首页> 外文期刊>Human Factors >Embedding Training Within Warnings Improves Skills of Identifying Phishing Webpages
【24h】

Embedding Training Within Warnings Improves Skills of Identifying Phishing Webpages

机译:将培训嵌入警告中可提高识别网络钓鱼网页的技能

获取原文
获取原文并翻译 | 示例
       

摘要

Objective: Evaluate the effectiveness of training embedded within security warnings to identify phishing webpages. Background: More than 20 million malware and phishing warnings are shown to users of Google Safe Browsing every week. Substantial click-through rate is still evident, and a common issue reported is that users lack understanding of the warnings. Nevertheless, each warning provides an opportunity to train users about phishing and how to avoid phishing attacks. Method: To test use of phishing-warning instances as opportunities to train users' phishing webpage detection skills, we conducted an online experiment contrasting the effectiveness of the current Chrome phishing warning with two training-embedded warning interfaces. The experiment consisted of three phases. In Phase 1, participants made login decisions on 10 webpages with the aid of warning. After a distracting task, participants made legitimacy judgments for 10 different login webpages without warnings in Phase 2. To test the long-term effect of the training, participants were invited back a week later to participate in Phase 3, which was conducted similarly as Phase 2. Results: Participants differentiated legitimate and fraudulent webpages better than chance. Performance was similar for all interfaces in Phase 1 for which the warning aid was present. However, training-embedded interfaces provided better protection than the Chrome phishing warning on both subsequent phases. Conclusion: Embedded training is a complementary strategy to compensate for lack of phishing webpage detection skill when phishing warning is absent. Application: Potential applications include development of training-embedded warnings to enable security training at scale.
机译:目标:评估嵌入在安全警告中以识别网络钓鱼网页的培训的有效性。背景:每周向Google安全浏览用户显示超过2000万的恶意软件和网络钓鱼警告。相当高的点击率仍然很明显,并且报告的一个常见问题是用户对警告缺乏理解。但是,每种警告都提供了培训用户有关网络钓鱼以及如何避免网络钓鱼攻击的机会。方法:为了测试使用网络钓鱼警告实例作为培训用户网络钓鱼网页检测技能的机会,我们进行了一个在线实验,将当前的Chrome网络钓鱼警告的有效性与两个内置培训的警告界面进行了对比。实验包括三个阶段。在第1阶段,参与者借助警告在10个网页上做出了登录决定。在完成一项令人分神的任务后,参与者在第2阶段对10个不同的登录网页进行了合法性判断,而没有发出警告。为测试培训的长期效果,一周后又邀请参与者参加第3阶段,该阶段与第3阶段相似2.结果:与众不同,参与者区分合法和欺诈性网页更好。对于第1阶段中存在警告辅助功能的所有接口,其性能都相似。但是,在随后的两个阶段中,与培训的嵌入式界面相比,Chrome钓鱼警告提供了更好的保护。结论:嵌入式培训是一种补充策略,可以在没有网络钓鱼警告的情况下弥补网络钓鱼网页检测技能的不足。应用程序:潜在的应用程序包括开发嵌入式培训警告,以实现大规模的安全培训。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号