[论文解读] Integrating self-efficacy into a gamified approach to thwart phishing attacks
本文提出了一种游戏化的教育工具,通过整合关于网络钓鱼检测的概念性知识与程序性知识,提升用户的自我效能感,从而增强用户对网络钓鱼威胁的规避行为。该游戏结合了交互式URL分析、渐进式难度等级以及游戏内提示,以建立用户的自信心与动机,证明知识整合能显著提升自我效能感与对网络钓鱼的抵抗力。
Security exploits can include cyber threats such as computer programs that can disturb the normal behavior of computer systems (viruses), unsolicited e-mail (spam), malicious software (malware), monitoring software (spyware), attempting to make computer resources unavailable to their intended users (Distributed Denial-of-Service or DDoS attack), the social engineering, and online identity theft (phishing). One such cyber threat, which is particularly dangerous to computer users is phishing. Phishing is well known as online identity theft, which targets to steal victims' sensitive information such as username, password and online banking details. This paper focuses on designing an innovative and gamified approach to educate individuals about phishing attacks. The study asks how one can integrate self-efficacy, which has a co-relation with the user's knowledge, into an anti-phishing educational game to thwart phishing attacks? One of the main reasons would appear to be a lack of user knowledge to prevent from phishing attacks. Therefore, this research investigates the elements that influence (in this case, either conceptual or procedural knowledge or their interaction effect) and then integrate them into an anti-phishing educational game to enhance people's phishing prevention behaviour through their motivation.
研究动机与目标
- 为解决终端用户作为网络安全中‘最薄弱环节’的持续性脆弱性,尤其是在网络钓鱼攻击方面。
- 探究自我效能感——由概念性与程序性知识塑造——如何被有效利用以改善网络钓鱼威胁规避行为。
- 设计一种游戏化教育干预措施,系统性地整合两类知识,以提升用户动机与安全意识。
- 开发一种基于游戏的学习环境,提供即时反馈与自适应挑战,以维持用户参与度并建立信心。
- 创建一种可扩展的、以用户为中心的安全教育模型,适用于政府机构、学校及公共部门。
提出的方法
- 游戏分为初级、中级与高级三个难度等级,逐步提升URL模式的复杂性,以测试程序性知识。
- 玩家需识别URL中的网络钓鱼指标,如可疑域名或数字型子域名,以评估概念性知识。
- ‘帮助’系统允许玩家向‘大鱼’角色咨询提示(例如:‘公司名称后出现连字符通常表示诈骗’),模拟现实世界中的指导。
- 每次使用帮助功能将减少剩余时间100秒,引入使用成本以鼓励独立检测并强化学习效果。
- 应用社会认知理论的理论基础,强调概念性与程序性知识对自我效能感的交互影响。
- 游戏设计整合了时间压力、渐进式难度与反馈循环等激励元素,以维持参与度并建立信心。
实验结果
研究问题
- RQ1如何在游戏化反网络钓鱼教育工具中有效整合自我效能感,以改善用户行为?
- RQ2在网络钓鱼检测中,概念性知识与程序性知识对自我效能感的相对影响是什么?
- RQ3概念性知识与程序性知识之间的交互作用如何影响自我效能感与网络钓鱼威胁规避行为?
- RQ4游戏化学习环境在多大程度上能提升反网络钓鱼教育中的动机与知识保留?
- RQ5基于游戏的方法是否能通过渐进式、反馈驱动的挑战有效训练用户识别网络钓鱼URL?
主要发现
- 在游戏化情境中整合概念性与程序性知识,能显著提升用户在检测网络钓鱼威胁方面的自我效能感。
- 概念性与程序性知识之间的交互效应被发现对自我效能感具有积极影响,从而导致更强的网络钓鱼威胁规避行为。
- 使用游戏内提示(例如:‘公司名称后出现连字符通常表示诈骗’)改善了学习效果,同时保持时间压力作为激励因素。
- 从初级到高级的渐进式难度等级,有效提升了玩家的参与度与技能发展。
- 游戏设计成功创建了一个具有激励性、反馈丰富的环境,通过即时后果维持注意力并强化学习。
- 所提出的框架具有可扩展性,适用于学校与政府机构等公共机构部署,以提升国家网络安全意识。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。