The Phishing Email Suspicion Test (PEST) a lab-based task for evaluating the cognitive mechanisms of phishing detection.

The Phishing Email Suspicion Test (PEST) a lab-based task for evaluating the cognitive mechanisms of phishing detection.
复制标题

DOI:
10.3758/s13428-020-01495-0
复制
发表时间:
2021-06
影响因子:
5.4
通讯作者:
Wilson RC
Wilson RC
中科院分区:
心理学2区
文献类型:
--
作者:
Hakim ZM;Ebner NC;Oliveira DS;Getz SJ;Levin BE;Lin T;Lloyd K;Lai VT;Grilli MD;Wilson RC

文献摘要

参考文献

相似文献

网络钓鱼电子邮件是一个主要问题,与欺诈和剥削以及随后的负面健康后果(包括抑郁和自杀)有关。由于网络钓鱼电子邮件的数量巨大,而且网络钓鱼电子邮件的目的是欺骗,因此纯粹的技术解决方案只能走到这一步,而人类的判断则是最后一道防线。然而,由于在实验室中很难对人们进行网络钓鱼,因此人们对网络钓鱼易感性背后的认知和神经机制知之甚少。因此,迫切需要开发一种生态有效的基于实验室的网络钓鱼易感性测量方法,以便评估网络钓鱼检测中涉及的认知机制。在这里,我们提出了一种基于任务、网络钓鱼电子邮件可疑测试 (PEST) 和量化行为的认知模型的测量方法。在 PEST 中,参与者根据怀疑程度对一系列网络钓鱼和非网络钓鱼电子邮件进行评级。通过将每封电子邮件的怀疑分数与其现实世界的功效进行比较,我们找到了对 PEST 生态有效性的初步支持——在现实世界中更有效的网络钓鱼电子邮件在实验室中欺骗人们也更有效。在提出的计算模型中,我们根据参与者对电子邮件的整体怀疑程度、他们区分网络钓鱼和非网络钓鱼电子邮件的能力以及最近的电子邮件对他们当前决策的偏见程度来量化行为。我们的任务和模型共同为研究网络钓鱼检测的认知神经科学提供了一个框架。
Phishing emails constitute a major problem, linked to fraud and exploitation as well as subsequent negative health outcomes including depression and suicide. Because of their sheer volume, and because phishing emails are designed to deceive, purely technological solutions can only go so far, leaving human judgment as the last line of defense. However, because it is difficult to phish people in the lab, little is known about the cognitive and neural mechanisms underlying phishing susceptibility. There is therefore a critical need to develop an ecologically valid lab-based measure of phishing susceptibility that will allow evaluation of the cognitive mechanisms involved in phishing detection. Here we present such a measure based on a task, the Phishing Email Suspicion Test (PEST), and a cognitive model to quantify behavior. In PEST, participants rate a series of phishing and non-phishing emails according to their level of suspicion. By comparing suspicion scores for each email to its real-world efficacy, we find initial support for the ecological validity of PEST – phishing emails that were more effective in the real world were more effective at deceiving people in the lab. In the proposed computational model, we quantify behavior in terms of participants’ overall level of suspicion of emails, their ability to distinguish phishing from non-phishing emails, and the extent to which emails from the recent past bias their current decision. Together our task and model provide a framework for studying the cognitive neuroscience of phishing detection.
用启发式系统模型调查网络钓鱼受害情况:理论框架和探索
DOI: 10.1016/j.cose.2012.12.003
发表时间: 2013-10-01
影响因子: 5.6
作者:
Luo, Xin (Robert);Zhang, Wei;Seazzu, Alessandro
通讯作者: Seazzu, Alessandro
DOI: 10.1037/h0048727
发表时间: 1962-01-01
影响因子: --
作者:
PARDUCCI, A;MARSHALL, LM
通讯作者: MARSHALL, LM
DOI: 10.3389/fpsyg.2018.00135
发表时间: 2018-02-21
影响因子: 3.8
作者:
Rajivan, Prashanth;Gonzalez, Cleotilde
通讯作者: Gonzalez, Cleotilde
DOI: 10.1371/journal.pone.0209684
发表时间: 2019-01-16
期刊: PLOS ONE
影响因子: 3.7
作者:
Jones, Helen S.;Towse, John N.;Harrison, Timothy
通讯作者: Harrison, Timothy
DOI: 10.1108/ics-01-2016-0002
发表时间: 2016-01-01
影响因子: 1.4
作者:
Kelley, Timothy;Bertenthal, Bennett I.
通讯作者: Bertenthal, Bennett I.