Skip to main content
QUICK REVIEW

[论文解读] Falling for Phishing: An Empirical Investigation into People's Email Response Behaviors

Asangi Jayatilaka, Nalin Asanka Gamagedara Arachchilage|arXiv (Cornell University)|Aug 10, 2021
Spam and Phishing Detection参考文献 35被引用 7
一句话总结

本研究通过一项包含19名参与者的思考 aloud 用户实验,在模拟电子邮件环境中探究人们为何会受钓鱼邮件欺骗。研究识别出11项影响电子邮件响应决策的认知与情境因素,揭示了人类电子邮件决策中存在的系统性缺陷,这些缺陷削弱了当前的安全培训与检测系统的效果。

ABSTRACT

Despite sophisticated phishing email detection systems, and training and awareness programs, humans continue to be tricked by phishing emails. In an attempt to better understand why phishing email attacks still work and how best to mitigate them, we have carried out an empirical study to investigate people's thought processes when reading their emails. We used a scenario-based role-play "think aloud" method and follow-up interviews to collect data from 19 participants. The experiment was conducted using a simulated web email client, and real phishing and legitimate emails adapted to the given scenario. The analysis of the collected data has enabled us to identify eleven factors that influence people's response decisions to both phishing and legitimate emails. Furthermore, based on the user study findings, we discuss novel insights into flaws in the general email decision-making behaviors that could make people susceptible to phishing attacks.

研究动机与目标

  • 理解导致个体在已有检测与培训机制下仍响应钓鱼邮件的认知与行为因素。
  • 调查人们在真实情境下的实时决策过程中如何评估钓鱼邮件与合法邮件的可信度。
  • 识别人类电子邮件响应行为中的系统性缺陷,这些缺陷导致其易受社会工程攻击。
  • 通过基于实证的人类行为研究,为设计更有效的钓鱼邮件检测系统与用户培训项目提供依据。
  • 探讨情境线索、紧迫感与发件人可信度在塑造用户对邮件内容反应中的作用。

提出的方法

  • 通过基于情景的角色扮演研究,使用模拟的网页电子邮件客户端,以复现真实世界的电子邮件环境。
  • 采用“思考 aloud”协议,让参与者在评估真实钓鱼邮件与合法邮件时口头表达其思维过程。
  • 通过后续访谈收集定性数据,以深化对决策依据的理解。
  • 使用主题分析法识别影响电子邮件响应决策的重复性模式与影响因素。
  • 对真实钓鱼邮件与合法邮件进行改编,以契合特定的情景背景,确保生态效度。
  • 重点识别导致对邮件真实性误判的认知启发式与情境线索。

实验结果

研究问题

  • RQ1哪些认知与情境因素影响个体对钓鱼邮件与合法邮件的响应决策?
  • RQ2用户在模拟环境中实时评估邮件时,如何判断邮件的可信度?
  • RQ3紧迫感、发件人身份与邮件内容在塑造用户对邮件的反应中起到何种作用?
  • RQ4当前的安全意识培训为何未能解决钓鱼邮件易感性的根本原因?
  • RQ5人类电子邮件决策过程中的哪些系统性缺陷使用户容易受到社会工程攻击?

主要发现

  • 识别出11项显著影响用户对钓鱼邮件与合法邮件响应决策的独立因素,包括紧迫感、发件人熟悉度与邮件结构。
  • 参与者频繁依赖启发式线索(如语气与格式),而非技术性指标(如邮件头信息或域名验证)。
  • 即使具备安全意识培训,用户在显示名称看似合法时,仍常无法识别伪造的邮件地址。
  • 紧迫感与基于恐惧的措辞显著提高了响应可能性,无论邮件是否真实。
  • 用户表现出不一致的评估标准,根据对发件人可信度的感知,对相似邮件应用不同判断标准。
  • 本研究揭示,当前的安全培训未能充分应对导致钓鱼邮件易感性的认知捷径。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。