Skip to main content
QUICK REVIEW

[论文解读] Gone Quishing: A Field Study of Phishing with Malicious QR Codes

Filipo Sharevski, Amy Devine|arXiv (Cornell University)|Apr 8, 2022
Spam and Phishing Detection被引用 8
一句话总结

本实地研究通过模拟新冠状病毒数字护照注册过程,调查了通过恶意二维码实施的钓鱼攻击(即quishing)。研究发现,67%的参与者因便利性而自愿分享了Google或Facebook账号密码,反映出对quishing攻击的认知水平较低,并提出了Quishing意识量表(QAS)及可用性安全提示,以提升用户防护能力。

ABSTRACT

The COVID-19 pandemic enabled "quishing", or phishing with malicious QR codes, as they became a convenient go-between for sharing URLs, including malicious ones. To explore the quishing phenomenon, we conducted a 173-participant study where we used a COVID-19 digital passport sign-up trial with a malicious QR code as a pretext. We found that 67 % of the participants were happy to sign-up with their Google or Facebook credentials, 18.5% to create a new account, and only 14.5% to skip on the sign-up. Convenience was the single most cited factor for the willingness to yield participants' credentials. Reluctance of linking personal accounts with new services was the reason for creating a new account or skipping the registration. We also developed a Quishing Awareness Scale (QAS) and found a significant relationship between participants' QR code behavior and their sign-up choices: the ones choosing to sign-up with Facebook scored the lowest while the one choosing to skip the highest on average. We used our results to propose quishing awareness training guidelines and develop and test usable security indicators for warning users about the threat of quishing.

研究动机与目标

  • 在新冠状病毒疫情期间,调查用户在真实世界条件下对quishing攻击的易感性。
  • 评估便利性和信任在用户通过二维码分享凭证意愿中的作用。
  • 开发并验证用于衡量个体quishing易感性差异的Quishing意识量表(QAS)。
  • 设计并测试可在不破坏可用性的前提下警示用户quishing威胁的可用性安全提示。
  • 基于实证研究结果,提供可操作的quishing意识培训指导方案。

提出的方法

  • 通过173名参与者的实地研究,以真实的新冠状病毒数字护照注册作为情境预设。
  • 在一份经CDC授权的海报中嵌入恶意二维码,以模拟合法的数字疫苗接种注册流程。
  • 测量参与者的注册选择:使用Facebook/Google凭证、创建新账户,或跳过注册。
  • 基于行为模式开发Quishing意识量表(QAS),并验证其可靠性。
  • 设计并测试了用于移动设备的原型安全提示,以标识潜在的quishing风险。
  • 分析安全警告的时间成本-收益权衡,并通过后续调查评估用户偏好。

实验结果

研究问题

  • RQ1当用户优先考虑便利性而非安全性时,其对quishing攻击的易感性如何?
  • RQ2影响用户通过二维码分享凭证决策的因素是什么——便利性、信任,还是意识水平?
  • RQ3用户quishing意识与其注册行为之间是否存在可测量的相关性?
  • RQ4可用性安全提示能否在不引发可用性摩擦的前提下有效警告用户quishing威胁?
  • RQ5如何基于实证行为数据设计quishing意识培训?

主要发现

  • 67%的参与者自愿使用其Google或Facebook凭证进行注册,优先考虑便利性而非安全性。
  • 仅14.5%的参与者选择跳过注册,表明对凭证共享的抵抗意愿较低。
  • 使用Facebook凭证的参与者在Quishing意识量表(QAS)上得分最低,表明其意识水平较低。
  • 选择跳过注册的参与者在QAS上得分最高,表明其对quishing风险有更高的认知。
  • 研究发现二维码行为与注册选择之间存在显著相关性,验证了QAS作为可靠测量工具的有效性。
  • 综合时间成本与可用性的安全提示,相较于传统警告机制,在quishing情境下更具有效性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。