Can we fight social engineering attacks by social means? Assessing social salience as a means to improve phish detection

Can we fight social engineering attacks by social means? Assessing social salience as a means to improve phish detection
复制标题

我们可以通过社交手段来对抗社会工程攻击吗?

DOI:
--
复制
发表时间:
2017
期刊:
Symposium On Usable Privacy and Security
影响因子:
--
通讯作者:
P. Briggs
P. Briggs
中科院分区:
--
文献类型:
--
作者:
James Nicholson;L. Coventry;P. Briggs

文献摘要

被引文献

相似文献

对于个人和组织来说,网络钓鱼仍然是一个问题,我们每年都会损失数十亿美元。分析要评估发件人显着性的效果(突出发送者的重要字段)和接收器显着性(显示其他用户的数量,在收到同一电子邮件中)被要求评估他们对自己的判断的信心,并且这些信心得分对实际表现的校准很差,特别是对于网络钓鱼(而不是真正的)电子邮件,我们还研究了冲动行为在网络钓鱼中的作用功能失调的冲动性不太可能检测到网络钓鱼电子邮件的存在。
Phishing continues to be a problem for both individuals and organisations, with billions of dollars lost every year. We propose the use of nudges – more specifically social saliency nudges that aim to highlight important information to the user when evaluating emails. We used a signal detection analysis to assess the effects of both sender saliency (highlighting important fields from the sender) and receiver saliency (showing numbers of other users in receipt of the same email). Sender saliency improved phish detection but did not introduce any unwanted response bias. Users were asked to rate their confidence in their own judgements and these confidence scores were poorly calibrated with actual performance, particularly for phishing (as opposed to genuine) emails. We also examined the role of impulsive behaviour on phish detection, concluding that those who score highly on dysfunctional impulsivity are less likely to detect the presence of phishing emails.