control Event that eliminates or attenuates ceMrteanitnal Attitudes or builds new
Control Capabilities so that thesMeental Attitudes no longer play the role a fragility
(e.g., when one is able to control their curiosity, greed or fear). This, in turn, helps preventing
Asset Catches to some degree. For example, thTaerget acquires cybersecurity knowledge
through the training, which can elimTinaartgeet’s Ignorance in relation to some common
Lure. Consequently, the associatAesdset Catch events are prevented because the type of
Situation that could trigger them has been ruled out. Similarly, it is possible to assign a given
likelihood for instances of a typPehoifshing Attack causeAsset Catch events of a specific
type. In other words, we can analyze which kinPdhsiosfhing Attacks are the most successful
at capturinAgssets.</p>
        <p>By representing a number of interconnected entities that are relPehvaisnhtinfogrAttacks
andAsset Catch events, PHATO can support the design of suitable countermeasures. For
example, phishing awareness training is one of the most eficient ways of preventing people
from falling for a phish29[]. Figure6 displays such a case wherePahishing Awareness
Program is designed to be caountermeasure to Asset Catch events of a certain type by the
manifestation oPfhishing Awareness Training wherein theTargets participate. In this
case, aPhishing Awareness Program is a social entity whose capabilities are manifested by
Phishing Awareness Training, which may remove some ofTarget’s Fragilities, therefore
preventing certain typesAosfset Catch event.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>5. Related work</title>
      <p>
        Although there are numerous ontology-based works in security and cybersecurity, recent
literature review3s0,[31, 32] have shown they are mostly focused on specific applications and
lack ontological foundations. As a consequence, an in-depth ontological analysis of phishing
attacks is missing. For example, i3n] t[he authors are interested in automated phishing detection
with the aid of a proposed taxonomy. Similarly6,]ian d[escription logic and OWL ontologies
are proposed to represent scenarios of e-mail phishing attacks. The latter also presents a list of
ontology-based works, which are lightweight (DL, RDF, OWL, frames) and application-focused.
A few of these works resemble an ontological account but they focus on social engineering
in general, not phishing attacks. Even these ofer no more than an4O, W5] Lor[ UML-like
[
        <xref ref-type="bibr" rid="ref7 ref8">7, 8</xref>
        ] ontology. Just like noticed 3b0y][for security ontologies, we could not find publicly any
artifacts reported by this literature, which makes any evaluation more dificult (for instance, to
check logical consistency and unintended instances). Therefore, to the best of our knowledge,
the present work is the first analysis and conceptualization of phishing attacks employing a
foundational ontology. For comparison, Fi7gudreepicts an interesting proposal of a domain
ontology of social engineering by Waetnagl [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], where we can clearly notice the lack of
ontological distinctions among the classes (objects, events, modes, situations, etc.). This may
yield too many unintended instances, as shown by Olievteailr[a15] by analyzing a well-known
cybersecurity ontology.
      </p>
    </sec>
    <sec id="sec-7">
      <title>6. Final considerations</title>
      <p>Dealing appropriately with phishing attacks is currently one of the main challenges in the
cybersecurity field. They pose a special threat to people’s and organization’s assets by combining
smartly social and technical elements. Understanding and modeling phishing attacks are part
of the solution. However, current models present a number of limitations due to their lack of
ontological foundations, such as informality and unintended instances. With the aid of the
Reference Ontology for Security Engineering (ROSE), which is based on thCeommon Ontology
of Value and Risk (COVER) and theUnified Foundational Ontology (UFO), we propose the first
well-foundedPhishing Attack Ontology (PHATO). We have shown that PHATO represents the
key elements of phishing attacks found in the research literature. We also discussed some
implications of PHATO for the design of anti-phishing countermeasures.</p>
      <p>However, PHATO, naturally, needs further validation, such as web semantic applications,
expert assessment, formal validation, integration of datasets, and others. Furthermore, integrating
PHATO with acompetence ontology [33, 34, 35] can improve its capability of modeling human
factors involved in phishing attacks and countermeasures. For example, competencies as types
of Mental Attitudes that counteraTcatrget’s Fragilities: critical thinking, cybersecurity
knowledge and skills, etc. Because these competencies often emerge from the interaction of
otherMental Attitudes, asystem core ontology [36] can come in handy. We intend to continue
this work in this direction in the future.</p>
    </sec>
    <sec id="sec-8">
      <title>Acknowledgments</title>
      <sec id="sec-8-1">
        <title>Work supported by Accenture Israel Cybersecurity Labs.</title>
        <p>[9] Z. Alkhalil, C. Hewage, L. Nawaf, I. Khan, Phishing attacks: A recent comprehensive study
and a new anatomy, Frontiers in Computer Science 3 (2021) 563060.
