How Experts Detect Phishing Scam Emails

How Experts Detect Phishing Scam Emails
复制标题

DOI:
10.1145/3415231
复制
发表时间:
2020-10
影响因子:
--
通讯作者:
Rick Wash
Rick Wash
中科院分区:
--
文献类型:
--
作者:
Rick Wash

文献摘要

相似文献

网络钓鱼诈骗电子邮件是电子邮件,假装是什么,他们不是为了让电子邮件的收件人采取一些行动,他们通常不会。虽然针对网络钓鱼的技术保护减少了收到的网络钓鱼电子邮件的数量,但它们并不完美,网络钓鱼仍然是技术和通信系统中最大的安全风险来源之一。为了更好地了解最终用户可以用来识别网络钓鱼消息的认知过程,我采访了21位IT专家,了解他们在自己的收件箱中成功识别电子邮件为网络钓鱼的实例。IT专家自然会遵循识别网络钓鱼电子邮件的三阶段流程。在第一阶段,电子邮件收件人试图理解电子邮件,并了解它如何与他们生活中的其他事情联系起来。当他们这样做的时候,他们注意到了差异:关于电子邮件的小事情。当收件人注意到更多的差异,他们觉得需要一个替代的解释的电子邮件。在某种程度上,电子邮件的某些特征-通常是请求操作的链接的存在-触发他们认识到网络钓鱼是一种可能的替代解释。此时,他们会产生怀疑(第二阶段),并通过查找技术细节来调查电子邮件,以最终确定电子邮件是否为网络钓鱼。一旦他们发现这样的信息,然后他们移动到第三阶段,并通过删除它或报告来处理电子邮件。我讨论了这个过程可能失败的方式,以及改进最终用户关于网络钓鱼的培训的启示。
Phishing scam emails are emails that pretend to be something they are not in order to get the recipient of the email to undertake some action they normally would not. While technical protections against phishing reduce the number of phishing emails received, they are not perfect and phishing remains one of the largest sources of security risk in technology and communication systems. To better understand the cognitive process that end users can use to identify phishing messages, I interviewed 21 IT experts about instances where they successfully identified emails as phishing in their own inboxes. IT experts naturally follow a three-stage process for identifying phishing emails. In the first stage, the email recipient tries to make sense of the email, and understand how it relates to other things in their life. As they do this, they notice discrepancies: little things that are "off'' about the email. As the recipient notices more discrepancies, they feel a need for an alternative explanation for the email. At some point, some feature of the email --- usually, the presence of a link requesting an action --- triggers them to recognize that phishing is a possible alternative explanation. At this point, they become suspicious (stage two) and investigate the email by looking for technical details that can conclusively identify the email as phishing. Once they find such information, then they move to stage three and deal with the email by deleting it or reporting it. I discuss ways this process can fail, and implications for improving training of end users about phishing.