Setting Priorities in Behavioral Interventions: An Application to Reducing Phishing Risk.
نویسندگان
چکیده
Phishing risk is a growing area of concern for corporations, governments, and individuals. Given the evidence that users vary widely in their vulnerability to phishing attacks, we demonstrate an approach for assessing the benefits and costs of interventions that target the most vulnerable users. Our approach uses Monte Carlo simulation to (1) identify which users were most vulnerable, in signal detection theory terms; (2) assess the proportion of system-level risk attributable to the most vulnerable users; (3) estimate the monetary benefit and cost of behavioral interventions targeting different vulnerability levels; and (4) evaluate the sensitivity of these results to whether the attacks involve random or spear phishing. Using parameter estimates from previous research, we find that the most vulnerable users were less cautious and less able to distinguish between phishing and legitimate emails (positive response bias and low sensitivity, in signal detection theory terms). They also accounted for a large share of phishing risk for both random and spear phishing attacks. Under these conditions, our analysis estimates much greater net benefit for behavioral interventions that target these vulnerable users. Within the range of the model's assumptions, there was generally net benefit even for the least vulnerable users. However, the differences in the return on investment for interventions with users with different degrees of vulnerability indicate the importance of measuring that performance, and letting it guide interventions. This study suggests that interventions to reduce response bias, rather than to increase sensitivity, have greater net benefit.
منابع مشابه
Disease Control Priorities Third Edition Is Published: A Theory of Change Is Needed for Translating Evidence to Health Policy
How can evidence from economic evaluations of the type the Disease Control Priorities project have synthesized be translated to better priority setting? This evidence provides insights into how investing in health, particularly though priority interventions and expanded access to health insurance and prepaid care, can not only save lives but also help alleviate poverty and provide financial ris...
متن کاملThe Future of Disease Control Priorities; Comment on “Disease Control Priorities Third Edition Is Published: A Theory of Change Is Needed for Translating Evidence to Health Policy”
The Disease Control Priorities (DCP) project has substantially influenced national and global health priorities since 1993. DCP’s basic framework involves identification of disease burdens based on premature deaths and disability and application of the most cost-effective interventions to the largest burdens, taking into account local feasibility. The future impact of DCP will need to take into...
متن کاملThe Effectiveness of Psychological Interventions on Reducing the Symptoms of Post-Traumatic Stress Disorder in Military Personnel: A Systematic Review
Background and Aim: Considering the nature of post-traumatic stress disorder (PTSD) in the military profession, challenges in the effectiveness of psychological interventions on the symptoms of the disorder and sustainable recovery have been reported among the military population. The present research aims to identify effective psychological interventions for PTSD symptoms and compare their eff...
متن کاملChapter 3 Improving Phishing Countermeasures
As the battle against phishing continues, many questions remain about where stakeholders should place their efforts to achieve effective prevention, speedy detection, and fast action. Do stakeholders have sufficient incentives to act? What should be the top priorities for the anti-phishing community? To provide insights into these questions we conducted 31 in-depth interviews with anti-phishing...
متن کاملPrioritising, Ranking and Resource Implementation - A Normative Analysis
Background Priority setting in publicly financed healthcare systems should be guided by ethical norms and other considerations viewed as socially valuable, and we find several different approaches for how such norms and considerations guide priorities in healthcare decision-making. Common to many of these approaches is that interventions are ranked in relation to each other, following the appli...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Risk analysis : an official publication of the Society for Risk Analysis
دوره شماره
صفحات -
تاریخ انتشار 2017