Creative Persuasion: A Study on Adversarial Behaviors and Strategies in Phishing Attacks

Creative Persuasion: A Study on Adversarial Behaviors and Strategies in Phishing Attacks
复制标题

DOI:
10.3389/fpsyg.2018.00135
复制
发表时间:
2018-02-21
影响因子:
3.8
通讯作者:
Gonzalez, Cleotilde
Gonzalez, Cleotilde
中科院分区:
心理学3区
文献类型:
--
作者:
Rajivan, Prashanth;Gonzalez, Cleotilde

文献摘要

被引文献

相似文献

网络钓鱼攻击的成功取决于对人类弱点的有效利用。这项研究探讨了网络钓鱼的一个很大程度上被忽视但至关重要的方面:敌对行为。我们的目标是了解人类行为和攻击者使用的策略,以及这些行为和策略如何决定最终用户对网络钓鱼电子邮件的响应。我们通过一个新的实验范式,包括两个阶段来实现这一点。在对抗阶段,105名参与者扮演网络钓鱼对手的角色,他们被激励产生多个网络钓鱼电子邮件,以逃避检测并说服最终用户做出响应。在最终用户阶段,340名参与者执行了一项电子邮件管理任务,他们检查并分类了由参与者在第一阶段沿着生成的钓鱼电子邮件和良性电子邮件。参与者在对手的角色,自我报告的策略,他们在每封电子邮件中,他们创建,并回应了个人创造力的测试。将研究两个阶段的数据结合起来进行分析,以衡量敌对行为对最终用户对网络钓鱼电子邮件的响应的影响。我们发现,持续使用特定攻击策略的参与者(例如,发送通知,使用权威的语气,或表达共同的兴趣)在所有的尝试中,总体上更成功,相比之下,其他人在每次尝试中探索不同的策略。我们还发现,策略在很大程度上决定了最终用户是更有可能立即回复电子邮件,还是删除它。个人创造力并不是对抗性能的可靠预测因子,但它是对手逃避检测能力的预测因子。总之,最初提供的网络钓鱼示例、使用的策略以及参与者对某些策略的坚持导致了说服最终用户响应网络钓鱼电子邮件的更高性能。这些见解可用于通知工具和培训程序,以检测电子邮件中的网络钓鱼策略。
Success of phishing attacks depend on effective exploitation of human weaknesses. This research explores a largely ignored, but crucial aspect of phishing: the adversarial behavior. We aim at understanding human behaviors and strategies that adversaries use, and how these may determine the end-user response to phishing emails. We accomplish this through a novel experiment paradigm involving two phases. In the adversarial phase, 105 participants played the role of a phishing adversary who were incentivized to produce multiple phishing emails that would evade detection and persuade end-users to respond. In the end-user phase, 340 participants performed an email management task, where they examined and classified phishing emails generated by participants in phase-one along with benign emails. Participants in the adversary role, self-reported the strategies they employed in each email they created, and responded to a test of individual creativity. Data from both phases of the study was combined and analyzed, to measure the effect of adversarial behaviors on end-user response to phishing emails. We found that participants who persistently used specific attack strategies (e.g., sending notifications, use of authoritative tone, or expressing shared interest) in all their attempts were overall more successful, compared to others who explored different strategies in each attempt. We also found that strategies largely determined whether an end-user was more likely to respond to an email immediately, or delete it. Individual creativity was not a reliable predictor of adversarial performance, but it was a predictor of an adversary's ability to evade detection. In summary, the phishing example provided initially, the strategies used, and the participants' persistence with some of the strategies led to higher performance in persuading end-users to respond to phishing emails. These insights may be used to inform tools and training procedures to detect phishing strategies in emails.