Influence Techniques in Phishing Attacks: An Examination of Vulnerability and Resistance

成果类型:
Article
署名作者:
Wright, Ryan T.; Jensen, Matthew L.; Thatcher, Jason Bennett; Dinger, Michael; Marett, Kent
署名单位:
University of Massachusetts System; University of Massachusetts Amherst; University of Oklahoma System; University of Oklahoma - Norman; Clemson University; Mississippi State University
刊物名称:
INFORMATION SYSTEMS RESEARCH
ISSN/ISSBN:
1047-7047
DOI:
10.1287/isre.2014.0522
发表日期:
2014
页码:
385-400
关键词:
SELF-DETERMINATION THEORY Intrinsic motivation interpersonal deception E-commerce persuasion inoculation MODEL COMMUNICATION QUALITY logit
摘要:
Phishing is a major threat to individuals and organizations. Along with billions of dollars lost annually, phishing attacks have led to significant data breaches, loss of corporate secrets, and espionage. Despite the significant threat, potential phishing targets have little theoretical or practical guidance on which phishing tactics are most dangerous and require heightened caution. The current study extends persuasion and motivation theory to postulate why certain influence techniques are especially dangerous when used in phishing attacks. We evaluated our hypotheses using a large field experiment that involved sending phishing messages to more than 2,600 participants. Results indicated a disparity in levels of danger presented by different influence techniques used in phishing attacks. Specifically, participants were less vulnerable to phishing influence techniques that relied on fictitious prior shared experience and were more vulnerable to techniques offering a high level of self-determination. By extending persuasion and motivation theory to explain the relative efficacy of phishers' influence techniques, this work clarifies significant vulnerabilities and lays the foundation for individuals and organizations to combat phishing through awareness and training efforts.
来源URL: