[论文解读] Phish Phinder: A Game Design Approach to Enhance User Confidence in Mitigating Phishing Attacks
Phish Phinder 是一款严肃游戏,通过将自我效能感融入游戏化学习体验,提升用户识别和避免网络钓鱼攻击的信心。该游戏通过互动式、叙事驱动的挑战,测试恶意URL、相似域名和伪装技术等,利用滑动操作、奖励机制和即时反馈,提升用户在概念性和程序性网络钓鱼意识方面的认知,初步结果显示用户参与度和威胁检测信心均有所提高。
Phishing is an especially challenging cyber security threat as it does not attack computer systems, but targets the user who works on that system by relying on the vulnerability of their decision-making ability. Phishing attacks can be used to gather sensitive information from victims and can have devastating impact if they are successful in deceiving the user. Several anti-phishing tools have been designed and implemented but they have been unable to solve the problem adequately. This failure is often due to security experts overlooking the human element and ignoring their fallibility in making trust decisions online. In this paper, we present Phish Phinder, a serious game designed to enhance the user's confidence in mitigating phishing attacks by providing them with both conceptual and procedural knowledge about phishing. The user is trained through a series of gamified challenges, designed to educate them about important phishing related concepts, through an interactive user interface. Key elements of the game interface were identified through an empirical study with the aim of enhancing user interaction with the game. We also adopted several persuasive design principles while designing Phish Phinder to enhance phishing avoidance behaviour among users.
研究动机与目标
- 解决人类在面对网络钓鱼时持续存在的脆弱性问题,聚焦于用户在威胁检测中的信心与自我效能感。
- 克服传统反钓鱼工具的局限性——这些工具依赖用户判断,却缺乏充分的培训或信心建设。
- 设计一款引人入胜、互动性强的游戏,通过叙事驱动的、游戏化的挑战,传递关于网络钓鱼的概念性与程序性知识。
- 融入说服性设计原则——包括叙事、奖励、进度追踪和无缝反馈,以维持用户参与度,并改善网络钓鱼规避行为。
- 开发一个基于实证用户反馈的移动端友好游戏界面,确保在真实世界培训场景中的可用性与有效性。
提出的方法
- 基于自我效能感与网络钓鱼意识的理论模型(Arachchilage & Love, 2013)设计 Phish Phinder。
- 整合六项核心网络钓鱼检测概念:恶意URL、相似域名、可疑邮件主题行、显示名称伪装、回复地址伪装以及HTML混淆技术。
- 实施基于滑动的操作模式:向左滑动以避免(标记为恶意),向右滑动以“食用”(接受为合法),或轻触以获取游戏内向导(Shifu)的帮助。
- 通过叙事推进保持用户参与度,包含不断演进的故事情节与情境化的进度追踪。
- 采用奖励机制(如奖牌)来奖励用户在时间压力下完成附加挑战,以强化学习效果与动机。
- 应用说服性设计原则,如即时反馈、错误选择导致生命值损失,以及求助时的时间惩罚,以模拟现实世界后果。
实验结果
研究问题
- RQ1如何有效将自我效能感整合到游戏化安全培训工具中,以提升用户在识别网络钓鱼攻击时的信心?
- RQ2哪些游戏设计元素——如叙事、奖励和反馈机制——最能有效提升用户参与度与网络钓鱼威胁规避行为?
- RQ3在用户焦点小组反馈的指导下,该游戏的互动界面在多大程度上改善了网络钓鱼检测知识的获取与保持?
- RQ4通过游戏化挑战同时传递概念性与程序性知识,如何影响用户在时间压力下正确识别网络钓鱼指标的能力?
- RQ5一种强调信心与技能培养的游戏化方法,是否能带来更一致且准确的用户决策,从而应对现实世界中的网络钓鱼场景?
主要发现
- 该游戏成功地将自我效能感融入游戏化学习环境,用户在游戏后报告其识别网络钓鱼威胁的信心显著提升。
- 焦点小组的实证反馈证实,叙事推进、奖励机制和进度追踪是维持用户参与度与动机的关键因素。
- 基于滑动的操作模式配合即时反馈(如Shifu的回应),有效测试并强化了用户对网络钓鱼指标的概念性理解。
- 错误选择(如“食用”恶意蠕虫)会导致生命值损失与时间惩罚,模拟现实后果,通过基于后果的反馈强化学习效果。
- 帮助机制设有60秒时间成本,鼓励用户在不确定时主动寻求指导,促进深思熟虑的决策,减少冲动反应。
- 经用户中心方法验证的游戏设计,展现出在提升网络钓鱼检测意识与行为结果方面的强大潜力。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。