首页> 外文会议>International Conference on Financial Cryptography and Data Security >The Importance of Being Earnest In Security Warnings
【24h】

The Importance of Being Earnest In Security Warnings

机译:认真对待安全警告的重要性

获取原文

摘要

In response to the threat of phishing, web browsers display warnings when users arrive at suspected phishing websites. Previous research has offered guidance to improve these warnings. We performed a laboratory study to investigate how the choice of background color in the warning and the text describing the recommended course of action impact a user's decision to comply with the warning. We did not reveal to participants that the subject of the study was the warning, and then we observed as they responded to a simulated phishing attack. We found that both the text and background color had a significant effect on the amount of time participants spent viewing a warning, however, we observed no significant differences with regard to their decisions to ultimately obey that warning. Despite this null result, our exit survey data suggest that misunderstandings about the threat model led participants to believe that the warnings did not apply to them. Acting out of bounded rationality, participants made conscientious decisions to ignore the warnings. We conclude that when warnings do not correctly align users' risk perceptions, users may unwittingly take avoidable risks.
机译:在响应网络钓鱼威胁时,Web浏览器在用户到达怀疑网络钓鱼网站时显示警告。以前的研究提供了改善这些警告的指导。我们执行了一个实验室研究,调查了如何在警告中选择背景颜色的选择以及描述建议的行动方案的文本会影响用户的决定遵守警告。我们没有向参与者透露,研究的主题是警告,然后我们观察到他们对模拟网络钓鱼攻击的反应。我们发现,文本和背景颜色都对参与者花费的时间效果显着影响,但是,我们观察到他们的决定没有显着差异,最终遵守警告。尽管如此,我们的出口调查数据表明,关于威胁模型的误解,LED参与者认为警告不适用于他们。脱离有界合理性,参与者取得了尽责的决定来忽视警告。我们得出的结论是,当警告不正确地对准用户的风险看法时,用户可能会不知不觉地采取可避免的风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号