Email is ubiquitous, and in the context of phishing, it becomes critical, as risky behaviours like clicking on phishing links or downloading malicious files can lead to severe consequences. While much research exists on phishing susceptibility, there is still a gap in understanding factors that influence user micro-behaviour when interacting with phishing emails. To address this, we offer a tool, the Precision Email Simulator, to support phishing researchers, as well as considerations in conceptualising controlled ‘experimental simulation’ studies, which are currently underutilised in phishing research. The Precision Email Simulator simulates real-world email inboxes and tracks precision user data, such as time spent on messages and eye-tracking for key areas like URLs and sender addresses. We discuss the practical uses of our simulator, and provide recommendations and guidelines of using our email simulator.
Phishing sites exploit users’ limited understanding of website identity to mimic legitimate sites. While X.509 certificates can provide crucial cues regarding a website’s identity, current browsers fail to effectively communicate this information to users, even as phishing becomes an increasingly serious issue. To address this, we developed Site Inspector (SI), a UI tool that conveys website identity and connection encryption information, along with brief explanations of the relevant underlying security concepts. SI is implemented as a Mozilla Firefox browser extension, but the basic design could be integrated into any web browser. SI organizes content in a three-tiered abstraction hierarchy, drawing on Ecological Interface Design. The top level presents an indicator of the website owner, if known, and also whether the connection is encrypted. The second and third levels offer progressively detailed explanations of the verification process. SI adheres to design principles aimed at educating users about security through the UI while overcoming associated challenges. Its text is concise and direct, respecting limitations in users’ attentional resources and motivation to engage with security matters. As a proof of concept for SI’s principled design, we conducted a user study with 30 participants to evaluate its effectiveness in helping users differentiate real from fraudulent websites. Results suggested that SI improved users’ ability to identify fraudulent sites. Future work will involve further testing with a larger user base, integrated SI directly into browsers, and ultimately a more widespread and improved validation process for certificates, with stronger verification and transparency
Online scams targeting Pasifika people are on the rise, posing a challenge for security. To investigate how language affects phishing susceptibility, we partnered with the IT department of the national government of a Melanesian country to conduct an ecologically valid phishing simulation study with the government's employees. Each month for four months, 2,000 participants received a simulated phishing email written in either English or the local language of their country; all participants were competent in both languages. We recorded whether participants opened the email and whether they clicked the link within it. When emails included personal requests for assistance, those in the local language elicited more clicks than those in English. These findings may be due to the influence of emotion on reasoning when thinking in a foreign language, a cultural emphasis on helping in Melanesian societies, and in-group preferences. We discuss the implications for how language and culture can impact vulnerability with special attention to low-resource languages which are likely to have less effective mail filters.
This paper investigates how non-experts understand figurative language created by computer scientists to describe cybersecurity incidents. Its method is informed by applied linguistics, crisis communication, and cybersecurity research. Using a set of cyberattack stories composed with figurative words and a set composed with more literal versions, and an online survey, the study examines whether the use of metaphor and neologism clarifies or obfuscates the technical aspects of cybersecurity for non-experts. The results showed participants in the literal set scored significantly better in comprehension. However, participants made important errors in both literal and figurative versions. This underlines the need for organizations to employ language strategically and provide more effective explanations of cybersecurity situations.
Modern software applications, notably those utilizing microservices architectures, rely heavily on REST API technology for communication. Testing these APIs is challenging, time-consuming, and prone to errors. This paper introduces Pulse-UI, an AI-supported tool designed to enhance test sequence generation for REST APIs, aiming to reduce the workload involved in managing test sequences efficiently and improve overall test quality.
Phishing emails typically masquerade themselves as reputable identities to trick people into providing sensitive information and credentials. Despite advancements in cybersecurity, attackers continuously adapt, posing ongoing threats to individuals and organisations. While email users are the last line of defence, they are not always well-prepared to detect phishing emails. This study examines how workload affects susceptibility to phishing, using eye-tracking technology to observe participants’ reading patterns and interactions with tailored phishing emails. Incorporating both quantitative and qualitative analysis, we investigate users’ attention to two phishing indicators, email sender and hyperlink URLs, and their reasons for assessing the trustworthiness of emails and falling for phishing emails. Our results provide concrete evidence that attention to the email sender can reduce phishing susceptibility. While we found no evidence that attention to the actual URL in the browser influences phishing detection, attention to the text masking links can increase phishing susceptibility. We also highlight how email relevance, familiarity, and visual presentation impact first impressions of email trustworthiness and phishing susceptibility.
