DocumentCode
2210264
Title
Phishing in a university community: Two large scale phishing experiments
Author
Mohebzada, J.G. ; El Zarka, A. ; Bhojani, A.H. ; Darwish, Ali
Author_Institution
Dept. of Electr. & Comput. Eng., Univ. of Calgary, Calgary, AB, Canada
fYear
2012
fDate
18-20 March 2012
Firstpage
249
Lastpage
254
Abstract
Phishing is a type of social engineering where a potential victim is sent a message that impersonates a legitimate source or organization. Phishing attacks typically lure the targets into revealing confidential information such as password, credit card details, bank account numbers, or any other sensitive information. Human behavior and technology are two equally important aspects of phishing attacks, while current anti-phishing research have focused on the technology front, very few real life studies have been performed with a focus on the human aspects of phishing attacks. In this paper, we present the results of two large scale real life phishing attacks conducted on more than 10,000 community members of a university that includes students, alumni, faculty and staff. Our study is the first large scale phishing experiment on human subjects. Previous work suggests that users´ demographics are useful indicators in identifying the most vulnerable users to phishing attacks. Our results illustrate that user demographics alone cannot predict user´s susceptibility to phishing attacks. We also found that warning users about phishing risks alone is not sufficient to prevent more users from responding to the phishing attack. Even though subjects were warned not to respond to phishing emails, many disregarded the warning. We explain our findings through analysis of the empirical results of the two real life phishing attacks conducted.
Keywords
computer crime; data privacy; educational institutions; real-time systems; social sciences; unsolicited e-mail; confidential information; current antiphishing research; human behavior; human subjects; large scale phishing experiments; large scale real life phishing attacks; phishing emails; social engineering; university community; user susceptibility prediction; users demographics; Conferences; Information technology; Technological innovation; cyber security; personality trait; phishing; social engineering; user vulnerability;
fLanguage
English
Publisher
ieee
Conference_Titel
Innovations in Information Technology (IIT), 2012 International Conference on
Conference_Location
Abu Dhabi
Print_ISBN
978-1-4673-1100-7
Type
conf
DOI
10.1109/INNOVATIONS.2012.6207742
Filename
6207742
Link To Document