The Phishing Email Suspicion Test (PEST) a lab-based task for evaluating the cognitive mechanisms of phishing detection

被引:0
|
作者
Ziad M. Hakim
Natalie C. Ebner
Daniela S. Oliveira
Sarah J. Getz
Bonnie E. Levin
Tian Lin
Kaitlin Lloyd
Vicky T. Lai
Matthew D. Grilli
Robert C. Wilson
机构
[1] University of Arizona,Department of Psychology
[2] University of Florida,Department of Psychology
[3] University of Florida,Department of Aging and Geriatric Research, Institute on Aging
[4] University of Florida,Florida Institute for Cybersecurity
[5] Evelyn F. McKnight Brain Institute,Department of Electrical and Computer Engineering
[6] University of Florida,Department of Neurology, Miller School of Medicine
[7] University of Miami,Cognitive Science Program
[8] University of Arizona,undefined
来源
Behavior Research Methods | 2021年 / 53卷
关键词
Phishing; Cybersecurity; Decision making; Sequential effects;
D O I
暂无
中图分类号
学科分类号
摘要
Phishing emails constitute a major problem, linked to fraud and exploitation as well as subsequent negative health outcomes including depression and suicide. Because of their sheer volume, and because phishing emails are designed to deceive, purely technological solutions can only go so far, leaving human judgment as the last line of defense. However, because it is difficult to phish people in the lab, little is known about the cognitive and neural mechanisms underlying phishing susceptibility. There is therefore a critical need to develop an ecologically valid lab-based measure of phishing susceptibility that will allow evaluation of the cognitive mechanisms involved in phishing detection. Here we present such a measure based on a task, the Phishing Email Suspicion Test (PEST), and a cognitive model to quantify behavior. In PEST, participants rate a series of phishing and non-phishing emails according to their level of suspicion. By comparing suspicion scores for each email to its real-world efficacy, we find initial support for the ecological validity of PEST – phishing emails that were more effective in the real world were more effective at deceiving people in the lab. In the proposed computational model, we quantify behavior in terms of participants’ overall level of suspicion of emails, their ability to distinguish phishing from non-phishing emails, and the extent to which emails from the recent past bias their current decision. Together, our task and model provide a framework for studying the cognitive neuroscience of phishing detection.
引用
收藏
页码:1342 / 1352
页数:10
相关论文
共 20 条
  • [1] The Phishing Email Suspicion Test (PEST) a lab-based task for evaluating the cognitive mechanisms of phishing detection
    Hakim, Ziad M.
    Ebner, Natalie C.
    Oliveira, Daniela S.
    Getz, Sarah J.
    Levin, Bonnie E.
    Lin, Tian
    Lloyd, Kaitlin
    Lai, Vicky T.
    Grilli, Matthew D.
    Wilson, Robert C.
    BEHAVIOR RESEARCH METHODS, 2021, 53 (03) : 1342 - 1352
  • [2] Phishing Email Detection Based on Hybrid Features
    Yang, Zhuorao
    Qiao, Chen
    Kan, Wanling
    Qiu, Junji
    2018 4TH INTERNATIONAL CONFERENCE ON ENVIRONMENTAL SCIENCE AND MATERIAL APPLICATION, 2019, 252
  • [3] Detection method of phishing email based on persuasion principle
    Li, Xue
    Zhang, Dongmei
    Wu, Bin
    PROCEEDINGS OF 2020 IEEE 4TH INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2020), 2020, : 571 - 574
  • [4] LSTM Based Phishing Detection for Big Email Data
    Li, Qi
    Cheng, Mingyu
    Wang, Junfeng
    Sun, Bowen
    IEEE TRANSACTIONS ON BIG DATA, 2022, 8 (01) : 278 - 288
  • [5] A Content-Based Phishing Email Detection Method
    Che, Hongming
    Liu, Qinyun
    Zou, Lin
    Yang, Hongji
    Zhou, Dongdai
    Yu, Feng
    2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C), 2017, : 415 - 422
  • [6] Phishing Email Detection based on Named Entity Recognition
    Listik, Vit
    Let, Simon
    Sedivy, Jan
    Hlavac, Vaclav
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2019, : 252 - 256
  • [7] Phishing Email Detection Based on Binary Search Feature Selection
    Sonowal G.
    SN Computer Science, 2020, 1 (4)
  • [8] Intelligent Deep Learning Based Cybersecurity Phishing Email Detection and Classification
    Brindha, R.
    Nandagopal, S.
    Azath, H.
    Sathana, V
    Joshi, Gyanendra Prasad
    Kim, Sung Won
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 74 (03): : 5901 - 5914
  • [9] A Systematic Review on Deep-Learning-Based Phishing Email Detection
    Gray, L. Earl
    Conley, Justin M.
    Bursian, Steven J.
    Kamruzzaman, Abu
    Asif, Rameez
    ELECTRONICS, 2023, 12 (21)
  • [10] Simulating Phishing Email Processing with Instance-Based Learning and Cognitive Chunk Activation
    Shonman, Matthew
    Li, Xiangyang
    Zhang, Haoruo
    Dahbura, Anton
    BRAIN INFORMATICS, BI 2018, 2018, 11309 : 468 - 478