Visible to the public Phish Finders: Crowd-powered RE for anti-phishing training tools

TitlePhish Finders: Crowd-powered RE for anti-phishing training tools
Publication TypeConference Paper
Year of Publication2022
AuthorsRosser, Holly, Mayor, Maylene, Stemmler, Adam, Ahuja, Vinod, Grover, Andrea, Hale, Matthew
Conference Name2022 IEEE 30th International Requirements Engineering Conference Workshops (REW)
Keywordscitizen science, Conferences, crowdsourcing, cybersecurity, Human Behavior, Organizations, phishing, pubcrawl, requirements engineering, Software, Training, Zooniverse
AbstractMany organizations use internal phishing campaigns to gauge awareness and coordinate training efforts based on those findings. Ongoing content design is important for phishing training tools due to the influence recency has on phishing susceptibility. Traditional approaches for content development require significant investment and can be prohibitively costly, especially during the requirements engineering phase of software development and for applications that are constantly evolving. While prior research primarily depends upon already known phishing cues curated by experts, our project, Phish Finders, uses crowdsourcing to explore phishing cues through the unique perspectives and thought processes of everyday users in a realistic yet safe online environment, Zooniverse. This paper contributes qualitative analysis of crowdsourced comments that identifies novel cues, such as formatting and typography, which were identified by the crowd as potential phishing indicators. The paper also shows that crowdsourcing may have the potential to scale as a requirements engineering approach to meet the needs of content labeling for improved training tool development.
NotesISSN: 2770-6834
DOI10.1109/REW56159.2022.00031
Citation Keyrosser_phish_2022