首页> 外文会议>ACM Conference on Human Factors in Computing Systems >Who Provides Phishing Training? Facts, Stories, and People Like Me
【24h】

Who Provides Phishing Training? Facts, Stories, and People Like Me

机译:谁提供网络钓鱼培训? 事实,故事和像我这样的人

获取原文

摘要

Humans represent one of the most persistent vulnerabilities in many computing systems. Since human users are independent agents who make their own choices, closing these vulnerabilities means persuading users to make different choices. Focusing on one specific human choice - clicking on a link in a phishing email - we conducted an experiment to identify better ways to train users to make more secure decisions. We compared traditional facts-and-advice training against training that uses a simple story to convey the same lessons. We found a surprising interaction effect: facts-and-advice training works better than not training users, but only when presented by a security expert. Stories don't work quite as well as facts-and-advice, but work much better when told by a peer. This suggests that the perceived origin of training materials can have a surprisingly large effect on security outcomes.
机译:人类代表了许多计算系统中最持久的漏洞之一。 由于人类用户是自行选择的独立代理,关闭这些漏洞意味着说服用户进行不同的选择。 专注于一个特定的人类选择 - 点击网络钓鱼电子邮件中的链接 - 我们进行了一个实验,以确定培训用户做出更安全决策的更好方法。 我们比较了传统的事实和建议训练,以防止使用一个简单的故事来传达相同的课程。 我们发现了一个令人惊讶的互动效果:事实和建议培训的工作比不是培训用户更好,但只有在安全专家呈现时。 故事不太作用以及事实和建议,但是在同行告诉我们时的工作要好得多。 这表明培训材料的感知起源可能对安全结果有一个令人惊讶的巨大影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号