Methodologies and Ethical Considerations in Phishing Research: A Comprehensive Review

George N. Thomopoulos, Dimitrios P. Lyras, Christos A. Fidas · 2023

Phishing is a significant security threat that causes financial and reputational losses to end-users and service providers in modern information systems. Current anti-phishing research is fragmented and does not address the issue from a pervasive computing perspective. As phishing attacks exploit human susceptibility, designing appropriate and personalized anti-phishing security frameworks that consider individual behavior is crucial. Phishing experiments raise ethical and legal concerns. Researchers carry out experiments to measure the probability and frequency that something vulnerable could happen, using this information to identify the most effective protection measures. This paper aims to identify ethical and practical issues related to the creation and execution of phishing experiments. The review examines the types of experiments conducted, ethical rules applied, user consent obtained, and the types of phishing examined in the experiments. Our aim in this review is to focus on identifying legal white spaces and ethical considerations by providing a complete review of the current approaches and processes used in phishing experiments.

Read the paper · More papers on PaperTik