论文标题

SOK:以人为本的网络钓鱼敏感性

SoK: Human-Centered Phishing Susceptibility

论文作者

Zhuo, Sijie, Biddle, Robert, Koh, Yun Sing, Lottridge, Danielle, Russello, Giovanni

论文摘要

网络钓鱼被认为是对组织和个人的严重威胁。尽管在阻止网络钓鱼攻击方面取得了重大的技术进步,但在网络钓鱼电子邮件到达电子邮件客户端后,人们仍然是最后的防线。有关该主题的大多数现有文献都集中在与网络钓鱼有关的技术方面。但是,导致人类容易受到网络钓鱼攻击的因素仍然没有得到很好的理解。为了填补这一空白,我们回顾了可用的文献,并提出了一个三阶段的网络钓鱼易感性模型(PSM),以解释人类如何参与网络钓鱼检测和预防,并且我们系统地研究了文献中研究的网络钓鱼易感变量,并使用我们的模型将其分类。该模型揭示了需要解决的几个研究空白,以提高用户的检测性能。我们还提出了研究网络钓鱼易感变量和证据标准质量的实际影响评估。这些可以作为未来研究的指南,以改善实验设计,结果质量并提高发现的可靠性和普遍性。

Phishing is recognised as a serious threat to organisations and individuals. While there have been significant technical advances in blocking phishing attacks, people remain the last line of defence after phishing emails reach their email client. Most of the existing literature on this subject has focused on the technical aspects related to phishing. However, the factors that cause humans to be susceptible to phishing attacks are still not well-understood. To fill this gap, we reviewed the available literature and we propose a three-stage Phishing Susceptibility Model (PSM) for explaining how humans are involved in phishing detection and prevention, and we systematically investigate the phishing susceptibility variables studied in the literature and taxonomize them using our model. This model reveals several research gaps that need to be addressed to improve users' detection performance. We also propose a practical impact assessment of the value of studying the phishing susceptibility variables, and quality of evidence criteria. These can serve as guidelines for future research to improve experiment design, result quality, and increase the reliability and generalizability of findings.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源