Visible to the public Building Confidence not to be Phished Through a Gamified Approach: Conceptualising User's Self-Efficacy in Phishing Threat Avoidance Behaviour

TitleBuilding Confidence not to be Phished Through a Gamified Approach: Conceptualising User's Self-Efficacy in Phishing Threat Avoidance Behaviour
Publication TypeConference Paper
Year of Publication2019
AuthorsBaral, Gitanjali, Arachchilage, Nalin Asanka Gamagedara
Conference Name2019 Cybersecurity and Cyberforensics Conference (CCC)
ISBN Number978-1-7281-2600-5
KeywordsCognition, Computer crime, computer games, Computers, Electronic mail, Games, Gamification/Gamified approach, gamified approach, gaming prototype, heuristic knowledge, Human Behavior, Human Behavior and Cybersecurity, human factors, Internet, knowledge, knowledge attributes, observational knowledge, online identity theft attack, phishing, phishing attack, phishing attacks, phishing threat avoidance behaviour, phishing threat prevention behaviour, pubcrawl, Self-Efficacy, social cognitive theory, structural knowledge, threat avoidance motivation, Threat avoidance motivation and behaviour, Tools, Training, user self-efficacy
Abstract

Phishing attacks are prevalent and humans are central to this online identity theft attack, which aims to steal victims' sensitive and personal information such as username, password, and online banking details. There are many antiphishing tools developed to thwart against phishing attacks. Since humans are the weakest link in phishing, it is important to educate them to detect and avoid phishing attacks. One can argue self-efficacy is one of the most important determinants of individual's motivation in phishing threat avoidance behaviour, which has co-relation with knowledge. The proposed research endeavours on the user's self-efficacy in order to enhance the individual's phishing threat avoidance behaviour through their motivation. Using social cognitive theory, we explored that various knowledge attributes such as observational (vicarious) knowledge, heuristic knowledge and structural knowledge contributes immensely towards the individual's self-efficacy to enhance phishing threat prevention behaviour. A theoretical framework is then developed depicting the mechanism that links knowledge attributes, self-efficacy, threat avoidance motivation that leads to users' threat avoidance behaviour. Finally, a gaming prototype is designed incorporating the knowledge elements identified in this research that aimed to enhance individual's self-efficacy in phishing threat avoidance behaviour.

URLhttps://ieeexplore.ieee.org/document/8854543
DOI10.1109/CCC.2019.000-1
Citation Keybaral_building_2019