在模拟社会工程攻击中测量用户判断错误的实验程序的试点测试

Tommy Pollock, Y. Levy, Wei Li, Ajoy Kumar
{"title":"在模拟社会工程攻击中测量用户判断错误的实验程序的试点测试","authors":"Tommy Pollock, Y. Levy, Wei Li, Ajoy Kumar","doi":"10.36965/ojakm.2022.10(2)23-40","DOIUrl":null,"url":null,"abstract":"Distracted users appear to have difficulties correctly distinguishing between legitimate and malicious emails or search engine results. Additionally, mobile phone users appear to have a more challenging time identifying malicious content due to the smaller screen size and the limited security features in mobile phone applications. Thus, the goal of this research study was to conduct a pilot test and validate a set of field experiments based on Subject Matter Experts (SMEs) feedback to assess users’ judgment when exposed to two types of simulated social engineering attacks: phishing and Potentially Malicious Search Engine Results (PMSER), based on the interaction of the environment (distracting vs. non-distracting) and type of device used (mobile vs. computer). This paper provides the results from the pilot test we conducted using recruited volunteers consisting of 10 participants out of 20 volunteers invited. Due to COVID-19 restrictions, all interactions in this pilot testing were conducted remotely. These restrictions somewhat limited our ability to control the testing environment to ensure a completely non-distractive environment during these parts of the study; however, a significant attempt was made to ensure such a non-distractive environment was genuinely adhered to during that part of the study. Our initial pilot testing results indicate that the findings were counterintuitive for the Phishing Intelligence Quotient (IQ) tests. In contrast, results of the PMSER were intuitive with improved detection on a computer compared to mobile. We conclude with a discussion on the study limitations and further research.","PeriodicalId":325473,"journal":{"name":"Online Journal of Applied Knowledge Management","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-09-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Pilot testing of experimental procedures to measure user's judgment errors in simulated social engineering attacks\",\"authors\":\"Tommy Pollock, Y. Levy, Wei Li, Ajoy Kumar\",\"doi\":\"10.36965/ojakm.2022.10(2)23-40\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Distracted users appear to have difficulties correctly distinguishing between legitimate and malicious emails or search engine results. Additionally, mobile phone users appear to have a more challenging time identifying malicious content due to the smaller screen size and the limited security features in mobile phone applications. Thus, the goal of this research study was to conduct a pilot test and validate a set of field experiments based on Subject Matter Experts (SMEs) feedback to assess users’ judgment when exposed to two types of simulated social engineering attacks: phishing and Potentially Malicious Search Engine Results (PMSER), based on the interaction of the environment (distracting vs. non-distracting) and type of device used (mobile vs. computer). This paper provides the results from the pilot test we conducted using recruited volunteers consisting of 10 participants out of 20 volunteers invited. Due to COVID-19 restrictions, all interactions in this pilot testing were conducted remotely. These restrictions somewhat limited our ability to control the testing environment to ensure a completely non-distractive environment during these parts of the study; however, a significant attempt was made to ensure such a non-distractive environment was genuinely adhered to during that part of the study. Our initial pilot testing results indicate that the findings were counterintuitive for the Phishing Intelligence Quotient (IQ) tests. In contrast, results of the PMSER were intuitive with improved detection on a computer compared to mobile. We conclude with a discussion on the study limitations and further research.\",\"PeriodicalId\":325473,\"journal\":{\"name\":\"Online Journal of Applied Knowledge Management\",\"volume\":\"7 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-09-15\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Online Journal of Applied Knowledge Management\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.36965/ojakm.2022.10(2)23-40\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Online Journal of Applied Knowledge Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.36965/ojakm.2022.10(2)23-40","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

分心的用户似乎很难正确区分合法和恶意的电子邮件或搜索引擎结果。此外,由于手机屏幕尺寸较小,而且手机应用程序的安全功能有限,手机用户在识别恶意内容方面似乎面临着更大的挑战。因此,本研究的目标是根据主题专家(sme)的反馈进行试点测试并验证一组现场实验,以评估用户在暴露于两种类型的模拟社会工程攻击时的判断:网络钓鱼和潜在恶意搜索引擎结果(PMSER),基于环境的相互作用(分散与非分散)和使用的设备类型(移动与计算机)。本文提供了我们进行的试点测试的结果,我们从邀请的20名志愿者中招募了10名志愿者。由于COVID-19的限制,本次试点测试中的所有互动都是远程进行的。这些限制在一定程度上限制了我们控制测试环境的能力,以确保在研究的这些部分中完全没有分心的环境;然而,为了确保在这部分研究中真正坚持这样一个不分散注意力的环境,我们做出了重大的尝试。我们最初的试点测试结果表明,这些发现违反了网络钓鱼智商(IQ)测试的直觉。相比之下,PMSER的结果是直观的,与移动设备相比,在计算机上改进了检测。最后,我们讨论了研究的局限性和进一步的研究。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Pilot testing of experimental procedures to measure user's judgment errors in simulated social engineering attacks
Distracted users appear to have difficulties correctly distinguishing between legitimate and malicious emails or search engine results. Additionally, mobile phone users appear to have a more challenging time identifying malicious content due to the smaller screen size and the limited security features in mobile phone applications. Thus, the goal of this research study was to conduct a pilot test and validate a set of field experiments based on Subject Matter Experts (SMEs) feedback to assess users’ judgment when exposed to two types of simulated social engineering attacks: phishing and Potentially Malicious Search Engine Results (PMSER), based on the interaction of the environment (distracting vs. non-distracting) and type of device used (mobile vs. computer). This paper provides the results from the pilot test we conducted using recruited volunteers consisting of 10 participants out of 20 volunteers invited. Due to COVID-19 restrictions, all interactions in this pilot testing were conducted remotely. These restrictions somewhat limited our ability to control the testing environment to ensure a completely non-distractive environment during these parts of the study; however, a significant attempt was made to ensure such a non-distractive environment was genuinely adhered to during that part of the study. Our initial pilot testing results indicate that the findings were counterintuitive for the Phishing Intelligence Quotient (IQ) tests. In contrast, results of the PMSER were intuitive with improved detection on a computer compared to mobile. We conclude with a discussion on the study limitations and further research.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Understanding knowledge hiding behaviors in the workplace using a serious game data collection approach Special issue editorial: Knowledge hiding and knowledge hoarding in different environments Knowledge hiding and knowledge hoarding: Using grounded theory for conceptual development The impact of knowledge hiding and toxic leadership on knowledge worker productivity – Evidence from IT sector of Pakistan Pilot testing of experimental procedures to measure user's judgment errors in simulated social engineering attacks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1