| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Analiza phishing napadov z imitacijo bank : diplomsko delo visokošolskega študijskega programa Informacijska varnost
Authors:ID Maglica, Nejc (Author)
ID Prislan Mihelič, Kaja (Mentor) More about this mentor... New window
ID Mihelič, Anže (Comentor)
Files:.pdf VS_Maglica_Nejc_2026.pdf (869,02 KB)
MD5: 671C83BCA9575D8979B5F433B2F5B676
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:Diplomska naloga analizira phishing napade, usmerjene v bančne institucije, s posebnim poudarkom na Banki X. Cilj diplomske naloge je predstaviti značilnosti takšnih napadov in oceniti učinkovitost obstoječih zaščitnih ukrepov. V teoretičnem delu so predstavljene najpogostejše oblike phishinga, kot so e-poštni phishing, smishing in spear phishing, ter psihološki sprožilci, med katerimi izstopajo občutek nujnosti, izkoriščanje avtoritete in obljuba koristi. Predstavljene so bile tudi tehnične metode, ki jih uporabljajo napadalci, vključno z manipulacijo domen, zlorabo TLS-certifikatov in uporabo proxy rešitev za prestrezanje podatkov v realnem času. Posebej so poudarjeni regulativni in standardizacijski okvirji (NIS2, DORA, GDPR, ISO/IEC 27001, ISO/IEC 27701, PCI DSS), ki opredeljujejo obveznosti bank na področju kibernetske varnosti. Empirični del je temeljil na analizi primerov napadov iz obdobja 2023–2025, zbranih iz javnih virov in anonimno obdelanih podatkov Banke X. Rezultati so pokazali, da napadalci kombinirajo tehnično imitacijo uporabniških vmesnikov, zlorabo HTTPS in manipulacijo domen s psihološkimi elementi, kar znatno zmanjša možnost, da bi uporabniki napade prepoznali. Ugotovljeno je bilo, da obstoječi ukrepi omogočajo hitro odkrivanje in ublažitev posledic, vendar niso vedno uspešni pri preprečevanju napadov. Na podlagi analize je bilo priporočeno, da se uvedejo naprednejše oblike večfaktorske avtentikacije, proaktivno spremljanje novih registracij domene in okrepi komunikacijske kanale za hitro obveščanje uporabnikov. Zaključek naloge potrjuje, da je dolgoročno odpornost bank in njihovih uporabnikov mogoče doseči le s celostnim pristopom, ki združuje tehnične, organizacijske in vedenjske ukrepe.
Keywords:diplomske naloge
Publication status:Published
Publication version:Version of Record
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:N. Maglica
Year of publishing:2026
Year of performance:2026
Number of pages:VII f., 41 str.
PID:20.500.12556/DKUM-97598 New window
UDC:343.3/.7:004(043.2)
COBISS.SI-ID:281849347 New window
Publication date in DKUM:16.06.2026
Views:214
Downloads:25
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:24.03.2026

Secondary language

Language:English
Title:Analysis of bank imitation phisihing attacks
Abstract:This thesis analysed phishing attacks targeting banking institutions, with a particular focus on Bank X. The purpose of the research was to identify the main characteristics of such attacks and to assess the effectiveness of existing security measures. The theoretical part included a review of common phishing techniques, such as e-mail phishing, smishing and spear-phishing, as well as psychological triggers like urgency, authority and promised benefits. Technical methods used by attackers were also presented, including domain manipulation, TLS certificate abuse and the use of real-time proxy solutions for data interception. Special emphasis was placed on regulatory and standardisation frameworks (NIS2, DORA, GDPR, ISO/IEC 27001, ISO/IEC 27701, PCI DSS), which define the obligations of banks in the field of cybersecurity. The empirical part was based on the analysis of phishing cases from the period 2023–2025, collected from public sources and anonymised internal data of Bank X. The results showed that attackers combine technical imitation of user interfaces, misuse of HTTPS and domain manipulation with psychological techniques, significantly reducing the likelihood of user detection. It was established that current measures enable rapid detection and mitigation, but are less effective in prevention. Based on the findings, recommendations were made to implement advanced forms of multi-factor authentication, proactively monitor new domain registrations and strengthen communication channels for user awareness. The conclusion confirms that long-term resilience of banks and their customers requires a comprehensive approach that integrates technical, organisational and behavioural measures.
Keywords:phishing, banking security, cyber security, social engineering, data security


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica