【24h】

EyeBit: Eye-Tracking Approach for Enforcing Phishing Prevention Habits

机译:eyebit:用于执行网络钓鱼预防习惯的眼跟踪方法

获取原文

摘要

This paper proposes a cognitive method with the goal to get end users into the habit of checking the address bar of the web browser. Earlier surveys of end user behavior emphasized that users become victims to phishing due to the lack of knowledge about the structure of URLs, domain names, and security information. Therefore, there exist many approaches to improve the knowledge of end users. However, the knowledge gained will not be applied unless end users are aware of the importance and develop a habit to check the browser's address bar for the URL structure and relevant security information. We assume that the habit of checking the bar will improve educational effect, user awareness of secure information, and detection accuracy even in the case of sophisticated phishing attacks. To assess this assumption, this paper conducts a participant-based experiment where 23 participants' eye movement records are analyzed, and observes that novices do not tend to have the said habit. We then consider a way for them to acquire these habits, and develop a system which requires them to look at the address bar before entering some information into web input forms. Our prototype named EyeBit is developed as a browser extension, which interacts with an eye-tracking device to check if the user looks at the browser's address bar. The system deactivates all input forms of the websites, and reactivates them only if the user has looked at the bar. This paper shows the preliminary results of our participant-based experiments, and discusses the effectiveness of our proposal, while considering the potential inconvenience caused by EyeBit.
机译:本文提出了一种认知方法,目标是将最终用户纳入检查Web浏览器的地址栏的习惯。早期的最终用户行为调查强调,由于缺乏关于网址,域名和安全信息的结构缺乏了解,用户成为网络钓鱼的受害者。因此,存在许多方法来提高最终用户的知识。但是,除非最终用户知道重要性并制定习惯来检查浏览器的地址栏以及相关安全信息,否则将无法应用所获得的知识。我们假设检查酒吧的习惯将提高教育效果,用户对安全信息的认识,以及即使在复杂的网络钓鱼攻击的情况下也是如此的检测准确性。为了评估这一假设,本文进行了一个基于参与者的实验,分析了23名参与者的眼球运动记录,并观察到新手不会倾向于有上述习惯。然后,我们考虑他们获取这些习惯的方法,并开发一个系统,该系统需要他们在输入一些信息进入Web输入表单之前查看地址栏。我们的原型名为EyeBit被开发为浏览器扩展,其与眼跟踪设备交互以检查用户是否查看浏览器的地址栏。该系统取消激活网站的所有输入形式,只有在用户看栏时才会重新激活它们。本文展示了我们参与者的实验的初步结果,并讨论了我们提案的有效性,同时考虑到eyebit造成的潜在不便。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号