Phishing Detection · Requirements Engineering · Case Study

Phishing Detection Tool for Law Enforcement Use

CFLW Cyber Strategies · The Hague, Netherlands

Researched the core requirements to translate the BigPhish proof-of-concept into operational law enforcement technology. The project was completed as part of my Bachelor’s thesis in Computer Science at Vrije Universiteit Amsterdam.


Introduction & literature review

Extensive research existed on phishing detection and mitigation, with various anti-phishing tools developed to address the threat, alongside studies on the legislative and operational strategies law enforcement uses to combat phishing. However, our literature review revealed a gap: a lack of research on anti-phishing tools specifically designed for law enforcement use, or informed by input from officers about their specific needs.

This gap highlighted the need for more tailored solutions, which was what the BigPhish tool aimed to provide.

BigPhish and its potential

BigPhish was originally developed by the Netherlands Organisation for Applied Scientific Research (TNO) to explore the Dutch phishing landscape, as presented by Bijmans et al. (2021). The study highlighted its potential as an effective phishing detection tool, especially due to its real-time and early detection capabilities, valuable for disrupting phishing operations before they cause significant harm. Recognising this potential, CFLW Cyber Strategies began evaluating and transforming BigPhish from a proof-of-concept into a fully operational law enforcement tool.

Research questions

The main goal of this study was to identify the core requirements needed to translate BigPhish from a proof-of-concept into a fully operational law enforcement technology, and to propose solutions addressing them.

These were our two main research questions, with their respective sub-questions:

  1. RQ1: What are the core requirements to translate a phishing detection tool proof-of-concept into an operational law enforcement technology?
    • RQ1.1: What is the extensive list of requirements to translate BigPhish into an operational technology?
    • RQ1.2: Which of the gathered requirements should take priority, based on impact and implementation effort?
  2. RQ2: What are potential solutions to address the top three highest-priority requirements identified?

Research methods

RQ1 was addressed through a case study, based on the guidelines outlined by Runeson et al. (2008). This was carried out in two parts:

  1. Requirement gathering: analysing the paper the tool was originally presented in, reviewing its source code, consulting domain experts at the company, running two rounds of consultations with stakeholders to validate the identified requirements and surface additional needs, and examining the phishing supply chain and the life cycle of phishing attacks through relevant literature.
  2. Requirement prioritisation: using the MoSCoW method (Must have, Should have, Could have, Won’t have), based on impact and implementation effort, and informed by stakeholder feedback, triangulation of recurring requirements, and further consultation with domain experts.

RQ2 was addressed by gathering relevant literature, researching additional sources, and consulting domain experts, drawing on these combined inputs to identify potential solutions for the top three highest-priority requirements.

Conclusions

Building on the foundational work of Bijmans et al. (2021) demonstrating BigPhish’s early detection capabilities, our research extended this by proposing targeted improvements informed by literature, domain expertise, and law enforcement feedback. Focusing on scalability, user-friendliness, and expanding the tool’s capabilities, we outlined a comprehensive plan for the tool’s evolution and proposed solutions for the top three most impactful requirements, providing a clear roadmap for BigPhish’s transformation into an effective law enforcement tool.

As the findings are owned by CFLW Cyber Strategies, they are confidential and cannot be disclosed publicly.