Eyes on the Phish(er): Towards Understanding Users' Email Processing Pattern and Mental Models in Phishing Detection

Sijie Zhuo, Robert Biddle, Jared Daniel Recomendable, Giovanni Russello, Danielle Lottridge
{"title":"Eyes on the Phish(er): Towards Understanding Users' Email Processing Pattern and Mental Models in Phishing Detection","authors":"Sijie Zhuo, Robert Biddle, Jared Daniel Recomendable, Giovanni Russello, Danielle Lottridge","doi":"arxiv-2409.07717","DOIUrl":null,"url":null,"abstract":"Phishing emails typically masquerade themselves as reputable identities to\ntrick people into providing sensitive information and credentials. Despite\nadvancements in cybersecurity, attackers continuously adapt, posing ongoing\nthreats to individuals and organisations. While email users are the last line\nof defence, they are not always well-prepared to detect phishing emails. This\nstudy examines how workload affects susceptibility to phishing, using\neye-tracking technology to observe participants' reading patterns and\ninteractions with tailored phishing emails. Incorporating both quantitative and\nqualitative analysis, we investigate users' attention to two phishing\nindicators, email sender and hyperlink URLs, and their reasons for assessing\nthe trustworthiness of emails and falling for phishing emails. Our results\nprovide concrete evidence that attention to the email sender can reduce\nphishing susceptibility. While we found no evidence that attention to the\nactual URL in the browser influences phishing detection, attention to the text\nmasking links can increase phishing susceptibility. We also highlight how email\nrelevance, familiarity, and visual presentation impact first impressions of\nemail trustworthiness and phishing susceptibility.","PeriodicalId":501541,"journal":{"name":"arXiv - CS - Human-Computer Interaction","volume":"49 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-09-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"arXiv - CS - Human-Computer Interaction","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/arxiv-2409.07717","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Phishing emails typically masquerade themselves as reputable identities to trick people into providing sensitive information and credentials. Despite advancements in cybersecurity, attackers continuously adapt, posing ongoing threats to individuals and organisations. While email users are the last line of defence, they are not always well-prepared to detect phishing emails. This study examines how workload affects susceptibility to phishing, using eye-tracking technology to observe participants' reading patterns and interactions with tailored phishing emails. Incorporating both quantitative and qualitative analysis, we investigate users' attention to two phishing indicators, email sender and hyperlink URLs, and their reasons for assessing the trustworthiness of emails and falling for phishing emails. Our results provide concrete evidence that attention to the email sender can reduce phishing susceptibility. While we found no evidence that attention to the actual URL in the browser influences phishing detection, attention to the text masking links can increase phishing susceptibility. We also highlight how email relevance, familiarity, and visual presentation impact first impressions of email trustworthiness and phishing susceptibility.
盯着 "钓鱼网站":了解用户的电子邮件处理模式和网络钓鱼检测中的心理模型
网络钓鱼电子邮件通常伪装成信誉良好的身份,诱使人们提供敏感信息和凭证。尽管网络安全取得了进步,但攻击者仍在不断调整,对个人和组织造成持续威胁。虽然电子邮件用户是最后一道防线,但他们并不总是做好了检测网络钓鱼电子邮件的充分准备。本研究使用眼睛跟踪技术来观察参与者的阅读模式以及与定制的网络钓鱼电子邮件的互动,从而研究工作量如何影响对网络钓鱼的易感性。通过定量和定性分析,我们调查了用户对电子邮件发件人和超链接 URL 这两个网络钓鱼指标的关注程度,以及他们评估电子邮件可信度和上当受骗的原因。我们的研究结果提供了具体证据,证明对电子邮件发件人的关注可以降低网络钓鱼的易感性。虽然我们没有发现任何证据表明关注浏览器中的实际 URL 会影响网络钓鱼的检测,但关注文本屏蔽链接会增加网络钓鱼的易感性。我们还强调了电子邮件的相关性、熟悉程度和视觉呈现如何影响对电子邮件可信度的第一印象和网络钓鱼的易感性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信