Visible to the public Use of Phishing Training to Improve Security Warning Compliance: Evidence from a Field ExperimentConflict Detection Enabled

TitleUse of Phishing Training to Improve Security Warning Compliance: Evidence from a Field Experiment
Publication TypeConference Proceedings
Year of Publication2017
AuthorsWeining Yang, Aiping Xiong, Jing Chen, Robert W. Proctor, Ninghui Li
KeywordsA Human Information-Processing Analysis of Online Deception Detection, phishing; field study; active warning
Abstract

The current approach to protect users from phishing attacks is to display a warning when the webpage is considered suspicious. We hypothesize that users are capable of making correct informed decisions when the warning also conveys the reasons why it is displayed. We chose to use traffic rankings of domains, which can be easily described to users, as a warning trigger and evaluated the effect of the phishing warning message and phishing training. The evaluation was conducted in a field experiment. We found that knowledge gained from the training enhances the effectiveness of phishing warnings, as the number of participants being phished was reduced. However, the knowledge by itself was not sufficient to provide phishing protection. We suggest that integrating training in the warning interface, involving traffic ranking in phishing detection, and explaining why warnings are generated will improve current phishing defense.

DOI10.1145/3055305.3055310
Citation Keynode-34191
Refereed DesignationRefereed