Categorizing human phishing difficulty: a Phish Scale

Categorizing human phishing difficulty: a Phish Scale
复制标题

对人类网络钓鱼难度进行分类:网络钓鱼量表

DOI:
--
复制
发表时间:
2020
影响因子:
3.9
通讯作者:
M. Theofanos
M. Theofanos
中科院分区:
--
文献类型:
--
作者:
M. Steves;Kristen K. Greene;M. Theofanos

文献摘要

被引文献

相似文献

随着组织继续投资网络钓鱼意识培训计划,许多首席信息安全官 (CISO) 担心他们的培训活动点击率很高或不稳定,因为他们必须向组织官员证明培训预算的合理性,因为当点击率没有下降时,组织官员质疑意识培训的有效性。我们认为,点击率应该根据目标受众的网络钓鱼电子邮件的难度而变化。过去的研究表明,当网络钓鱼电子邮件的前提与用户的工作环境一致时,用户检测网络钓鱼的难度就会大得多。鉴于此,我们提出了网络钓鱼量表,以便 CISO 和网络钓鱼培训实施者可以轻松评估其网络钓鱼练习的难度,并帮助解释相关的点击率。我们的量表基于过去对网络钓鱼线索和用户上下文的研究,并将该量表应用于之前发布的数据和基于企业的网络钓鱼活动的新数据。网络钓鱼规模在当前的网络钓鱼数据集上表现良好,但未来需要通过更多种类的网络钓鱼电子邮件来验证它。网络钓鱼量表显示出作为一种工具的巨大前景,可以帮助构建跨部门网络钓鱼活动点击率的数据共享。
As organizations continue to invest in phishing awareness training programs, many chief information security officers (CISOs) are concerned when their training exercise click rates are high or variable, as they must justify training budgets to organization officials who question the efficacy of awareness training when click rates are not declining. We argue that click rates should be expected to vary based on the difficulty of the phishing email for a target audience. Past research has shown that when the premise of a phishing email aligns with a user’s work context, it is much more challenging for users to detect a phish. Given this, we propose a Phish Scale, so CISOs and phishing training implementers can easily rate the difficulty of their phishing exercises and help explain associated click rates. We base our scale on past research in phishing cues and user context, and apply the scale to previously published and new data from enterprise-based phishing exercises. The Phish Scale performed well with the current phishing dataset, but future work is needed to validate it with a larger variety of phishing emails. The Phish Scale shows great promise as a tool to help frame data sharing on phishing exercise click rates across sectors.