论文标题
少更多:利用社会信任来提高欺骗攻击的有效性
Less is More: Exploiting Social Trust to Increase the Effectiveness of a Deception Attack
论文作者
论文摘要
网络钓鱼,IRS骗局等网络攻击仍然成功地欺骗了互联网用户。用户是针对这些攻击的最后一条防线,因为攻击者似乎总是找到一种绕过安全系统的方法。了解用户对骗局和欺诈的理由可以帮助安全提供者改善用户安全卫生实践。在这项工作中,我们研究用户在公司代表欺诈的背景下的几个变量的推理和有效性。我们研究的一些变量是:1)使用LinkedIn作为传递网络钓鱼消息而不是使用电子邮件的媒介的效果,2)自然语言生成技术在生成网络钓鱼电子邮件中的有效性,3)如何将发送者的联系信息添加到电子邮件中,影响参与者的感知。从受试者内研究获得的结果表明,即使是为了著名的攻击 - 公司代表欺诈,参与者也没有准备。调查结果包括:大约65%的平均检测率和有关成功率如何随立面和通讯员(发送者/接收方)信息变化的见解。一个重要的发现是,一组较小的精心挑选的策略比大的“混乱”策略更好。我们还发现,男性和女性如何处理同一公司代表性欺诈方面存在显着差异。我们工作的见解可以帮助捍卫者制定更好的策略来评估其防御能力并制定更好的训练策略。
Cyber attacks such as phishing, IRS scams, etc., still are successful in fooling Internet users. Users are the last line of defense against these attacks since attackers seem to always find a way to bypass security systems. Understanding users' reason about the scams and frauds can help security providers to improve users security hygiene practices. In this work, we study the users' reasoning and the effectiveness of several variables within the context of the company representative fraud. Some of the variables that we study are: 1) the effect of using LinkedIn as a medium for delivering the phishing message instead of using email, 2) the effectiveness of natural language generation techniques in generating phishing emails, and 3) how some simple customizations, e.g., adding sender's contact info to the email, affect participants perception. The results obtained from the within-subject study show that participants are not prepared even for a well-known attack - company representative fraud. Findings include: approximately 65% mean detection rate and insights into how the success rate changes with the facade and correspondent (sender/receiver) information. A significant finding is that a smaller set of well-chosen strategies is better than a large `mess' of strategies. We also find significant differences in how males and females approach the same company representative fraud. Insights from our work could help defenders in developing better strategies to evaluate their defenses and in devising better training strategies.