Proceedings 2018 Workshop on Usable Security 2018
DOI: 10.14722/usec.2018.23016
|View full text |Cite
|
Sign up to set email alerts
|

User Context: An Explanatory Variable in Phishing Susceptibility

Abstract: Abstract-Extensive research has been performed to examine the effectiveness of phishing defenses, but much of this research was performed in laboratory settings. In contrast, this work presents 4.5 years of workplace-situated, embedded phishing email training exercise data, focusing on the last three phishing exercises with participant feedback. The sample was an operating unit consisting of approximately 70 staff members within a U.S. government research institution. A multiple methods assessment approach rev… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

1
44
0

Year Published

2019
2019
2024
2024

Publication Types

Select...
4
2
1

Relationship

0
7

Authors

Journals

citations
Cited by 36 publications
(45 citation statements)
references
References 12 publications
1
44
0
Order By: Relevance
“…There were more clickers on the IT help desk email than the other two emails. This result may suggest that university employees pay more attention to emails related to their work context, which is consistent with findings from Greene et al [5]. The financial email fooled the smallest proportion of users, which may suggest that people are more alert to the emails that come from an unfamiliar bank that they were not enrolled.…”
Section: Discussionsupporting
confidence: 88%
See 3 more Smart Citations
“…There were more clickers on the IT help desk email than the other two emails. This result may suggest that university employees pay more attention to emails related to their work context, which is consistent with findings from Greene et al [5]. The financial email fooled the smallest proportion of users, which may suggest that people are more alert to the emails that come from an unfamiliar bank that they were not enrolled.…”
Section: Discussionsupporting
confidence: 88%
“…Jagatic et al [9] suggest that a sender address from the university domain lowers students' guard. Greene et al [5] argue that the alignment of user context and the phishing attack premise is a significant factor in phishing susceptibility. Vishwanath et al [14] found the level of attention to urgency cues or to email subject lines significantly affects clicking response to phishing emails; however, levels of attention to grammar or spelling were significantly less likely to affect users being phished.…”
Section: Phishing Email Content Previous Researchmentioning
confidence: 99%
See 2 more Smart Citations
“…Past work [14] has shown that click rates will vary based on the contextual relevance of the phish, with highly contextually relevant phish resulting in extreme spikes in click rates-despite years of phishing awareness training. Furthermore, attackers continue to refine and vary phishing attack premises.…”
Section: Introductionmentioning
confidence: 99%