2016
DOI: 10.1007/978-3-319-33630-5_10
|View full text |Cite
|
Sign up to set email alerts
|

Teaching Phishing-Security: Which Way is Best?

Abstract: Abstract. Ever more processes of our daily lives are shifting into the digital realm. Consequently, users face a variety of IT-security threats with possibly severe ramifications. It has been shown that technical measures alone are insufficient to counter all threats. For instance, it takes technical measures on average 32 hours before identifying and blocking phishing websites. Therefore, teaching users how to identify malicious websites is of utmost importance, if they are to be protected at all times. A num… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

2
25
0

Year Published

2017
2017
2024
2024

Publication Types

Select...
6
2

Relationship

2
6

Authors

Journals

citations
Cited by 29 publications
(27 citation statements)
references
References 12 publications
2
25
0
Order By: Relevance
“…The first provides a general introduction to phishing, a brief overview of the techniques used by cybercriminals, their potential consequences, and the indicators to help detect illegitimate emails and URLs. The second provides additional instruction on how to avoid being deceived by phishing emails or URLs. Game-based training (self-paced, both groups): Many studies [10, 11, 13, 15, 16, 20, 21, 22] leverage game-play to interactively educate users. Training games allow users to play interactively with challenges to decide if emails are trustworthy.…”
Section: Methodsmentioning
confidence: 99%
See 2 more Smart Citations
“…The first provides a general introduction to phishing, a brief overview of the techniques used by cybercriminals, their potential consequences, and the indicators to help detect illegitimate emails and URLs. The second provides additional instruction on how to avoid being deceived by phishing emails or URLs. Game-based training (self-paced, both groups): Many studies [10, 11, 13, 15, 16, 20, 21, 22] leverage game-play to interactively educate users. Training games allow users to play interactively with challenges to decide if emails are trustworthy.…”
Section: Methodsmentioning
confidence: 99%
“…This study uses the web browser-based game Anti-Phishing Phil [13] (freely accessible at http://www.ucl.ac.uk/cert/antiphishing/) and Anti-Phishing Phyllis ( free demo version at https://beta.wombatsecurity.com/webdemo/4.7/?module=phyllis). Both games played completely take between five and 10 min. Text-based training (self-paced, both groups): An educational text was created based on freely available material [13, 15, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31] including examples and describing the best practices to detect phishing emails. The content is identical to the instructor-led training presentation with a brief introduction to phishing, an example with its possible consequences, indicators of illegitimate emails and URL addresses, and additional examples of phishing emails and websites.…”
Section: Methodsmentioning
confidence: 99%
See 1 more Smart Citation
“…Our proposed concept requires the goals to be derived from behavioral recommendations of information security awareness materials. We chose an extended version of the NoPhish anti-phishing awareness and education materials (Stockhardt et al, 2016) as basis for our goal derivation. They were a perfect fit, since they include clear behavioral recommendations and their effectiveness was proven in many settings (Canova et al, 2014;Kunz et al, 2016;Stockhardt et al, 2016).…”
Section: Creation Of the Goals Used In The Studymentioning
confidence: 99%
“…Our research group has a long history of developing phishing awareness programmes (including apps, flyers, reading material, presentations for seminars) and have carried out several user studies verifying their effectiveness [5][6][7]26,28,33,[39][40][41]. Our initial programmes required learners to spend between 20 to 45 minutes completing the awareness programmes.…”
Section: Introductionmentioning
confidence: 99%