Creative Persuasion: A Study on Adversarial Behaviors and Strategies in Phishing Attacks

被引:34
|
作者
Rajivan, Prashanth [1 ]
Gonzalez, Cleotilde [1 ]
机构
[1] Carnegie Mellon Univ, Dynam Decis Making Lab, Social & Decis Sci, Pittsburgh, PA 15213 USA
来源
FRONTIERS IN PSYCHOLOGY | 2018年 / 9卷
关键词
phishing; adversarial behavior; strategy; deception; creativity; persuasion; simulation; VULNERABILITY; PREFERENCE; DECISIONS; PEOPLE;
D O I
10.3389/fpsyg.2018.00135
中图分类号
B84 [心理学];
学科分类号
04 ; 0402 ;
摘要
Success of phishing attacks depend on effective exploitation of human weaknesses. This research explores a largely ignored, but crucial aspect of phishing: the adversarial behavior. We aim at understanding human behaviors and strategies that adversaries use, and how these may determine the end-user response to phishing emails. We accomplish this through a novel experiment paradigm involving two phases. In the adversarial phase, 105 participants played the role of a phishing adversary who were incentivized to produce multiple phishing emails that would evade detection and persuade end-users to respond. In the end-user phase, 340 participants performed an email management task, where they examined and classified phishing emails generated by participants in phase-one along with benign emails. Participants in the adversary role, self-reported the strategies they employed in each email they created, and responded to a test of individual creativity. Data from both phases of the study was combined and analyzed, to measure the effect of adversarial behaviors on end-user response to phishing emails. We found that participants who persistently used specific attack strategies (e.g., sending notifications, use of authoritative tone, or expressing shared interest) in all their attempts were overall more successful, compared to others who explored different strategies in each attempt. We also found that strategies largely determined whether an end-user was more likely to respond to an email immediately, or delete it. Individual creativity was not a reliable predictor of adversarial performance, but it was a predictor of an adversary's ability to evade detection. In summary, the phishing example provided initially, the strategies used, and the participants' persistence with some of the strategies led to higher performance in persuading end-users to respond to phishing emails. These insights may be used to inform tools and training procedures to detect phishing strategies in emails.
引用
下载
收藏
页数:14
相关论文
共 50 条
  • [41] SeVuc: A study on the Security Vulnerabilities of Capsule Networks against adversarial attacks
    Marchisio, Alberto
    Nanfa, Giorgio
    Khalid, Faiq
    Hanif, Muhammad Abdullah
    Martina, Maurizio
    Shafique, Muhammad
    MICROPROCESSORS AND MICROSYSTEMS, 2023, 96
  • [42] Practical Attacks on Machine Learning: A Case Study on Adversarial Windows Malware
    Demetrio, Luca
    Biggio, Battista
    Roli, Fabio
    IEEE SECURITY & PRIVACY, 2022, 20 (05) : 77 - 85
  • [43] Adversarial Light Projection Attacks on Face Recognition Systems: A Feasibility Study
    Dinh-Luan Nguyen
    Arora, Sunpreet S.
    Wu, Yuhang
    Yang, Hao
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW 2020), 2020, : 3548 - 3556
  • [44] Adversarial attacks on graph-level embedding methods: a case study
    Maurizio Giordano
    Lucia Maddalena
    Mario Manzo
    Mario Rosario Guarracino
    Annals of Mathematics and Artificial Intelligence, 2023, 91 : 259 - 285
  • [45] Adversarial attacks on graph-level embedding methods: a case study
    Giordano, Maurizio
    Maddalena, Lucia
    Manzo, Mario
    Guarracino, Mario Rosario
    ANNALS OF MATHEMATICS AND ARTIFICIAL INTELLIGENCE, 2023, 91 (2-3) : 259 - 285
  • [46] Cybersecurity Awareness Enhancement: A Study of the Effects of Age and Gender of Thai Employees Associated with Phishing Attacks
    Daengsi, Therdpong
    Pornpongtechavanich, Phisit
    Wuttidittachotti, Pongpisit
    EDUCATION AND INFORMATION TECHNOLOGIES, 2022, 27 (04) : 4729 - 4752
  • [47] Cybersecurity Awareness Enhancement: A Study of the Effects of Age and Gender of Thai Employees Associated with Phishing Attacks
    Therdpong Daengsi
    Phisit Pornpongtechavanich
    Pongpisit Wuttidittachotti
    Education and Information Technologies, 2022, 27 : 4729 - 4752
  • [48] Reinforcing Cybersecurity Awareness through Simulated Phishing Attacks: Findings From an HEI Case Study
    Ciupe, Aurelia
    Orza, Bogdan
    2024 IEEE GLOBAL ENGINEERING EDUCATION CONFERENCE, EDUCON 2024, 2024,
  • [49] A Study on Adversarial Sample Resistance and Defense Mechanism for Multimodal Learning-Based Phishing Website Detection
    Duy, Phan The
    Minh, Vo Quang
    Dang, Bui Tan Hai
    Son, Ngo Duc Hoang
    Quyen, Nguyen Huu
    Pham, Van-Hau
    IEEE Access, 2024, 12 : 137805 - 137824
  • [50] Adversarial Attacks in a Multi-view Setting: An Empirical Study of the Adversarial Patches Inter-view Transferability
    Tarchoun, Bilel
    Alouani, Ihsen
    Ben Khalifa, Anouar
    Mahjoub, Mohamed Ali
    2021 INTERNATIONAL CONFERENCE ON CYBERWORLDS (CW 2021), 2021, : 299 - 302