helping organizations combat phishing

Wombat Security Technologies was founded to commercialize products originally developed at Carnegie Mellon University as part of one of the largest anti-phishing research projects in the US. Our enterprise-ready solutions have grown out of peer-reviewed scientific work conducted by leading researchers in the field and have been tested in the laboratory and the real world. The following is a selection of scientific publications detailing scientific evaluations of Wombat’s underlying technologies

Research Publications

Teaching Johnny Not to Fall for Phish
P. Kumaraguru, S. Sheng, A. Acquisti, L. Cranor, and J. Hong. ACM Transactions on Internet Technology, Vol. V, No. N, September 2009, Pages 1–31.

School of Phish: A Real-Word Evaluation of Anti-Phishing Training.
P. Kumaraguru, J. Cranshaw, A. Acquisti, L. Cranor, J. Hong, M.A. Blair, and T. Pham. SOUPS 2009. [Originally published as CyLab Technical Report CMU-CyLab-09-002, 2009]

Anti-Phishing Landing Page: Turning a 404 into a Teachable Moment for End Users
P. Kumaraguru, L. Cranor, and L. Mather. CEAS 2009.

Lessons from a real world evaluation of anti-phishing training.
P. Kumaraguru, S. Sheng, A. Acquisti, L. Cranor, and J. Hong. In Proceedings of the third eCrime Researchers Summit (eCrime 2008), October 15-16, 2008, Atlanta, GA.

Anti-Phishing Phil: The Design and Evaluation of a Game That Teaches People Not to Fall for Phish
S. Sheng, B. Magnien, P. Kumaraguru, A. Acquisti, L. Cranor, J. Hong, and E. Nunge. In Proceedings of the 2007 Symposium On Usable Privacy and Security, Pittsburgh, PA, July 18-20, 2007.

CANTINA: A content-based approach to detecting phishing web sites
Y. Zhang, J. Hong, and L. Cranor. In Proceedings of the 16th International conference on World Wide Web, Banff, Alberta, Canada, May 8-12, 2007.

Getting Users to Pay Attention to Anti-Phishing Education: Evaluation of Retention and Transfer
P. Kumaraguru, Y. Rhee, S. Sheng, S. Hasan, A. Acquisti, L. Cranor and J. Hong. In Proceedings of the 2nd Annual eCrime Researchers Summit, October 4-5, 2007, Pittsburgh, PA, p. 70-81.

Protecting People from Phishing: The Design and Evaluation of an Embedded Training Email System
P. Kumaraguru, Y. Rhee, A. Acquisti, L. Cranor, J. Hong, and E. Nunge. In CHI 2007: Conference on Human Factors in Computing Systems, San Jose, California, 28 April – May 3, 2007, p. 905-914. [Originally published as CyLab Technical Report CMU-CyLab-06-017, 2006]

Learning to Detect Phishing Emails
I. Fette, N. Sadeh, and A. Tomasic. In Proceedings of the 16th International Conference on World Wide Web, Banff, Alberta,
Canada, May 8-12, 2007.