Training to Mitigate Phishing Attacks Using Mindfulness Techniques

Training to Mitigate Phishing Attacks Using Mindfulness Techniques
复制标题

使用正念技术减轻网络钓鱼攻击的培训

DOI:
10.1080/07421222.2017.1334499
复制
发表时间:
2017
影响因子:
7.7
通讯作者:
J. Thatcher
J. Thatcher
中科院分区:
管理学2区
文献类型:
--
作者:
M. Jensen;Michael Dinger;Ryan T. Wright;J. Thatcher

文献摘要

参考文献

被引文献

相似文献

摘要网络钓鱼攻击创历史新高,造成数十亿美元的损失。为了减轻网络钓鱼的影响,组织经常使用基于规则的培训来教个人识别某些线索或应用一套规则来避免网络钓鱼攻击。基于规则的方法改进了针对网络钓鱼的组织防御;然而,定期重复基于规则的培训可能不会提高对攻击的抵抗力。为了扩展可用于打击网络钓鱼攻击的工具包,我们使用正念理论开发了一种新的培训方法,可以在个人熟悉基于规则的培训后执行。正念方法教会个人在消息评估期间动态分配注意力,提高对上下文的意识,并预防对可疑消息的判断-这些技术对于在组织环境中检测网络钓鱼攻击至关重要,但在基于规则的教学中没有涉及这些技术。为了评估我们方法的有效性,我们在美国一所大学的一项实地研究中比较了基于规则的培训计划和正念培训计划,该研究涉及355名熟悉网络钓鱼攻击并定期接受基于规则的指导的学生、教职员工。为了评估培训的稳健性,我们以纯文本或文本加图形的格式交付了每个程序。十天后,我们对参与者进行了一次网络钓鱼攻击,使用了通用和定制的网络钓鱼消息。我们发现,接受正念训练的参与者能够更好地避免网络钓鱼攻击。特别是,那些对自己的检测能力已经有信心的参与者,以及那些报告电子邮件注意力较低和对互联网风险的感知较低的参与者,观察到了改善。这项工作介绍并提供了支持一种新方法的证据,该方法可用于开发反网络钓鱼培训。
Abstract Phishing attacks are at a record high and are causing billions of dollars in losses. To mitigate phishing’s impact, organizations often use rule-based training to teach individuals to identify certain cues or apply a set of rules to avoid phishing attacks. The rule-based approach has improved organizational defenses against phishing; however, regular repetition of rule-based training may not yield increasing resistance to attacks. To expand the toolkit available to combat phishing attacks, we used mindfulness theory to develop a novel training approach that can be performed after individuals are familiar with rule-based training. The mindfulness approach teaches individuals to dynamically allocate attention during message evaluation, increase awareness of context, and forestall judgment of suspicious messages—techniques that are critical to detecting phishing attacks in organizational settings, but are unaddressed in rule-based instruction. To evaluate the efficacy of our approach, we compared rule-based and mindfulness training programs in a field study at a U.S. university that involved 355 students, faculty, and staff who were familiar with phishing attacks and received regular rule-based guidance. To evaluate the robustness of the training, we delivered each program in text-only or text-plus-graphics formats. Ten days later, we conducted a phishing attack on participants that used both generic and customized phishing messages. We found that participants who received mindfulness training were better able to avoid the phishing attack. In particular, improvement was observed for participants who were already confident in their detection ability and those who reported low e-mail mindfulness and low perceptions of Internet risk. This work introduces and provides evidence supporting a new approach that may be used to develop anti-phishing training.
DOI: 10.1037/1082-989x.7.2.178
发表时间: 2002-06
影响因子: 7
作者:
Booil Jo
通讯作者: Booil Jo