The Influence of Context on Response to Spear-Phishing Attacks: an In-Situ Deception Study

Algorithmic Transparency & AuditabilityPrivacy Perception & Decision-MakingOnline Harassment & Counter-ToolsCybersecurity EngineersPrivacy Policy MakersContent Governance & Platform Compliance Teams

Title of the Paper

The Influence of Context on Response to Spear-Phishing Attacks: an In-Situ Deception Study

Bibliographic Information

  • Subject Area: Cybersecurity, user behavior research, evaluation of phishing attack impacts
  • Keywords: cybersecurity, human-computer interaction, phishing attacks, empirical study, qualitative research methods

Research Background and Problem

  • Identified Problems or Challenges:

    1. Phishing attacks are a prevalent cybersecurity threat. Customized phishing attacks, such as spear-phishing, are highly targeted and difficult to counter using technical detection methods.
    2. Despite user education and anti-phishing training, organizations remain vulnerable to such attacks.
    3. There is insufficient knowledge about how employees' work environments and contexts influence their responses to phishing attacks.
  • Significance: Spear-phishing attacks are one of the primary causes of data breaches, accounting for 90% of data breaches in 2020. These attacks not only harm individuals and businesses but can also threaten critical infrastructure or societal functions.

  • Research Motivation and Related Work:

    • Motivation: A deeper understanding of how contextual factors influence employees' responses to phishing emails is needed to propose more effective defense strategies.
    • Related Research:
      • Studies have found that the success of phishing attacks is closely tied to the use of social influence tactics (e.g., authority, commitment, or time pressure).
      • Existing anti-phishing education and embedded training have limitations, such as potentially inducing negative or humiliating user experiences and insufficient preparation for advanced attacks.

Proposed Solution

  • Proposed Methods or Solutions:
    The authors employed an in-situ deception methodology, designing simulated phishing emails to observe participants' real-time behaviors and conducting follow-up interviews.

  • Innovations:

    1. Using customized spear-phishing emails containing authority and urgency cues to directly test employees' real-world responses.
    2. Combining observational data with qualitative interviews to capture participants' emotions, thought processes, and behaviors.
    3. Focusing on ecological validity in real work environments to analyze how work contexts influence employees' anti-phishing capabilities.
  • Implementation Steps and Techniques:

    1. Conducting on-site observations at a European university, selecting 14 representative employees (including researchers and administrative staff).
    2. Sending simulated spear-phishing emails to participants while recording their immediate reactions (e.g., whether they clicked on the link).
    3. Collecting retrospective reflections and proposed solutions from participants through semi-structured interviews and the UX Curve method.

Research Findings

  • Specific Findings:

    • Only 29% of participants clicked on the phishing link, resulting in a "successful" simulated attack. However, a key finding was that the cognitive processes behind the decision to click or not could be categorized into fast, automated processes (less deliberation) and slow, reflective processes (thoroughly examining suspicious elements in the email).
    • Major contextual factors included internal pressures (e.g., the need to quickly respond to superior emails), social support, and task types.
    • Social interactions helped detect suspicious emails, but participants who fell for the phishing attack often refrained from reporting the issue due to feelings of shame.
  • Advantages Over Existing Solutions:

    • Compared to previous studies, this research systematically analyzed contextual factors influencing the success of phishing attacks.
    • Proposed organizational-level solutions, such as encouraging open consultation among colleagues and optimizing employee behavior through environmental adjustments.
  • Experimental or Evaluation Results:

    1. The primary reason for clicking on phishing emails was trust in the source (e.g., the appearance of a professor's name) and acting quickly, highlighting the significant role of "authority cues" in the success of attacks.
    2. Emotions (e.g., stress) and social environments (e.g., colleague interactions) significantly influenced participants' email handling behaviors.
  • Limitations and Future Directions:

    • Limitations:
      1. The sample was limited to a university environment, and participants were all highly educated, making it difficult to generalize to other types of organizations.
      2. The use of English in phishing emails may not fully apply to multilingual organizational contexts.
    • Future Directions:
      1. Further research on the challenges of detecting phishing on mobile devices.
      2. Exploring how social interventions can improve employees' phishing detection and reporting capabilities.
      3. Investigating the impact of time and physiological factors (e.g., employee fatigue) on responses to phishing attacks.

Summary and Recommendations

  • Recommendations:

    • Anti-phishing training should focus on "context" rather than solely targeting individual characteristics, such as reducing social norms that pressure employees to respond to emails quickly.
    • Promote "anti-phishing" as a socialized behavior, creating an organizational culture that encourages employees to report mistakes without fear of humiliation.
    • Design more advanced training programs for spear-phishing, particularly emphasizing employees' vigilance toward social and technical cues.
  • Academic Contribution:

    • Provides qualitative insights into how contextual factors dynamically influence anti-phishing behaviors.
    • Calls for anti-phishing research to adopt interdisciplinary perspectives, integrating technical solutions with social psychology methods to enhance organizational cybersecurity.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/95829/2023

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3581170
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
No award tagged
group
Authors
1 authors
sell
Subtopics
Algorithmic Transparency & Auditability, Privacy Perception & Decision-Making, Online Harassment & Counter-Tools
work
Professions
Cybersecurity Engineers, Privacy Policy Makers, Content Governance & Platform Compliance Teams
article
Content Status
Full text indexed
hub
Related Papers
0 related papers