I don't need an expert! Making URL phishing features human comprehensible
Authors
Document Title
I Don’t Need an Expert! Making URL Phishing Features Human Comprehensible
Document Information
- Subject Area: Cybersecurity and Human-Computer Interaction
- Keywords: Phishing, URL feature analysis, user education, usable security tools, decision support, URL reading, real-time learning, security training
Research Background and Problem Statement
-
Identified Problems or Challenges:
- Ordinary users find it difficult to accurately assess whether a URL is safe, even security experts struggle without the aid of tools.
- Current phishing detection primarily relies on automated systems and basic URL reading skills, which are limited in handling complex scenarios.
- URLs consist of intricate components, and users often fail to correctly parse or interpret them based on contextual information.
- Automated phishing filters are not always 100% accurate, and users may not be able to rely on slow professional feedback in urgent situations.
-
Importance of the Research:
- Phishing is one of the primary causes of data breaches, accounting for a significant proportion of internet crime complaints, leading to substantial financial and reputational losses.
- Empowering users to make security judgments independently, without relying entirely on professionals and systems, can reduce misjudgments and operational errors.
-
Motivation and Related Work:
- Existing anti-phishing support tools (e.g., browser warnings and plugins) are limited in capability and primarily target technical users.
- User education is helpful but constrained by memory decay and the evolution of attacks, showing inherent limitations.
- The goal of this research is to provide users with an intuitive method, leveraging expert tools, to make judgments based on specific contextual information.
Solution
-
Proposed Method or Solution:
- This paper designs a "URL Feature Report" that presents URL information in a format similar to "privacy nutrition labels," enabling users to make security judgments through visualized data.
- The report includes multiple sections: URL summary, factual information (e.g., domain registration location and ranking), potential attack method analysis (e.g., mixed characters, use of IP addresses), and heuristic guidance to assist users in parsing.
- Safety issues are marked with colors and intuitive design elements (e.g., traffic light color system) to help non-technical users easily understand.
-
Innovative Aspects:
- The report design is based on users' contextual knowledge, aiming to foster both conceptual and procedural knowledge acquisition, rather than merely providing a simple safe/unsafe judgment.
- It integrates fine-grained data typically hidden in expert tools (e.g., domain registration queries, malicious blacklist matching) to enhance human-machine collaboration.
- The report offers intuitive explanations to build user trust and confidence, rather than blind reliance on technology.
-
Implementation Steps and Key Technologies:
- Iterative report design through eight focus groups, including security experts, HCI experts, and ordinary users.
- Simulated report appearance and usability based on characteristic datasets, combining two types of phishing URLs and two types of safe URLs.
- Online experimental studies to test the impact of different report detail levels on users' URL security judgment accuracy.
Research Outcomes
-
Specific Results:
- The most detailed comprehensive report achieved a URL security judgment accuracy rate of 93%, while the summary report format resulted in an accuracy rate of 83%, significantly higher than methods relying solely on domain highlighting (65%).
- Both focus groups and online experiments revealed that users could better understand URL features through the report and utilize various features (e.g., domain age, ranking, presence of obfuscation techniques) in actual decision-making.
-
Advantages Compared to Existing Solutions:
- Offers clearer and more intuitive security feature displays compared to existing tools, particularly designed for visual friendliness and flexibility for ordinary users.
- Users can make personalized security judgments based on context, with the report providing diverse data to minimize information loss.
- Quantifies user acceptance of different report formats, providing strong evidence for practical implementation.
-
Experimental or Evaluation Results:
- Analysis of 6,877 URLs showed that the report displayed an average of seven key information lines (extracted from 23 possible lines), effectively reducing redundant information.
- Experimental results demonstrated that users, after learning to use the report, could better distinguish between safe and phishing URLs, showing strong adaptability to techniques like spelling similarities and symbol confusion.
-
Limitations and Future Directions:
- Certain complex concepts in the report (e.g., PageRank and location information) remain challenging for some users to understand.
- The study focuses on pre-access URL judgment and does not address security detection of the webpage content behind the URL.
- While online experiments demonstrated the report's potential, future research should involve field testing (e.g., as a browser plugin).
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can ordinary users accurately judge URL safety through understandable report formats?Category: Cyber Threats and ProtectionSimilar questionsarrow_forward
- Can URL feature reports help users understand security features such as domain registration information, rankings, and obfuscation techniques?Category: Cyber Threats and ProtectionSimilar questionsarrow_forward
- Compared with traditional anti-phishing tools, what improvements in judgment accuracy do intuitively designed URL feature reports offer?Category: Cyber Threats and ProtectionSimilar questionsarrow_forward
Practical Problems
1- Users struggle to independently judge whether URLs are safe; existing tools are not intuitive enough.Category: Cyber Threats and ProtectionSimilar questionsarrow_forward
- 60%
Paths Explored, Paths Omitted, Paths Obscured: Decision Points & Selective Reporting in End-to-End Data Analysis
CHI '20· Explainable AI (XAI) +1
- 60%
Truth or Dare: Understanding and Predicting How Users Lie and Provide Untruthful Data Online
CHI '21· AI Ethics, Fairness & Accountability +1
- 60%
Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices
CHI '21· Privacy by Design & User Control +1
- 60%
Covert Embodied Choice: Decision-Making and the Limits of Privacy Under Biometric Surveillance
CHI '21· Privacy by Design & User Control +1
- 60%
"Okay, whatever": An Evaluation of Cookie Consent Interfaces
CHI '22· Privacy Perception & Decision-Making +1
- 60%
“Our Users' Privacy is Paramount to Us”: A Discourse Analysis of How Period and Fertility Tracking App Companies Address the Roe v Wade Overturn
CHI '24· Privacy by Design & User Control +1
- 60%
Out-of-Device Privacy Unveiled: Designing and Validating the Out-of-Device Privacy Scale (ODPS)
CHI '24· Privacy by Design & User Control +1
- 60%
Privacy Perceptions of Custom GPTs by Users and Creators
CHI '25· Algorithmic Transparency & Auditability +1
- 60%
Disconnecting: Towards a Semiotic Framework for Personal Data Trails
DIS '20· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)