The never-ending barrage of malicious emails, such as spam and phishing, is of constant concern for users, who rely on countermeasures such as email filters to keep the intended recipient safe. Modern email filters, one of our few defence mechanisms against malicious emails, are often circumvented by sophisticated attackers. This study focuses on how attackers exploit HTML and CSS in emails to conceal arbitrary content, allowing for multiple permutations of a malicious email, some of which may evade detection by email filters. This concealed content remains undetected by the recipient, presenting a serious security risk. Our research involved developing and applying an email sampling and analysis procedure to a large-scale dataset of unsolicited emails. We then identify the sub-types of concealment attackers use to conceal content and the HTML and CSS tricks employed.
Programming languages are languages --- “unnatural” languages because they are constructed explicitly; “formal” languages because they rely on mathematical notations and are described mathematically; “machine” languages because they are used to communicate with machines. Above all, programming languages are “human” languages. Programs in programming languages are spoken and read and written and designed and debugged and debated by humans, supported by human communities and forming those communities in turn. Langauge implementations, being programs themselves, are likewise designed and debugged and debated by humans. Programming languages adopt structural elements from natural language, including syntax, grammar, vocabulary, and even some sentence structure. Other aspects of language have received less attention, including noun declension, verb tense, and situation-appropriate register. Semiotics shows how language use can connote and imply, and will lead to interpretation. Language involves larger level structure too: conversations, stories, and documents of all kinds. Language supports both cognitive and affective processes, and is involved in building mental models that we use to recall, reason, and respond. Programming is a complex activity, uncertain yet precise, individual and social, involving intent and interpretation. Language is not the accident of programming --- it is the essence.
Phishing is one of the most prevalent social engineering attacks that targets both organizations and individuals. It is crucial to understand how email presentation impacts users' reactions to phishing attacks. We speculated that the device and email presentation may play a role, and, in particular, that how links are shown might influence susceptibility. Collaborating with the IT Services unit of a large organization doing a phishing training exercise, we conducted a study to explore the effects of the device and the presentation of links. Our findings indicate that mobile device and computer users were equally likely to click on unmasked links, however mobile device users were more likely to click on masked links compared to computer users. These findings suggest that link presentation plays a significant role in users' susceptibility to phishing attacks.
Phishing is recognized as a serious threat to organizations and individuals. While there have been significant technical advances in blocking phishing attacks, end-users remain the last line of defence after phishing emails reach their email inboxes. Most of the existing literature on this subject has focused on the technical aspects related to phishing. The factors that cause humans to be susceptible to phishing attacks are still not well-understood. To fill this gap, we reviewed the available literature and systematically categorized the phishing susceptibility variables studied. We classify variables based on their temporal scope, which led us to propose a three-stage Phishing Susceptibility Model (PSM) for explaining how humans are vulnerable to phishing attacks. This model reveals several research gaps that need to be addressed to understand and improve protection against phishing susceptibility. Our review also systematizes existing studies by their sample size and generalizability and further suggests a practical impact assessment of the value of studying variables: Some more easily lead to improvements than others. We believe that this article can provide guidelines for future phishing susceptibility research to improve experiment design and the quality of findings.
This paper explores how cultural factors impact the password-sharing attitudes and practices of young Bangladeshi adults.We conducted semi-structured interviews with 24 Bangladeshi participants aged between 18 and 39 about how, why, and with whom they share passwords.Using Grounded Theory, we identified three stages of password sharing (motivations, expectations, and problems) and three cultural factors (gender identity, collectivist social norms, and religious identity) that impact password sharing in Bangladesh.We found that password sharing is pervasive, and deeply affected by Bangladeshi culture and identity.Young adults' motivations and expectations for password sharing were complex and nuanced, and often served poorly by the tools and accounts that they were attempting to share.We found that Bangladeshi culture creates a situation in which password sharing is inevitable, but where individuals are inconvenienced and sometimes endangered by the action.
