A real world study on employees' susceptibility to phishing attacks

M. Bona, F. Paci
{"title":"A real world study on employees' susceptibility to phishing attacks","authors":"M. Bona, F. Paci","doi":"10.1145/3407023.3409179","DOIUrl":null,"url":null,"abstract":"Phishing email attacks have been around for fifteen years but they are still among the top security risks faced by organisations. The most common approach to mitigate these attacks is employees' education and awareness. Employees' awareness on phishing attacks is achieved by embedded training that educate employees when they fall for the attack. However, the effectiveness of embedded training in workplace settings is uncertain given the large number of employees that remain vulnerable to phishing email attacks. Similarly, the role of persuasion techniques in making employees vulnerable to phishing attacks is yet to be investigated in the workplace settings. Therefore, in this paper we investigate which persuasion technique between authority and urgency is more effective in making employees susceptible to phishing, the relation between employees' susceptibility and their demographic data, and the effectiveness of embedded training in reducing employees' susceptibility to phishing attacks. To this end, we conducted a real phishing study with 191 employees of an Italian company. We found that employees were more vulnerable to phishing attacks when urgency principle was exploited. The study also showed no significant effect of employees' demographic data on susceptibility to phishing. Embedded training was perceived as effective by employees but it did not reduce their susceptibility to phishing.","PeriodicalId":121225,"journal":{"name":"Proceedings of the 15th International Conference on Availability, Reliability and Security","volume":"23 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-08-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"13","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 15th International Conference on Availability, Reliability and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3407023.3409179","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 13

Abstract

Phishing email attacks have been around for fifteen years but they are still among the top security risks faced by organisations. The most common approach to mitigate these attacks is employees' education and awareness. Employees' awareness on phishing attacks is achieved by embedded training that educate employees when they fall for the attack. However, the effectiveness of embedded training in workplace settings is uncertain given the large number of employees that remain vulnerable to phishing email attacks. Similarly, the role of persuasion techniques in making employees vulnerable to phishing attacks is yet to be investigated in the workplace settings. Therefore, in this paper we investigate which persuasion technique between authority and urgency is more effective in making employees susceptible to phishing, the relation between employees' susceptibility and their demographic data, and the effectiveness of embedded training in reducing employees' susceptibility to phishing attacks. To this end, we conducted a real phishing study with 191 employees of an Italian company. We found that employees were more vulnerable to phishing attacks when urgency principle was exploited. The study also showed no significant effect of employees' demographic data on susceptibility to phishing. Embedded training was perceived as effective by employees but it did not reduce their susceptibility to phishing.
员工对网络钓鱼攻击易感性的真实世界研究
网络钓鱼电子邮件攻击已经存在了15年,但它们仍然是组织面临的最大安全风险之一。减轻这些攻击的最常见方法是员工的教育和意识。员工对网络钓鱼攻击的意识是通过嵌入式培训来实现的,这些培训可以在员工遭受攻击时对他们进行教育。然而,鉴于大量员工仍然容易受到网络钓鱼电子邮件攻击,在工作场所设置嵌入式培训的有效性尚不确定。同样,说服技术在使员工容易受到网络钓鱼攻击方面的作用还有待于在工作场所进行调查。因此,本文研究了权威和紧迫性之间哪种说服技术更有效地使员工容易受到网络钓鱼攻击,员工易感性与其人口统计数据之间的关系,以及嵌入式培训在降低员工对网络钓鱼攻击的易感性方面的有效性。为此,我们对一家意大利公司的191名员工进行了一次真实的网络钓鱼研究。我们发现,当紧急原则被利用时,员工更容易受到网络钓鱼攻击。该研究还显示,员工的人口统计数据对网络钓鱼的易感性没有显著影响。员工认为嵌入式培训是有效的,但它并没有减少他们对网络钓鱼的易感性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信