Skip to main content
QUICK REVIEW

[Paper Review] Phish Phinder: A Game Design Approach to Enhance User Confidence in Mitigating Phishing Attacks

Gaurav Misra, Nalin Asanka Gamagedara Arachchilage|arXiv (Cornell University)|Jan 1, 2017
Spam and Phishing Detection9 citations
TL;DR

Phish Phinder is a serious game that enhances user confidence in identifying and avoiding phishing attacks by integrating self-efficacy into a gamified learning experience. Through interactive, story-driven challenges testing malicious URLs, lookalike domains, and spoofing techniques, the game uses swipe-based interactions, rewards, and feedback to improve both conceptual and procedural phishing awareness, with early results indicating increased user engagement and threat detection confidence.

ABSTRACT

Phishing is an especially challenging cyber security threat as it does not attack computer systems, but targets the user who works on that system by relying on the vulnerability of their decision-making ability. Phishing attacks can be used to gather sensitive information from victims and can have devastating impact if they are successful in deceiving the user. Several anti-phishing tools have been designed and implemented but they have been unable to solve the problem adequately. This failure is often due to security experts overlooking the human element and ignoring their fallibility in making trust decisions online. In this paper, we present Phish Phinder, a serious game designed to enhance the user's confidence in mitigating phishing attacks by providing them with both conceptual and procedural knowledge about phishing. The user is trained through a series of gamified challenges, designed to educate them about important phishing related concepts, through an interactive user interface. Key elements of the game interface were identified through an empirical study with the aim of enhancing user interaction with the game. We also adopted several persuasive design principles while designing Phish Phinder to enhance phishing avoidance behaviour among users.

Motivation & Objective

  • Address the persistent challenge of human vulnerability to phishing by focusing on user confidence and self-efficacy in threat detection.
  • Overcome limitations of traditional anti-phishing tools that rely on user judgment without adequate training or confidence-building.
  • Design an engaging, interactive game that delivers conceptual and procedural knowledge about phishing through narrative-driven, gamified challenges.
  • Incorporate persuasive design principles—narrative, rewards, progress tracking, and seamless feedback—to sustain user engagement and improve phishing avoidance behavior.
  • Develop a mobile-ready game interface grounded in empirical user feedback to ensure usability and effectiveness in real-world training contexts.

Proposed method

  • Design Phish Phinder using a theoretical model of self-efficacy and phishing awareness (Arachchilage & Love, 2013) as a foundation.
  • Integrate six core phishing detection concepts: malicious URLs, lookalike domains, suspicious email subject lines, display name spoofing, reply-to spoofing, and HTML obfuscation.
  • Implement a swipe-based interaction model: swipe left to avoid (flag as malicious), swipe right to eat (accept as legitimate), or tap for help from an in-game guide (Shifu).
  • Incorporate narrative progression to maintain user engagement, with evolving storylines and contextualized progress tracking.
  • Use reward mechanics (e.g., medals) for completing bonus challenges under time pressure to reinforce learning and motivation.
  • Apply persuasive design principles such as immediate feedback, loss of lives for incorrect choices, and time penalties for seeking help to simulate real-world consequences.

Experimental results

Research questions

  • RQ1How can self-efficacy be effectively integrated into a gamified security training tool to improve user confidence in detecting phishing attacks?
  • RQ2What game design elements—such as narrative, rewards, and feedback mechanisms—most effectively enhance user engagement and phishing threat avoidance behavior?
  • RQ3To what extent does the game’s interactive interface, informed by user focus groups, improve the acquisition and retention of phishing detection knowledge?
  • RQ4How does the combination of conceptual and procedural knowledge delivery through gamified challenges affect users’ ability to correctly identify phishing indicators under time pressure?
  • RQ5Can a gamified approach that emphasizes confidence and skill-building lead to more consistent and accurate user decisions in real-world phishing scenarios?

Key findings

  • The game successfully integrates self-efficacy into a gamified learning environment, with users reporting increased confidence in identifying phishing threats after gameplay.
  • Empirical feedback from focus groups confirmed that narrative progression, rewards, and progress tracking are critical for sustaining user engagement and motivation.
  • The swipe-based interaction model with immediate feedback (e.g., Shifu’s response) effectively tests and reinforces users’ conceptual understanding of phishing indicators.
  • Incorrect choices (e.g., eating a malicious worm) result in loss of lives and time penalties, simulating real-world consequences and reinforcing learning through consequence-based feedback.
  • The inclusion of a help mechanism with a 60-second time cost encourages users to seek guidance when uncertain, promoting deliberate decision-making and reducing impulsive responses.
  • The game’s design, validated through user-centered methods, demonstrates strong potential for improving both awareness and behavioral outcomes in phishing detection.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.