Modelling user-phishing interaction

Modelling user-phishing interaction
复制标题

DOI:
10.1109/hsi.2008.4581513
复制
发表时间:
2008-05
期刊:
2008 Conference on Human System Interactions
影响因子:
--
通讯作者:
Xun Dong;John A. Clark;J. Jacob
Xun Dong;John A. Clark;J. Jacob
中科院分区:
其他
文献类型:
--
作者:
Xun Dong;John A. Clark;J. Jacob

文献摘要

相似文献

为了保护用户免受网络钓鱼攻击,系统设计人员和安全专业人员需要了解用户如何与这些攻击交互,并能够在给定情况下预测用户的行为。本文介绍了第一个可视化用户网络钓鱼交互的模型。我们提出了一种以统一和紧凑的方式准确描述用户感知的方法。在这个模型的背景下,我们研究了:在攻击中,感知和现实之间可能发生什么确切的不匹配;如何检测这些不匹配;以及为什么用户不能这样做。使用该模型,我们还确定了缺乏安全工具/指标的地方,为用户界面的安全评估提出了新的方面,并为有效的反网络钓鱼用户教育提供了指导。
To protect users from phishing attacks system designers and security professionals need to understand how users interact with those attacks and be able to predict userspsila behaviours in a given situation. In this paper we introduce the first model to visualise user-phishing interaction. We present a method to accurately describe userspsila perceptions in a uniform and compact manner. Within the context of this model we have investigated: what exact mismatches may occur between perception and reality in an attack; how to detect those mismatches; and why users fail to do so. Using this model we also identify where the security tools/indicators are lacking, suggest new aspects for security evaluation for the user interface, and provide guidance on effective anti-phishing user education.