In this paper, we present findings from a large-scale and long-term phishing experiment that we conducted in collaboration with a partner company. Our experiment ran for 15 months during which time more than 14,000 study participants (employees of the company) received different simulated phishing emails in their normal working context. We also deployed a reporting button to the company's email client which allowed the participants to report suspicious emails they received. We measured click rates for phishing emails, dangerous actions such as submitting credentials, and reported suspicious emails. The results of our experiment provide three types of contributions. First, some of our findings support previous literature with improved ecological validity. One example of such results is good effectiveness of warnings on emails. Second, some of our results contradict prior literature and common industry practices. Surprisingly, we find that embedded training during simulated phishing exercises, as commonly deployed in the industry today, does not make employees more resilient to phishing, but instead it can have unexpected side effects that can make employees even more susceptible to phishing. And third, we report new findings. In particular, we are the first to demonstrate that using the employees as a collective phishing detection mechanism is practical in large organizations. Our results show that such crowd-sourcing allows fast detection of new phishing campaigns, the operational load for the organization is acceptable, and the employees remain active over long periods of time.
翻译:在本文中,我们介绍了我们与一个伙伴公司合作进行的大规模和长期的钓鱼试验的结果。我们的实验持续了15个月,在此期间,超过14 000名研究参与者(公司雇员)在正常工作环境中收到了不同的模拟钓鱼邮件。我们还为公司的电子邮件客户安装了一个报告按钮,使参与者能够报告他们收到的可疑电子邮件。我们测量了钓鱼电子邮件的点击率,提交了证书等危险行动,并报告了可疑的电子邮件。我们实验的结果提供了三种类型的贡献。首先,我们的一些研究结果支持了以前的文献,提高了生态有效性。其中一个例子是电子邮件警告效果良好。第二,我们的一些结果与先前的文献和通常的行业做法相矛盾。令人惊讶的是,我们发现在模拟钓鱼演习中嵌入的培训使参与者能够报告他们收到的可疑的邮件。我们测量了钓鱼邮件的点击率,但是它仍然可以产生意想不到的副作用,使雇员更易受钓鱼的影响。第三,我们的一些研究结果就是电子邮件警告的好的效果。第二,我们的一些结果与以前的文献和常见的行业做法相矛盾。我们发现,在模拟钓鱼练习中发现了一个新的组织。我们用来展示这种快速的快速的实验结果。特别地展示了我们的组织。