• DocumentCode
    113427
  • Title

    Model for analysing Anti-Phishing Authentication Ceremonies

  • Author

    Hatunic-Webster, Edina ; Mtenzi, Fred ; O´Shea, Brendan

  • Author_Institution
    Sch. of Comput., Dublin Inst. of Technol., Dublin, Ireland
  • fYear
    2014
  • fDate
    8-10 Dec. 2014
  • Firstpage
    144
  • Lastpage
    150
  • Abstract
    Phishing takes advantage of the way humans interact with computers or interpret messages; and also that many online authentication protocols place a disproportional burden on human abilities. A security ceremony is an extension of the concept of network security protocol and includes user interface and human-protocol interaction. It is one way of extending the reach of current methods for social, technical and contextual analysis of security protocols to include humans. In this paper, we propose a Human Factors in Anti-Phishing Authentication Ceremonies (APAC) Framework for investigating phishing attacks in authentication ceremonies, which builds on The Human-in-the-Loop Security Framework of communication processing. We show how to apply the APAC framework to model human-protocol behaviour. The resulting Model for Analysing APAC correlates the framework components and examines how the authentication tasks required to be performed by humans influence their decision-making and consequently their phishing detection.
  • Keywords
    computer crime; cryptographic protocols; decision making; human factors; user interfaces; APAC framework; antiphishing authentication ceremony analysis; communication processing; contextual analysis; decision-making; human factors; human-in-the-loop security framework; human-protocol behaviour; human-protocol interaction; network security protocol; online authentication protocols; security ceremony; social analysis; technical analysis; user interface; Analytical models; Authentication; Computational modeling; Information processing; Protocols; Servers; Anti-Phishing Authentication; Ceremonies; Modeling Human-Protocol Behaviour;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology and Secured Transactions (ICITST), 2014 9th International Conference for
  • Conference_Location
    London
  • Type

    conf

  • DOI
    10.1109/ICITST.2014.7038795
  • Filename
    7038795