I don't need an expert! Making URL phishing features human comprehensible

Algorithmic Transparency & AuditabilityPrivacy Perception & Decision-MakingPrivacy Policy MakersHCI Researchers

Document Title

I Don’t Need an Expert! Making URL Phishing Features Human Comprehensible

Document Information

  • Subject Area: Cybersecurity and Human-Computer Interaction
  • Keywords: Phishing, URL feature analysis, user education, usable security tools, decision support, URL reading, real-time learning, security training

Research Background and Problem Statement

  • Identified Problems or Challenges:

    • Ordinary users find it difficult to accurately assess whether a URL is safe, even security experts struggle without the aid of tools.
    • Current phishing detection primarily relies on automated systems and basic URL reading skills, which are limited in handling complex scenarios.
    • URLs consist of intricate components, and users often fail to correctly parse or interpret them based on contextual information.
    • Automated phishing filters are not always 100% accurate, and users may not be able to rely on slow professional feedback in urgent situations.
  • Importance of the Research:

    • Phishing is one of the primary causes of data breaches, accounting for a significant proportion of internet crime complaints, leading to substantial financial and reputational losses.
    • Empowering users to make security judgments independently, without relying entirely on professionals and systems, can reduce misjudgments and operational errors.
  • Motivation and Related Work:

    • Existing anti-phishing support tools (e.g., browser warnings and plugins) are limited in capability and primarily target technical users.
    • User education is helpful but constrained by memory decay and the evolution of attacks, showing inherent limitations.
    • The goal of this research is to provide users with an intuitive method, leveraging expert tools, to make judgments based on specific contextual information.

Solution

  • Proposed Method or Solution:

    • This paper designs a "URL Feature Report" that presents URL information in a format similar to "privacy nutrition labels," enabling users to make security judgments through visualized data.
    • The report includes multiple sections: URL summary, factual information (e.g., domain registration location and ranking), potential attack method analysis (e.g., mixed characters, use of IP addresses), and heuristic guidance to assist users in parsing.
    • Safety issues are marked with colors and intuitive design elements (e.g., traffic light color system) to help non-technical users easily understand.
  • Innovative Aspects:

    • The report design is based on users' contextual knowledge, aiming to foster both conceptual and procedural knowledge acquisition, rather than merely providing a simple safe/unsafe judgment.
    • It integrates fine-grained data typically hidden in expert tools (e.g., domain registration queries, malicious blacklist matching) to enhance human-machine collaboration.
    • The report offers intuitive explanations to build user trust and confidence, rather than blind reliance on technology.
  • Implementation Steps and Key Technologies:

    • Iterative report design through eight focus groups, including security experts, HCI experts, and ordinary users.
    • Simulated report appearance and usability based on characteristic datasets, combining two types of phishing URLs and two types of safe URLs.
    • Online experimental studies to test the impact of different report detail levels on users' URL security judgment accuracy.

Research Outcomes

  • Specific Results:

    • The most detailed comprehensive report achieved a URL security judgment accuracy rate of 93%, while the summary report format resulted in an accuracy rate of 83%, significantly higher than methods relying solely on domain highlighting (65%).
    • Both focus groups and online experiments revealed that users could better understand URL features through the report and utilize various features (e.g., domain age, ranking, presence of obfuscation techniques) in actual decision-making.
  • Advantages Compared to Existing Solutions:

    • Offers clearer and more intuitive security feature displays compared to existing tools, particularly designed for visual friendliness and flexibility for ordinary users.
    • Users can make personalized security judgments based on context, with the report providing diverse data to minimize information loss.
    • Quantifies user acceptance of different report formats, providing strong evidence for practical implementation.
  • Experimental or Evaluation Results:

    • Analysis of 6,877 URLs showed that the report displayed an average of seven key information lines (extracted from 23 possible lines), effectively reducing redundant information.
    • Experimental results demonstrated that users, after learning to use the report, could better distinguish between safe and phishing URLs, showing strong adaptability to techniques like spelling similarities and symbol confusion.
  • Limitations and Future Directions:

    • Certain complex concepts in the report (e.g., PageRank and location information) remain challenging for some users to understand.
    • The study focuses on pre-access URL judgment and does not address security detection of the webpage content behind the URL.
    • While online experiments demonstrated the report's potential, future research should involve field testing (e.g., as a browser plugin).

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/47404/2021

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3411764.3445574
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2021
emoji_events
Award
No award tagged
group
Authors
3 authors
sell
Subtopics
Algorithmic Transparency & Auditability, Privacy Perception & Decision-Making
work
Professions
Privacy Policy Makers, HCI Researchers
article
Content Status
Full text indexed
hub
Related Papers
9 related papers