The Experts below are selected from a list of 87 Experts worldwide ranked by ideXlab platform
Jason Hong - One of the best experts on this subject based on the ideXlab platform.
-
You've Been Warned: An Empirical Study of the Effectiveness of Web Browser Phishing Warnings
2018Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79% of participants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings
-
You've been warned: An empirical study of the effectiveness of web browser Phishing warnings
2014Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79 % of partici-pants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings. Author Keywords Phishing, warning messages, mental models, usable privac
-
Effectiveness of Web Browser Phishing Warnings
2012Co-Authors: Lorrie Faith Cranor, Jason Hong, Serge EgelmanAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79 % of participants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings. Figure 1. The active Internet Explorer 7.0 Phishing warning. Author Keywords Phishing, warning messages, mental models, usable privac
-
you ve been warned an empirical study of the effectiveness of web browser Phishing warnings
Human Factors in Computing Systems, 2008Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers are now including active Phishing warnings after previous research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79% of participants heeded them, which was not the case for the passive warning that we tested---where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective warning messages within the Phishing context.
-
You’ve Been Warned: An Empirical Study of the Effectiveness of Web Browser Phishing Warnings
2008Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79 % of participants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings
Serge Egelman - One of the best experts on this subject based on the ideXlab platform.
-
You've Been Warned: An Empirical Study of the Effectiveness of Web Browser Phishing Warnings
2018Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79% of participants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings
-
You've been warned: An empirical study of the effectiveness of web browser Phishing warnings
2014Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79 % of partici-pants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings. Author Keywords Phishing, warning messages, mental models, usable privac
-
Effectiveness of Web Browser Phishing Warnings
2012Co-Authors: Lorrie Faith Cranor, Jason Hong, Serge EgelmanAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79 % of participants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings. Figure 1. The active Internet Explorer 7.0 Phishing warning. Author Keywords Phishing, warning messages, mental models, usable privac
-
you ve been warned an empirical study of the effectiveness of web browser Phishing warnings
Human Factors in Computing Systems, 2008Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers are now including active Phishing warnings after previous research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79% of participants heeded them, which was not the case for the passive warning that we tested---where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective warning messages within the Phishing context.
-
You’ve Been Warned: An Empirical Study of the Effectiveness of Web Browser Phishing Warnings
2008Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79 % of participants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings
Lorrie Faith Cranor - One of the best experts on this subject based on the ideXlab platform.
-
You've Been Warned: An Empirical Study of the Effectiveness of Web Browser Phishing Warnings
2018Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79% of participants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings
-
You've been warned: An empirical study of the effectiveness of web browser Phishing warnings
2014Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79 % of partici-pants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings. Author Keywords Phishing, warning messages, mental models, usable privac
-
Effectiveness of Web Browser Phishing Warnings
2012Co-Authors: Lorrie Faith Cranor, Jason Hong, Serge EgelmanAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79 % of participants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings. Figure 1. The active Internet Explorer 7.0 Phishing warning. Author Keywords Phishing, warning messages, mental models, usable privac
-
you ve been warned an empirical study of the effectiveness of web browser Phishing warnings
Human Factors in Computing Systems, 2008Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers are now including active Phishing warnings after previous research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79% of participants heeded them, which was not the case for the passive warning that we tested---where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective warning messages within the Phishing context.
-
You’ve Been Warned: An Empirical Study of the Effectiveness of Web Browser Phishing Warnings
2008Co-Authors: Serge Egelman, Lorrie Faith Cranor, Jason HongAbstract:Many popular web browsers now include active Phishing warnings since research has shown that passive warnings are often ignored. In this laboratory study we examine the effectiveness of these warnings and examine if, how, and why they fail users. We simulated a Spear Phishing Attack to expose users to browser warnings. We found that 97% of our sixty participants fell for at least one of the Phishing messages that we sent them. However, we also found that when presented with the active warnings, 79 % of participants heeded them, which was not the case for the passive warning that we tested—where only one participant heeded the warnings. Using a model from the warning sciences we analyzed how users perceive warning messages and offer suggestions for creating more effective Phishing warnings
Chaojing Tang - One of the best experts on this subject based on the ideXlab platform.
