A Phish Scale: Rating Human Phishing Message Detection Difficulty

M. Steves, Kristen K. Greene, M. Theofanos
{"title":"A Phish Scale: Rating Human Phishing Message Detection Difficulty","authors":"M. Steves, Kristen K. Greene, M. Theofanos","doi":"10.14722/usec.2019.23028","DOIUrl":null,"url":null,"abstract":"As organizations continue to invest in phishing awareness training programs, many Chief Information Security Officers (CISOs) are concerned when their training exercise click rates are high or variable, as they must justify training budgets to those who question the efficacy of training when click rates are not declining. We argue that click rates should be expected to vary based on the difficulty of the phishing email for a target audience. Past research has shown that when the premise of a phishing email aligns with a user’s work context, it is much more challenging for users to detect a phish. Given this, we propose a Phish Scale, so CISOs and phishing training implementers can easily rate the difficulty of their phishing exercises and help explain associated click rates. We based our scale on past research in phishing cues and user context, and applied it to previously published data and new data from organization-wide phishing exercises targeting approximately 5 000 employees. The Phish Scale performed well with the current phishing dataset, but future work is needed to validate it with a larger variety of phishing emails. The Phish Scale shows great promise as a tool to help frame data sharing on phishing exercise click rates across sectors. Keywords—phishing cues, embedded phishing awareness training, operational data, network security, phishing defenses, security defenses","PeriodicalId":215851,"journal":{"name":"Proceedings 2019 Workshop on Usable Security","volume":"96 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-02-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"18","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings 2019 Workshop on Usable Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.14722/usec.2019.23028","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 18

Abstract

As organizations continue to invest in phishing awareness training programs, many Chief Information Security Officers (CISOs) are concerned when their training exercise click rates are high or variable, as they must justify training budgets to those who question the efficacy of training when click rates are not declining. We argue that click rates should be expected to vary based on the difficulty of the phishing email for a target audience. Past research has shown that when the premise of a phishing email aligns with a user’s work context, it is much more challenging for users to detect a phish. Given this, we propose a Phish Scale, so CISOs and phishing training implementers can easily rate the difficulty of their phishing exercises and help explain associated click rates. We based our scale on past research in phishing cues and user context, and applied it to previously published data and new data from organization-wide phishing exercises targeting approximately 5 000 employees. The Phish Scale performed well with the current phishing dataset, but future work is needed to validate it with a larger variety of phishing emails. The Phish Scale shows great promise as a tool to help frame data sharing on phishing exercise click rates across sectors. Keywords—phishing cues, embedded phishing awareness training, operational data, network security, phishing defenses, security defenses
网络钓鱼量表:评估人类网络钓鱼信息检测难度
随着组织继续投资于网络钓鱼意识培训计划,许多首席信息安全官(ciso)担心他们的培训练习点击率是否很高或不稳定,因为他们必须在点击率没有下降的情况下向那些质疑培训有效性的人证明培训预算是合理的。我们认为点击率应该根据目标受众的网络钓鱼邮件的难度而变化。过去的研究表明,当网络钓鱼邮件的前提与用户的工作环境一致时,用户检测网络钓鱼邮件的难度要大得多。鉴于此,我们提出了一个网络钓鱼量表,这样ciso和网络钓鱼培训实施者就可以很容易地对他们的网络钓鱼练习的难度进行评级,并帮助解释相关的点击率。我们的量表基于过去对网络钓鱼线索和用户上下文的研究,并将其应用于以前发布的数据和针对大约5000名员工的组织范围内的网络钓鱼练习的新数据。Phish Scale在当前的网络钓鱼数据集上表现良好,但需要未来的工作来验证更多种类的网络钓鱼电子邮件。网络钓鱼量表作为一种工具显示出了巨大的前景,它可以帮助构建跨部门网络钓鱼活动点击率的数据共享。关键词:网络钓鱼线索,嵌入式网络钓鱼意识训练,操作数据,网络安全,网络钓鱼防御,安全防御
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信