Why phishing still works

International Journal of Human-Computer Studies(2015)

引用 123|浏览30
暂无评分
摘要
We have conducted a user study to assess whether improved browser security indicators and increased awareness of phishing have led to users׳ improved ability to protect themselves against such attacks. Participants were shown a series of websites and asked to identify the phishing websites. We use eye tracking to obtain objective quantitative data on which visual cues draw users׳ attention as they determine the legitimacy of websites. Our results show that users successfully detected only 53% of phishing websites even when primed to identify them and that they generally spend very little time gazing at security indicators compared to website content when making assessments. However, we found that gaze time on browser chrome elements does correlate to increased ability to detect phishing. Interestingly, users׳ general technical proficiency does not correlate with improved detection scores.
更多
查看译文
关键词
Phishing,Eye tracking,Usable security,User study
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要