[10] E. E. Lastdrager, Achieving a consensual definition of phishing based on a systematic
review of the literature, Crime Science 3 (2014) 1–10.
[11] G. Guizzardi, Ontology, ontologies and the ”I” of FAIR, Data Intelligence 2 (2020) 181–191.
[12] G. Guizzardi, The role of foundational ontologies for conceptual modeling and domain
ontology representation, in: 7th Intl. Baltic Conf. on Databases and Information Systems,
IEEE, 2006, pp. 17–25.
[13] S. Schulz, The role of foundational ontologies for preventing bad ontology design, in: 4th</p>
        <p>Joint Ontology Workshops (JOWO), volume 2205, CEUR-WS, 2018.
[14] C. M. Keet, The use of foundational ontologies in ontology development: an empirical
assessment, in: ESWC, Springer, 2011, pp. 321–335.
[15] Í. Oliveira, G. Engelberg, P. P. F. Barcelos, T. P. Sales, M. Fumagalli, R. Baratella, D. Klein,
G. Guizzardi, Boosting D3FEND: Ontological analysis and recommendations, in: Formal
Ontology in Information Systems: Proceedings of the Thirteenth International Conference
(FOIS 2023), volume forthcoming, IOS Press, 2023.
[16] Í. Oliveira, T. P. Sales, R. Baratella, M. Fumagalli, G. Guizzardi, An ontology of security
from a risk treatment perspective, in: International conference on conceptual modeling,
Springer, 2022, pp. 365–379.
[17] T. P. Sales, F. Baião, G. Guizzardi, J. P. A. Almeida, N. Guarino, J. Mylopoulos, The common
ontology of value and risk, in: Conceptual Modeling. ER 2018, volume 11157, Springer,
2018, pp. 121–135.
[18] G. Guizzardi, A. Botti Benevides, C. M. Fonseca, D. Porello, J. P. A. Almeida, T. P. Sales,</p>
        <p>Ufo: Unified foundational ontology, Applied ontology 17 (2022) 1–44.
[19] F. Salahdine, N. Kaabouch, Social engineering attacks: A survey, Future internet 11 (2019).
[20] K. L. Chiew, K. S. C. Yong, C. L. Tan, A survey of phishing attacks: Their types, vectors
and technical approaches, Expert Systems with Applications 106 (2018) 1–20.
[21] M. Jakobsson, Modeling and preventing phishing attacks, in: Financial Cryptography,
volume 5, Citeseer, 2005.
[22] J. Hong, The state of phishing attacks, Commun. ACM 55 (2012) 74–81. UhRtLt: ps:
//doi.org/10.1145/2063176.2063197.doi:10.1145/2063176.2063197.
[23] Z. Wang, H. Zhu, L. Sun, Social engineering in cybersecurity: Efect mechanisms, human
vulnerabilities and attack methods, IEEE Access 9 (2021) 11895–11910.
[24] M. Jakobsson, S. Myers, Phishing and countermeasures: understanding the increasing
problem of electronic identity theft, John Wiley &amp; Sons, 2006.
[25] G. Guizzardi, et al., Towards ontological foundations for conceptual modeling: The Unified</p>
        <p>Foundational Ontology (UFO) story, Applied ontology 10 (2015) 259–271.
[26] M. Verdonck, F. Gailly, Insights on the use and application of ontology and conceptual
modeling languages in ontology-driven conceptual modeling, in: Intl. Conf. on Conceptual
Modeling, Springer, 2016, pp. 83–97.
[27] R. Baratella, et al., Understanding and modeling prevention, in: Research Challenges in</p>
        <p>Information Science. RCIS 2022, volume 389–405, Springer, 2022, pp. 389–405.
[28] G. Guizzardi, et al., Grounding software domain ontologies in the Unified Foundational
Ontology (UFO): The case of the ODE software process ontology., in: Ibero-American</p>
      </sec>
      <sec id="sec-8-2">
        <title>Conference on Software Engineering, 2008, pp. 127–140.</title>
        <p>[29] K. Jansson, R. von Solms, Phishing for phishing awareness, Behaviour &amp; information
technology 32 (2013) 584–593.
[30] Í. Oliveira, et al., How FAIR are security core ontologies? A systematic mapping study, in:</p>
        <p>Research Challenges in Information Science., 2021, pp. 107–123.
[31] B. F. Martins, et al., Conceptual characterization of cybersecurity ontologies, in: IFIP</p>
        <p>Working Conference on The Practice of Enterprise Modeling, Springer, 2020, pp. 323–338.
[32] B. F. Martins, et al., A framework for conceptual characterization of ontologies and
its application in the cybersecurity domain, Software and Systems Modeling 21 (2022)
1437–1464.
