首页> 外文会议>Innovations in Information Technology (IIT), 2012 International Conference on >Phishing in a university community: Two large scale phishing experiments
【24h】

Phishing in a university community: Two large scale phishing experiments

机译:大学社区中的网络钓鱼:两次大型网络钓鱼实验

获取原文
获取原文并翻译 | 示例

摘要

Phishing is a type of social engineering where a potential victim is sent a message that impersonates a legitimate source or organization. Phishing attacks typically lure the targets into revealing confidential information such as password, credit card details, bank account numbers, or any other sensitive information. Human behavior and technology are two equally important aspects of phishing attacks, while current anti-phishing research have focused on the technology front, very few real life studies have been performed with a focus on the human aspects of phishing attacks. In this paper, we present the results of two large scale real life phishing attacks conducted on more than 10,000 community members of a university that includes students, alumni, faculty and staff. Our study is the first large scale phishing experiment on human subjects. Previous work suggests that users' demographics are useful indicators in identifying the most vulnerable users to phishing attacks. Our results illustrate that user demographics alone cannot predict user's susceptibility to phishing attacks. We also found that warning users about phishing risks alone is not sufficient to prevent more users from responding to the phishing attack. Even though subjects were warned not to respond to phishing emails, many disregarded the warning. We explain our findings through analysis of the empirical results of the two real life phishing attacks conducted.
机译:网络钓鱼是一种社会工程,向潜在的受害者发送模仿合法来源或组织的消息。网络钓鱼攻击通常诱使目标泄露机密信息,例如密码,信用卡详细信息,银行帐号或任何其他敏感信息。人类行为和技术是网络钓鱼攻击的两个同等重要的方面,尽管当前的反网络钓鱼研究集中在技术方面,但很少进行针对钓鱼攻击的人类方面的现实生活研究。在本文中,我们介绍了对一所大学的10,000多名社区成员(包括学生,校友,教职员工)进行的两次大规模的网络钓鱼攻击的结果。我们的研究是针对人类受试者的第一个大规模网络钓鱼实验。先前的工作表明,用户的人口统计信息是确定最容易受到网络钓鱼攻击的用户的有用指标。我们的结果表明,仅凭用户统计资料就无法预测用户对网络钓鱼攻击的敏感性。我们还发现仅警告用户有关网络钓鱼的风险还不足以阻止更多用户响应网络钓鱼攻击。即使警告对象不要对网络钓鱼电子邮件做出响应,但许多人还是忽略了该警告。我们通过分析两次实际钓鱼攻击的经验结果来解释我们的发现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号