-
Optimal Defense Strategy Selection for Spear-Phishing Attack Based on a Multistage Signaling Game
IEEE Access, 2019Co-Authors: Xiayang Chen, Lei Zhang, Chaojing TangAbstract:The integration of industrial control systems (ICS) with information technologies offers not only convenience but also creates security problems, from public networks to ICS. Spear-Phishing Attacks account for a considerable proportion of such security incidents. Therefore, there have been many studies about dealing with Spear-Phishing Attacks. Most of these studies focus on studying strategies with better defense capabilities for Spear-Phishing Attacks while neglecting the cost of implementing the strategies. However, a strategy with strong defense capabilities may not always be highly cost-effective. Moreover, considerable research has tended to consider the Attacker and defender separately while ignoring the fact that the Spear-Phishing Attack-defense process is a dynamic process of confrontation between the Attacker and the defender. Actually, the deployment of defense strategies should comprehensively consider the defender's condition and the adversary's possible actions. Therefore, how to select the optimal strategy that defends against Spear-Phishing Attacks with minimum overhead is a problem worthy of further study. Motivated by this consideration, we construct the multistage Spear-Phishing Attack-defense signaling game model (MSPAD-SGM), which comprehensively considers the defense capability, the strategy cost, and the possible strategies of the two sides. Based on this model, we propose the optimal strategy selection algorithm for the Spear-Phishing Attack-defense process. In addition, rather than numerical values, we adopt symbolic variables to quantify the payoffs and present a deep analysis of how the variation of payoffs influences the game result, which helps to reduce the subjectivity and improve the feasibility of our model. The simulation and deduction of the proposed approach are presented in a case study of MSPAD-SGM to demonstrate the feasibility and effectiveness of the proposed strategy's optimal selection approach. Our method provides decision support for the Spear-Phishing Attack-defense process and improves the dynamic analysis efficiency of defense decision-making.
Xiayang Chen - One of the best experts on this subject based on the ideXlab platform.
-
Optimal Defense Strategy Selection for Spear-Phishing Attack Based on a Multistage Signaling Game
IEEE Access, 2019Co-Authors: Xiayang Chen, Lei Zhang, Chaojing TangAbstract:The integration of industrial control systems (ICS) with information technologies offers not only convenience but also creates security problems, from public networks to ICS. Spear-Phishing Attacks account for a considerable proportion of such security incidents. Therefore, there have been many studies about dealing with Spear-Phishing Attacks. Most of these studies focus on studying strategies with better defense capabilities for Spear-Phishing Attacks while neglecting the cost of implementing the strategies. However, a strategy with strong defense capabilities may not always be highly cost-effective. Moreover, considerable research has tended to consider the Attacker and defender separately while ignoring the fact that the Spear-Phishing Attack-defense process is a dynamic process of confrontation between the Attacker and the defender. Actually, the deployment of defense strategies should comprehensively consider the defender's condition and the adversary's possible actions. Therefore, how to select the optimal strategy that defends against Spear-Phishing Attacks with minimum overhead is a problem worthy of further study. Motivated by this consideration, we construct the multistage Spear-Phishing Attack-defense signaling game model (MSPAD-SGM), which comprehensively considers the defense capability, the strategy cost, and the possible strategies of the two sides. Based on this model, we propose the optimal strategy selection algorithm for the Spear-Phishing Attack-defense process. In addition, rather than numerical values, we adopt symbolic variables to quantify the payoffs and present a deep analysis of how the variation of payoffs influences the game result, which helps to reduce the subjectivity and improve the feasibility of our model. The simulation and deduction of the proposed approach are presented in a case study of MSPAD-SGM to demonstrate the feasibility and effectiveness of the proposed strategy's optimal selection approach. Our method provides decision support for the Spear-Phishing Attack-defense process and improves the dynamic analysis efficiency of defense decision-making.