首页> 外文学位 >PhishGuru: A system for educating users about semantic attacks.
【24h】

PhishGuru: A system for educating users about semantic attacks.

机译:PhishGuru:一种用于教育用户有关语义攻击的系统。

获取原文
获取原文并翻译 | 示例

摘要

Online security attacks are a growing concern among Internet users. Currently, the Internet community is facing three types of security attacks: physical, syntactic, and semantic. Semantic attacks take advantage of the way humans interact with computers or interpret messages. There are three major approaches to counter semantic attacks: silently eliminating the attacks, warning users about the attacks, and training users not to fall for the attacks. The existing methods for silently eliminating the attack and warning users about the attack are unlikely to perform flawlessly and as users are the weakest link in these attacks, it is essential that user training complement other methods. The goal of my thesis is to show that computer users trained with an embedded training system, one grounded in the principles of learning science are able to make more accurate online trust decisions than users who read traditional security training materials, which are distributed via email or posted online. To achieve this goal, I focus on "phishing," a type of semantic attack. I have developed a system called "PhishGuru" based on embedded training methodology and learning science principles. Embedded training is a methodology in which training materials are integrated into the primary tasks users perform in their day-to-day lives. In contrast to existing training methodologies, the PhishGuru shows training materials to users through emails at the moment ("teachable moment") users actually fall for phishing attacks. I evaluated the embedded training methodology through laboratory and field studies. Real-world experiments showed that people trained with PhishGuru retain knowledge even after 28 days. PhishGuru training does not decrease users' willingness to click on links in legitimate messages. The design principles established in this thesis will help researchers to develop systems that can train users in other risky online situations. PhishGuru is also being used in a real-world implementation of the Anti-Phishing Working Group Landing Page initiative. PhishGuru is currently being commercialized by Wombat Security Technologies. http://www.cs.cmu.edu/∼ponguru/PK defense.html.
机译:在线安全攻击已成为Internet用户越来越关注的问题。当前,Internet社区面临三种类型的安全攻击:物理,语法和语义。语义攻击利用了人类与计算机交互或解释消息的方式。应对语义攻击的方法主要有三种:静默消除攻击,警告用户有关攻击以及培训用户不要遭受攻击。静默消除攻击并警告用户攻击的现有方法不可能完美无缺地执行,并且由于用户是这些攻击中最薄弱的环节,因此用户培训必须补充其他方法。我的论文的目的是表明,以嵌入式培训系统为基础进行培训的计算机用户(以学习科学的原理为基础)比阅读通过电子邮件或电子邮件分发的传统安全培训材料的用户能够做出更准确的在线信任决策。在线发布。为了实现此目标,我专注于“网络钓鱼”,这是一种语义攻击。我已经基于嵌入式培训方法和学习科学原理开发了一个名为“ PhishGuru”的系统。嵌入式培训是一种将培训材料集成到用户日常生活中执行的主要任务中的方法。与现有的培训方法相比,PhishGuru在用户实际陷入网络钓鱼攻击的那一刻(“可学习的时刻”)通过电子邮件向用户显示培训材料。我通过实验室和现场研究评估了嵌入式培训方法。真实世界的实验表明,经过PhishGuru培训的人即使在28天之后仍能保留知识。 PhishGuru培训不会降低用户点击合法邮件中链接的意愿。本文确立的设计原则将帮助研究人员开发可在其他风险在线情况下培训用户的系统。 PhishGuru还被用于反网络钓鱼工作组着陆页计划的实际实施中。 PhishGuru目前正由Wombat Security Technologies商业化。 http://www.cs.cmu.edu/~ponguru/PKdefence.html。

著录项

  • 作者

    Kumaraguru, Ponnurangam.;

  • 作者单位

    Carnegie Mellon University.;

  • 授予单位 Carnegie Mellon University.;
  • 学科 Education Technology of.;Computer Science.
  • 学位 Ph.D.
  • 年度 2009
  • 页码 184 p.
  • 总页数 184
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号