In this paper we have developed a sender-centric approach
to detecting phishing emails. This approach was developed
based on the observation that, although phishers can easily
manipulate both the content and structure of phishing emails, it
is much hard for them to completely conceal the sender information
of a phishing message. More importantly, such sender
information is often inconsistent with the target institution of
the phishing email, and can help separate phishing emails from
legitimate messages. We performed evaluation studies of the
sender-centric approach using real-world email traces, and our
evaluation studies showed that the sender-centric approach is
indeed a feasible and effective method in detecting phishing
emails. As future work, we plan to extend the sender-centric
approach to detecting non-banking phishing emails