User-Centred Security Education: A Game Design to Thwart Phishing Attacks
نویسنده
چکیده
Security exploits can include cyber threats such as computer programs that can disturb the normal behaviour of computer systems (viruses), unsolicited e-mail (spam), malicious software (malware), monitoring software (spyware), attempting to make computer resources unavailable to their intended users (Distributed Denial-of-Service or DDoS attack), the social engineering, and online identity theft (phishing) [4]. One such cyber threat, which is particularly dangerous to computer users is phishing [7] [2] [4]. Phishing is well known as online identity theft, which aims to steal sensitive information such as username, password and online banking details from its victims. Automated anti-phishing tools have been developed and used to alert users of potentially fraudulent emails and websites. However, these tools are not entirely reliable in detecting phishing attacks [12] [3]. Even the best anti-phishing tools missed over 20 percent of phishing websites [14]. Because “human” is the weakest link in information security [11] [3] [4]. It is not possible to completely avoid the end-user, for example in personal computer use, one mitigating approach for computer and information security is to educate the end-user in security prevention [3] [13] [12] [14] [8] [4]. The aim of this research study focuses on a design and development of a game prototype for mobile platforms to educate individuals about phishing attacks. Therefore, the study asks how does one identify which issues the game design needs to be addressed? The elements of a game design framework developed by Arachchilage and Love [3] for avoiding phishing attacks were used to address the game design issues. Our mobile game design aimed to enhance the users’ avoidance behaviour through their motivation to protect themselves against phishing threats. Garera et al. [9] strongly argue it is often possible to differentiate phishing websites from legitimate ones by carefully looking at the URL. Therefore, this mobile game prototype designed to teach people to identify legitimate URLs from mimic ones. A think-aloud study was conducted, along with a preand post-test, to assess the game design framework though the developed mobile game prototype. The study results showed a significant improvement of participants’ phishing avoidance behaviour in their post-test assessment. Furthermore, the study findings suggest that participants’ threat perception, safeguard effectiveness, self-efficacy, perceived severity and perceived susceptibility elements positively impact threat avoidance behaviour, whereas safeguard cost had a negative impact on it. Figure 1: The game design framework [3]
منابع مشابه
Integrating self-efficacy into a gamified approach to thwart phishing attacks
Security exploits can include cyber threats such as computer programs that can disturb the normal behavior of computer systems (viruses), unsolicited e-mail (spam), malicious software (malware), monitoring software (spyware), attempting to make computer resources unavailable to their intended users (Distributed Denial-of-Service or DDoS attack), the social engineering, and online identity theft...
متن کاملCan a Mobile Game Teach Computer Users to Thwart Phishing Attacks?
Phishing is an online fraudulent technique, which aims to steal sensitive information such as usernames, passwords and online banking details from its victims. To prevent this, anti-phishing education needs to be considered. This research focuses on examining the effectiveness of mobile game based learning compared to traditional online learning to thwart phishing threats. Therefore, a mobile g...
متن کاملPhish Phinder: A Game Design Approach to Enhance User Confidence in Mitigating Phishing Attacks
Phishing is an especially challenging cyber security threat as it does not attack computer systems, but targets the user who works on that system by relying on the vulnerability of their decision-making ability. Phishing attacks can be used to gather sensitive information from victims and can have devastating impact if they are successful in deceiving the user. Several anti-phishing tools have ...
متن کاملA Framework to Prevent QR Code Based Phishing Attacks
Though the rapid development and spread of Information and Communication Technology (ICT) making people's life much more easier, on the other hand it causing some serious threats to the society. Phishing is one of the most common cyber threat, that most users falls in. This research investigate on QR code based phishing attacks which is a newly adopted intrusive method and how to enhance the aw...
متن کاملDesigning a Mobile Game for Home Computer Users to Protect Against Phishing Attacks
This research aims to design an educational mobile game for home computer users to prevent from phishing attacks. Phishing is an online identity theft which aims to steal sensitive information such as username, password and online banking details from victims. To prevent this, phishing education needs to be considered. Mobile games could facilitate to embed learning in a natural environment. Th...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- CoRR
دوره abs/1511.03459 شماره
صفحات -
تاریخ انتشار 2015