[33] R. F. Calhau, C. L. B. Azevedo, J. P. A. Almeida, Towards Ontology-based Competence
Modeling in Enterprise Architecture, in: 25th IEEE Int. EDOC Conference (EDOC 2021),
IEEE, 2021. doi:10.1109/edoc52215.2021.00018.
[34] R. F. Calhau, J. P. A. Almeida, Zooming in on competences in ontology-based enterprise
architecture modeling, in: 2022 IEEE 26st International Enterprise Distributed Object
Computing Workshop (EDOCW), 2022.
[35] R. F. Calhau, S. Kokkula, D. Cameron, G. Guizzardi, J. P. A. Almeida, Modeling competence
framework elements with an ontology-based approach, in: 2023 IEEE 25th Conference
on Business Informatics (CBI), IEEE, 2023. URLh:ttps://doi.org/10.1109/cbi58679.2023.
10187498. doi:10.1109/cbi58679.2023.10187498.
[36] R. F. Calhau, T. P. Sales, Í. Oliveira, S. Kokkula, L. F. Pires, D. Cameron, G. Guizzardi, J. P. A.</p>
        <p>Almeida, A system core ontology for capability emergence modeling, in: 27th IEEE Int.
EDOC Conference (EDOC 2023), IEEE, 2023.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Sun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Zhu</surname>
          </string-name>
          ,
          <article-title>Defining social engineering in cybersecurity</article-title>
          ,
          <source>IEEE Access 8</source>
          (
          <year>2020</year>
          )
          <fpage>85094</fpage>
          -
          <lpage>85115</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>Internet</given-names>
            <surname>Crime Complaint Center</surname>
          </string-name>
          ,
          <source>Internet Crime Report, Technical Report, Federal Bureau of Investigation of The United States of America</source>
          ,
          <year>2022</year>
          .hUtRtLp:s://www.ic3.gov/Media/ PDF/AnnualReport/2022_IC3Report.p.df
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>S.-S.</given-names>
            <surname>Tseng</surname>
          </string-name>
          ,
          <string-name>
            <surname>C.-H. Ku</surname>
            ,
            <given-names>T.-J.</given-names>
          </string-name>
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>G.-G.</given-names>
          </string-name>
          <string-name>
            <surname>Geng</surname>
            ,
            <given-names>Y.-J.</given-names>
          </string-name>
          <string-name>
            <surname>Wang</surname>
          </string-name>
          ,
          <article-title>Building a frame-based antiphishing model based on phishing ontology</article-title>
          ,
          <source>in: International Conference on Advances in Information Technology</source>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>I. Alshanfari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Ismail</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N. J. M.</given-names>
            <surname>Zaizi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F. A.</given-names>
            <surname>Wahid</surname>
          </string-name>
          ,
          <article-title>Ontology-based formal specifications for social engineering</article-title>
          ,
          <source>International Journal of Technology Management and Information System</source>
          <volume>2</volume>
          (
          <year>2020</year>
          )
          <fpage>35</fpage>
          -
          <lpage>46</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Zhu</surname>
          </string-name>
          , P. Liu,
          <string-name>
            <given-names>L.</given-names>
            <surname>Sun</surname>
          </string-name>
          ,
          <article-title>Social engineering in cybersecurity: a domain ontology and knowledge graph application examples</article-title>
          ,
          <source>Cybersecurity</source>
          <volume>4</volume>
          (
          <year>2021</year>
          )
          <fpage>1</fpage>
          -
          <lpage>21</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>F.</given-names>
            <surname>Tchakounté</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Molengar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. M.</given-names>
            <surname>Ngossaha</surname>
          </string-name>
          ,
          <article-title>A description logic ontology for email phishing</article-title>
          ,
          <source>International Journal of Information Security Science</source>
          <volume>9</volume>
          (
          <year>2020</year>
          )
          <fpage>44</fpage>
          -
          <lpage>63</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>F.</given-names>
            <surname>Mouton</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Leenen</surname>
          </string-name>
          ,
          <string-name>
            <surname>M. M. Malan</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          <string-name>
            <surname>Venter</surname>
          </string-name>
          ,
          <article-title>Towards an ontological model defining the social engineering domain</article-title>
          ,
          <source>in: ICT and Society: 11th IFIP TC 9 International Conference on Human Choice and Computers, HCC11</source>
          <year>2014</year>
          , Turku, Finland,
          <source>July 30-August 1</source>
          ,
          <year>2014</year>
          . Proceedings 11, Springer,
          <year>2014</year>
          , pp.
          <fpage>266</fpage>
          -
          <lpage>279</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>T.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Ni</surname>
          </string-name>
          ,
          <article-title>Aligning social concerns with information system security: A fundamental ontology for social engineering</article-title>
          ,
          <source>Information Systems</source>
          <volume>104</volume>
          (
          <year>2022</year>
          )
          <fpage>101699</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>