Despite the sophisticated phishing email detection systems, and training and awareness programs, humans continue to be tricked by phishing emails. In an attempt to understand why phishing email attacks still work, we have carried out an empirical study to investigate how people make response decisions while reading their emails. We used a "think aloud" method and follow-up interviews to collect data from 19 participants. The analysis of the collected data has enabled us to identify eleven factors that influence people's response decisions to both phishing and legitimate emails. Based on the identified factors, we discuss how people can be susceptible to phishing attacks due to the flaws in their decision-making processes. Furthermore, we propose design directions for developing a behavioral plugin for email clients that can be used to nudge people's secure behaviors enabling them to have a better response to phishing emails.
翻译:尽管有先进的网上钓鱼电子邮件探测系统,以及培训和提高认识方案,人类仍然被网上钓鱼电子邮件所欺骗。为了了解为什么网上钓鱼电子邮件袭击仍然有效,我们开展了一项实证研究,调查人们如何在阅读电子邮件时做出回应决定。我们使用“高声思考”方法和后续访谈从19名参与者收集数据。对所收集的数据的分析使我们能够找出影响人们对网上钓鱼和合法电子邮件做出回应决定的11个因素。根据所查明的因素,我们讨论了人们如何因其决策过程的缺陷而容易遭到网上钓鱼袭击。此外,我们提出了为电子邮件客户开发行为插件的设计方向,该插件可用于激励人们的安全行为,使他们能够更好地回应网上钓鱼电子邮件。