An empirical investigation of the effect of target-related information in phishing attacks

被引:6
|
作者
Flores, Waldo Rocha [1 ]
Holm, Hannes [2 ]
Nohlberg, Marcus [3 ]
Ekstedt, Mathias [1 ]
机构
[1] Royal Inst Technol, Ind Informat & Control Syst, Stockholm, Sweden
[2] Swedish Def Res Agcy FOI, Linkoping, Sweden
[3] Univ Skovde, Sch Informat, Skovde, Sweden
关键词
Social engineering; phishing; security behavior; experiments; direct observations;
D O I
10.1109/EDOCW.2014.59
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Analyzing the role of target-related information in a security attack is an understudied topic in the behavioral information security research field. This paper presents an empirical investigation of the effect of adding information about the target in phishing attacks. Data was collected by conducting two phishing experiments using a sample of 158 employees at five Swedish organizations. The first experiment included a traditional mass-email attack with no target-related information, and the second experiment was a targeted phishing attack in which we included specific information related to the targeted employees' organization. The results showed that the number of organizational employees falling victim to phishing significantly increased when target-related information was added in the attack. During the first experiment 5.1 % clicked on the malicious link compared to 27.2 % of the second phishing attack, and 8.9 % of those executed the binary compared to 3.2 % of the traditional phishing attack. Adding target-related information is an effective way for attackers to significantly increase the effectiveness of their phishing attacks. This is the first study that has showed this significant effect using organizational employees as a sample. The implications of the results are further discussed.
引用
收藏
页码:357 / 363
页数:7
相关论文
共 50 条
  • [1] TARGET-RELATED NEOLOGISM FORMATION IN JARGONAPHASIA
    CHRISTMAN, SS
    [J]. BRAIN AND LANGUAGE, 1994, 46 (01) : 109 - 128
  • [2] The effect of target-related and target-irrelevant novel stimuli on response behaviour
    Hall, Julie M.
    Park, Haeme R. P.
    Krebs, Ruth M.
    Schomaker, Judith
    [J]. ACTA PSYCHOLOGICA, 2023, 232
  • [3] Target-related coordination of bimanual reaching movements
    Weigelt, M
    Mechsner, F
    Rieger, M
    Prinz, W
    [J]. JOURNAL OF SPORT & EXERCISE PSYCHOLOGY, 2004, 26 : S195 - S196
  • [4] Spatiotemporal analysis of category and target-related information processing in the brain during object detection
    Karimi-Rouzbahani, Hamid
    Vahab, Ehsan
    Ebrahimpour, Reza
    Menhaj, Mohammad Bagher
    [J]. BEHAVIOURAL BRAIN RESEARCH, 2019, 362 : 224 - 239
  • [5] Target-related coupling in bimanual reaching movements
    Weigelt, Matthias
    Rieger, Martina
    Mechsner, Franz
    Prinz, Wolfgang
    [J]. PSYCHOLOGICAL RESEARCH-PSYCHOLOGISCHE FORSCHUNG, 2007, 71 (04): : 438 - 447
  • [6] Target-related coupling in bimanual reaching movements
    Matthias Weigelt
    Martina Rieger
    Franz Mechsner
    Wolfgang Prinz
    [J]. Psychological Research, 2007, 71 : 438 - 447
  • [7] Optimism bias in susceptibility to phishing attacks: an empirical study
    Owen, Morne
    Flowerday, Stephen V.
    van der Schyff, Karl
    [J]. INFORMATION AND COMPUTER SECURITY, 2024, : 656 - 675
  • [8] Two-Target Stance Detection with Target-Related Zone Modeling
    Liu, Huan
    Li, Shoushan
    Zhou, Guodong
    [J]. INFORMATION RETRIEVAL, CCIR 2018, 2018, 11168 : 170 - 182
  • [9] Phishing threat avoidance behaviour: An empirical investigation
    Arachchilage, Nalin Asanka Gamagedara
    Love, Steve
    Beznosov, Konstantin
    [J]. COMPUTERS IN HUMAN BEHAVIOR, 2016, 60 : 185 - 197
  • [10] Exploring target-related information with reliable global pixel relationships for robust RGB-T tracking
    Zhang, Tianlu
    He, Xiaoyi
    Luo, Yongjiang
    Zhang, Qiang
    Han, Jungong
    [J]. PATTERN RECOGNITION, 2024, 155