• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

在警告中嵌入培训可提高识别钓鱼网页的技能。

Embedding Training Within Warnings Improves Skills of Identifying Phishing Webpages.

机构信息

Purdue University, Lafayette, Indiana, USA.

出版信息

Hum Factors. 2019 Jun;61(4):577-595. doi: 10.1177/0018720818810942. Epub 2018 Dec 10.

DOI:10.1177/0018720818810942
PMID:30526089
Abstract

OBJECTIVE

Evaluate the effectiveness of training embedded within security warnings to identify phishing webpages.

BACKGROUND

More than 20 million malware and phishing warnings are shown to users of Google Safe Browsing every week. Substantial click-through rate is still evident, and a common issue reported is that users lack understanding of the warnings. Nevertheless, each warning provides an opportunity to train users about phishing and how to avoid phishing attacks.

METHOD

To test use of phishing-warning instances as opportunities to train users' phishing webpage detection skills, we conducted an online experiment contrasting the effectiveness of the current Chrome phishing warning with two training-embedded warning interfaces. The experiment consisted of three phases. In Phase 1, participants made login decisions on 10 webpages with the aid of warning. After a distracting task, participants made legitimacy judgments for 10 different login webpages without warnings in Phase 2. To test the long-term effect of the training, participants were invited back a week later to participate in Phase 3, which was conducted similarly as Phase 2.

RESULTS

Participants differentiated legitimate and fraudulent webpages better than chance. Performance was similar for all interfaces in Phase 1 for which the warning aid was present. However, training-embedded interfaces provided better protection than the Chrome phishing warning on both subsequent phases.

CONCLUSION

Embedded training is a complementary strategy to compensate for lack of phishing webpage detection skill when phishing warning is absent.

APPLICATION

Potential applications include development of training-embedded warnings to enable security training at scale.

摘要

目的

评估嵌入式安全警告培训在识别网络钓鱼网页方面的有效性。

背景

谷歌安全浏览每周向用户展示超过 2000 万次恶意软件和网络钓鱼警告。尽管点击量仍然很高,但用户普遍反映缺乏对警告的理解。然而,每个警告都为培训用户了解网络钓鱼和如何避免网络钓鱼攻击提供了机会。

方法

为了测试利用网络钓鱼警告实例作为培训用户识别网络钓鱼网页技能的机会,我们进行了一项在线实验,对比了当前 Chrome 网络钓鱼警告与两种嵌入式培训警告界面的有效性。实验分为三个阶段。在第一阶段,参与者在警告的帮助下对 10 个网页做出登录决策。在分心任务之后,参与者在第二阶段不使用警告对 10 个不同的登录网页做出合法性判断。为了测试培训的长期效果,参与者在一周后被邀请回来参加第三阶段,该阶段的操作与第二阶段类似。

结果

参与者在区分合法和欺诈性网页方面的表现优于随机水平。在第一阶段,对于有警告辅助的所有界面,性能都相似。然而,在随后的两个阶段,嵌入式培训界面提供的保护优于 Chrome 网络钓鱼警告。

结论

嵌入式培训是一种补充策略,可以在没有网络钓鱼网页检测技能的情况下补偿这种不足。

应用

潜在的应用包括开发嵌入式培训警告,以实现大规模的安全培训。

相似文献

1
Embedding Training Within Warnings Improves Skills of Identifying Phishing Webpages.在警告中嵌入培训可提高识别钓鱼网页的技能。
Hum Factors. 2019 Jun;61(4):577-595. doi: 10.1177/0018720818810942. Epub 2018 Dec 10.
2
Is Domain Highlighting Actually Helpful in Identifying Phishing Web Pages?域名突出显示在识别网络钓鱼网页方面真的有帮助吗?
Hum Factors. 2017 Jun;59(4):640-660. doi: 10.1177/0018720816684064. Epub 2017 Jan 6.
3
Quantifying Phishing Susceptibility for Detection and Behavior Decisions.量化用于检测和行为决策的网络钓鱼易感性。
Hum Factors. 2016 Dec;58(8):1158-1172. doi: 10.1177/0018720816665025. Epub 2016 Aug 25.
4
An effective detection approach for phishing websites using URL and HTML features.一种利用 URL 和 HTML 特征的有效钓鱼网站检测方法。
Sci Rep. 2022 May 25;12(1):8842. doi: 10.1038/s41598-022-10841-5.
5
Signal Detection Theory (SDT) Is Effective for Modeling User Behavior Toward Phishing and Spear-Phishing Attacks.信号检测理论(SDT)可有效用于对用户针对网络钓鱼和鱼叉式网络钓鱼攻击的行为进行建模。
Hum Factors. 2018 Dec;60(8):1179-1191. doi: 10.1177/0018720818789818. Epub 2018 Jul 31.
6
Who Gets Caught in the Web of Lies?: Understanding Susceptibility to Phishing Emails, Fake News Headlines, and Scam Text Messages.谁容易陷入谎言的网络中?:了解易受网络钓鱼邮件、假新闻标题和诈骗短信影响的原因。
Hum Factors. 2024 Jun;66(6):1742-1753. doi: 10.1177/00187208231173263. Epub 2023 May 1.
7
Detecting phishing webpages homology analysis of webpage structure.检测网络钓鱼网页——网页结构的同源性分析
PeerJ Comput Sci. 2022 Feb 1;8:e868. doi: 10.7717/peerj-cs.868. eCollection 2022.
8
Detecting phishing websites using machine learning technique.利用机器学习技术检测钓鱼网站。
PLoS One. 2021 Oct 11;16(10):e0258361. doi: 10.1371/journal.pone.0258361. eCollection 2021.
9
It's the deceiver and the receiver: Individual differences in phishing susceptibility and false positives with item profiling.是欺骗者也是受骗者:个体差异在钓鱼易感性和项目分析中的假阳性。
PLoS One. 2018 Oct 26;13(10):e0205089. doi: 10.1371/journal.pone.0205089. eCollection 2018.
10
Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system.评估美国医疗体系内高风险员工强制参加网络钓鱼培训计划的效果。
J Am Med Inform Assoc. 2019 Jun 1;26(6):547-552. doi: 10.1093/jamia/ocz005.

引用本文的文献

1
Informing, simulating experience, or both: A field experiment on phishing risks.告知、模拟体验还是两者兼而有之:关于网络钓鱼风险的现场实验。
PLoS One. 2019 Dec 18;14(12):e0224216. doi: 10.1371/journal.pone.0224216. eCollection 2019.