Modelling user-phishing interaction
Xun Dong, John A. Clark, Jeremy L. Jacob · 2008
To protect users from phishing attacks system designers and security professionals need to understand how users interact with those attacks and be able to predict users’ behaviours in a given situation. In this paper we introduce the first model to visualise user-phishing interaction. We present a method to accurately describe users’ perceptions in a uniform and compact manner. Within the context of this model we have investigated: what exact mismatches may occur between perception and reality in an attack; how to detect those mismatches; and why users fail to do so. Using this model we also identify where the security tools/indicators are lacking, suggest new aspects for security evaluation for the user interface, and provide guidance on effective anti-phishing user education.