Usability evaluation of anti-phishing toolbars

被引:1
|
作者
Linfeng Li
Marko Helenius
机构
[1] University of Tampere,Department of Computer Sciences
来源
Journal in Computer Virology | 2007年 / 3卷 / 2期
关键词
Usability Evaluation; Usability Problem; Usability Issue; Menu Item; Heuristic Evaluation;
D O I
10.1007/s11416-007-0050-4
中图分类号
学科分类号
摘要
Phishing is considered as one of the most serious threats for the Internet and e-commerce. Phishing attacks abuse trust with the help of deceptive e-mails, fraudulent web sites and malware. In order to prevent phishing attacks some organizations have implemented Internet browser toolbars for identifying deceptive activities. However, the levels of usability and user interfaces are varying. Some of the toolbars have obvious usability problems, which can affect the performance of these toolbars ultimately. For the sake of future improvement, usability evaluation is indispensable. We will discuss usability of five typical anti-phishing toolbars: built-in phishing prevention in the Internet Explorer 7.0, Google toolbar, Netcraft Anti-phishing toolbar and SpoofGuard. In addition, we included Internet Explorer plug-in we have developed, Anti-phishing IEPlug. Our hypothesis was that usability of anti-phishing toolbars, and as a consequence also security of the toolbars, could be improved. Indeed, according to the heuristic usability evaluation, a number of usability issues were found. In this article, we will describe the anti-phishing toolbars, we will discuss anti-phishing toolbar usability evaluation approach and we will present our findings. Finally, we will propose advices for improving usability of anti-phishing toolbars, including three key components of anti-phishing client side applications (main user interface, critical warnings and the help system). For example, we found that in the main user interface it is important to keep the user informed and organize settings accordingly to a proper usability design. In addition, all the critical warnings an anti-phishing toolbar shows should be well designed. Furthermore, we found that the help system should be built to assist users to learn about phishing prevention as well as how to identify fraud attempts by themselves. One result of our research is also a classification of anti-phishing toolbar applications.
引用
收藏
页码:163 / 184
页数:21
相关论文
共 50 条
  • [1] Usability evaluation of anti-phishing toolbars
    Li, Linfeng
    Helenius, Marko
    [J]. JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2007, 3 (02): : 163 - 184
  • [2] Usability Evaluation of Active Anti-Phishing Browser Extensions for Persons with Visual Impairments
    Sonowal, Gunikhan
    Kuppusamy, K. S.
    Kumar, Ajit
    [J]. 2017 4TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATION SYSTEMS (ICACCS), 2017,
  • [3] An Evaluation of Users' Anti-Phishing Knowledge Retention
    Alnajim, Abdullah
    Munro, Malcolm
    [J]. 2009 INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT AND ENGINEERING, PROCEEDINGS, 2009, : 210 - 214
  • [4] Classification of Anti-phishing Solutions
    Chanti S.
    Chithralekha T.
    [J]. SN Computer Science, 2020, 1 (1)
  • [5] A Secured Methodology for Anti-Phishing
    Churi, Tanvi
    Sawardekar, Pranay
    Pardeshi, Abhijeet
    Vartak, Pallavi
    [J]. 2017 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2017,
  • [6] Anti-Phishing in Offense and Defense
    Yue, Chuan
    Wang, Haining
    [J]. 24TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2008, : 345 - 354
  • [7] Anti-phishing: A comprehensive perspective
    Varshney, Gaurav
    Kumawat, Rahul
    Varadharajan, Vijay
    Tupakula, Uday
    Gupta, Chandranshu
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2024, 238
  • [8] NoPhish: An anti-phishing education app
    Canova, Gamze
    Volkamer, Melanie
    Bergmann, Clemens
    Borza, Roland
    [J]. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2014, 8743 : 88 - 192
  • [9] Lessons From a Real World Evaluation of Anti-Phishing Training
    Kumaraguru, Ponnurangam
    Sheng, Steve
    Acquist, Alessandro
    Cranor, Lorrie Faith
    Hong, Jason
    [J]. 2008 ECRIME RESEARCHERS SUMMIT, 2008, : 59 - 70
  • [10] NoPhish: An Anti-Phishing Education App
    Canova, Gamze
    Volkamer, Melanie
    Bergmann, Clemens
    Borza, Roland
    [J]. SECURITY AND TRUST MANAGEMENT (STM 2014), 2014, 8743 : 188 - 192