首页> 外文期刊>Information technology & people >How stage theorizing can improve recommendations against phishing attacks
【24h】

How stage theorizing can improve recommendations against phishing attacks

机译:阶段理论化如何改善针对网络钓鱼攻击的建议

获取原文
获取原文并翻译 | 示例
       

摘要

Purpose Phishing remains a major cybersecurity problem. Mainly adopting variance approaches, researchers have suggested several recommendations to help users avoid being victimized in phishing attacks. However, the evidence suggests that anti-phishing recommendations are not very effective. The purpose of this paper is threefold: first, to analyze why the existing anti-phishing recommendations may not be very effective; second, to propose stage theorizing as an additional approach for studying phishing that can contribute toward more effective recommendations; and third, to demonstrate using a stage theory, how IS researchers can utilize the concept of stages in phishing research. Design/methodology/approach The study draws on findings from previous empirical phishing research to assess whether the reasons why people are victimized in phishing attacks can be categorized into stages. The criteria for stages of the Transtheoretical Model (TTM) are used as an example. Findings Analysis indicates support for the existence of stages of phishing victims. The criteria for stages of the TTM were applied to the reasons that subjects in previous studies gave for clicking on phishing links and to the anti-phishing recommendations proposed in previous studies. There was overall support for four of the five criteria of the TTM. The results from the current study indicate that a targeted approach is a better approach to proposing anti-phishing recommendations. Originality/value From a phishing perspective, there is a lack of research based on stage theorizing. The current study presents stage theorizing as an additional approach to the existing approaches and demonstrates how a stage theory can be used to make more effective recommendations against phishing. The study has thrown light on the benefits of stage theorizing and how its approach to targeted recommendations can be useful in IS security research.
机译:目的网络钓鱼仍然是主要的网络安全问题。研究人员主要采用差异方法,提出了一些建议,以帮助用户避免遭受网络钓鱼攻击。但是,有证据表明,反网络钓鱼的建议不是很有效。本文的目的有三点:首先,分析为什么现有的反网络钓鱼建议可能不是很有效;第二,提出阶段理论,作为研究网络钓鱼的另一种方法,可以有助于制定更有效的建议;第三,为了证明使用阶段理论,信息系统研究人员如何在网络钓鱼研究中利用阶段的概念。设计/方法/方法该研究借鉴了以前的网络钓鱼实证研究的结果,以评估是否可以将人们在网络钓鱼攻击中受害的原因分为几个阶段。以跨理论模型(TTM)的阶段标准为例。结果分析表明支持网络钓鱼受害者阶段的存在。 TTM阶段的标准适用于先前研究中的受试者给出的点击网络钓鱼链接的原因以及先前研究中提出的反网络钓鱼建议。 TTM的五项标准中的四项得到了总体支持。当前研究的结果表明,有针对性的方法是提出反网络钓鱼建议的更好方法。创意/价值从网络钓鱼的角度来看,缺乏基于阶段理论的研究。当前的研究提出了阶段理论作为现有方法的一种补充方法,并演示了如何使用阶段理论来提出更有效的网络钓鱼建议。该研究揭示了阶段理论化的好处,以及其针对性建议的方法如何在IS安全研究中有用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号