What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game

What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game
复制标题

What.Hack:通过角色扮演网络钓鱼模拟游戏进行反网络钓鱼培训

DOI:
--
复制
发表时间:
2019
期刊:
International Conference on Human Factors in Computing Systems
影响因子:
--
通讯作者:
Erik Andersen
Erik Andersen
中科院分区:
--
文献类型:
--
作者:
Z. Wen;Zhiqiu Lin;Rowena Chen;Erik Andersen

文献摘要

参考文献

被引文献

相似文献

网络钓鱼攻击是一个主要问题,2016年美国总统大选期间,民主党全国委员会(DNC)遭到黑客攻击就是明证。在那次攻击中,工作人员被伪造的谷歌安全邮件欺骗,共享密码,授予访问机密信息的权限。诸如此类的漏洞部分是由于网络安全方面的用户培训不足且令人厌倦。理想情况下,我们应该有更有吸引力的培训方法,以积极和有趣的方式教授网络安全。为了满足这一需求,我们引入了游戏《What》。这款游戏不仅教授网络钓鱼概念,还在角色扮演游戏中模拟了实际的网络钓鱼攻击,以鼓励玩家练习自我防御。我们的用户研究表明,我们的游戏设计在提高性能方面比标准形式的训练和竞争性训练游戏设计(不通过角色扮演模拟网络钓鱼)更具吸引力和有效性。
Phishing attacks are a major problem, as evidenced by the DNC hackings during the 2016 US presidential election, in which staff were tricked into sharing passwords by fake Google security emails, granting access to confidential information. Vulnerabilities such as these are due in part to insufficient and tiresome user training in cybersecurity. Ideally, we would have more engaging training methods that teach cybersecurity in an active and entertaining way. To address this need, we introduce the game What.Hack, which not only teaches phishing concepts but also simulates actual phishing attacks in a role-playing game to encourage the player to practice defending themselves. Our user study shows that our game design is more engaging and effective in improving performance than a standard form of training and a competing training game design (which does not simulate phishing attempts through role-playing).
DOI: 10.1145/2976749.2978382
发表时间: 2016-06
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Andrew Ruef;M. Hicks;James Parker;Dave Levin;Michelle L. Mazurek;Piotr (Peter) Mardziel
通讯作者: Andrew Ruef;M. Hicks;James Parker;Dave Levin;Michelle L. Mazurek;Piotr (Peter) Mardziel