Modelling User-Phishing Interaction

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

To protect users from phishing attacks system designers and security professionals need to understand how users interact with those attacks and be able to predict users' behaviours in a given situation. In this paper we introduce the first model to visualise user-phishing interaction. We present a method to accurately describe users' perceptions in a uniform and compact manner. Within the context of this model we have investigated: what exact mismatches may occur between perception and reality in an attack; how to detect those mismatches; and why users fail to do so. Using this model we also identify where the security tools/indicators are lacking, suggest new aspects for security evaluation for the user interface, and provide guidance on effective antiphishing user education.

Original languageEnglish
Title of host publication2008 CONFERENCE ON HUMAN SYSTEM INTERACTIONS, VOLS 1 AND 2
Place of PublicationNEW YORK
PublisherIEEE
Pages633-638
Number of pages6
ISBN (Print)978-1-4244-1542-7
Publication statusPublished - 2008
EventConference on Human System Interactions - Cracow
Duration: 25 May 200827 May 2008

Conference

ConferenceConference on Human System Interactions
CityCracow
Period25/05/0827/05/08

Keywords

  • Phishing
  • User Interaction
  • Decision Making Model

Cite this