Phishing is one of the most prevalent social engineering attacks that targets both organisations and individuals. It is crucial to understand how email presentation impacts users’ reactions to phishing attacks. We hypothesised that device type and email presentation could potentially play a role, particularly in how links are displayed, which might influence susceptibility. In collaboration with the IT Services unit of a large organisation for a phishing training exercise, we conducted a study to explore the effects of device type and link presentation. Our findings revealed no significant difference in users’ susceptibility to phishing when using mobile devices versus computers. However, the masking of phishing links as buttons or hypertext appeared to be influential in shaping users’ behaviour. More specifically, users were significantly more likely to click on phishing links when masked as hypertext. These findings suggest that link presentation plays a significant role in users’ susceptibility to phishing attacks.
Little research has been done on enabling software development teams to self-report waste to assist in productivity improvement. This study created a waste categorization and survey for teams to identify and quantify wasteful activities. Developers from a Swiss company used the survey for three weeks. Participants found the survey helpful for identifying waste but there was little evidence that self-reported waste correlated with improved performance.
Visual appeal has been shown to influence perceptions of usability and credibility, and we hypothesize that something similar is happening with user judgments of website security: What is beautiful is secure. Web certificates provide reliable information about a website's level of security, presented in browser interfaces. Users should use this to inform their trust decisions online, but evidence from laboratory studies and real-world usage suggests that they do not. We conducted two studies-one in lab, and one online-in which participants view and interact with websites with high and low visual appeal, and various security levels, and then make security-related judgments. In both studies, participants consistently rated visually appealing websites as more secure, and indicated they would be more likely to enter sensitive information into visually appealing websites-even when they were less secure. Our results provide evidence that users rely on visual appeal when making security and trust decisions on websites. We discuss how these results may be used to help users.
The principles in the Agile Manifesto, the Scrum Guide and most other approaches to agile software development emphasize self-organizing teams, but rarely address issues of leadership. In this paper we report on a study of the nature of different aspects of leadership in agile teams. We used an established model of leadership, distinguishing transactional and transformational styles, and asked IT professionals a set of questions about the leadership they experience, both from direct supervisors (hierarchical leadership) and from the team itself (shared leadership). We determined correlation measures of these four types of leadership with the extent of agility in the whole organization. Our results show that agility is indeed related to the transformational style, but that the transactional style also plays a part, especially as shared leadership. Furthermore, even in highly agile software development, leadership by direct supervisors still plays an important role. We propose that, as software development becomes more agile, the transactional aspects of leadership may shift away from the leadership dyad between supervisor and employee into the agile team, while transformational leadership is important for both the team and supervisors. We discuss our results in light of applications for both research and practice.
Background: Data breaches happen when an unauthorized party gains access to personally identifiable information. They are becoming more common and impactful, raising serious concerns for individuals as well as companies. Literature review: Although there is considerable literature on users’ mental models in security and privacy, there has been limited study of mental models related to data breaches. Research questions: 1. How do users understand data breaches? 2. What are their perceptions of the causes, responsibilities, and consequences, as well as possible prevention and appropriate follow up? Methodology: We explored end-user understanding of internet data breaches by conducting a study with 35 participants. They were asked to draw their understanding of data breaches and answer some open-ended and closed-ended questions afterwards. Results/discussion: Although their drawings varied in detail and complexity, we identified four patterns in the participants’ drawings: they illustrated abstractions of attacks to gain administrator access, end-user access, backdoor access, or access using database server vulnerabilities. We found that participants had a basic model of how an internet data breach happens, but with significant uncertainties regarding system vulnerabilities, causes, consequences, prevention methods, and follow-up steps after a breach. Conclusions: In all, end-user mental models of internet data breaches are basic and show gaps that emphasize the need for improved communication to increase users’ awareness and help them hold companies accountable.
ABSTRACTAn important challenge in cybersecurity is that many users have only weak understanding of the threats involved, and the defences against them. This means that, even when defences are available, user behaviour sometimes allows successful attacks. In the everyday world, however, most people have well-established security practices, and we speculate that learning about these practices might help identify patterns for software to better support secure user behaviour. This papers presents a focus group we conducted to start learning about the everyday security practices of people. Our analysis of the discussion shows several themes, including the role of context, various forms of dissuasion, checking before and after an absence, monitoring while away, and forms of insurance should an attack be successful. Overall, we came to see there was a cycle of behaviour from being at home, where people felt safer, and away, where risks were expected. We consider how these themes and the overall cycle might apply to cybersecurity.
Ali Arya合作论文数Dept . of Electrical & Computer Engineering, University of British Columbia12