Cyber Security: A Longitudinal Examination of Undergraduate Behavior and Perceptions
Carl J. Case, Darwin L. King · 2013
ABSTRACT:Internet fraud continues to be a challenge in the business world. This study was undertaken to expand upon a previous study and determine if undergraduate students are at a similar cyber security risk. Findings suggest that spam and phishing are becoming less problematic for the undergraduate population. During the five-year study period, spam decreased by 38%, the volume of phishing attacks decreased by 36%, and by 2012, only 4% of students reported receiving phishing attacks. It could be surmised that improved spam filters, proactive education, and responsible student behavior may be driving this positive trend.Case, Carl J.King, Darwin L.INTRODUCTIONInternet fraud has been an issue for many years. In 2001, for example, the Internet Fraud Complaint Center had complaints such as the Nigerian letter fraud (15% of complaints), identity theft (1.3% of complaints), and confidence fraud (3.1% of complaints) (Gierlasinski and Sullivan, 2007).Today, threats come in newer forms such as URL shortening, malware, phishing, and smishing. URL shortening or obfuscation results in the user being unknowingly redirected to another web address when a link is clicked (Wikipedia, 2012). Malware includes viruses, worms, botnets, and so on. Botnet command and control, for example, has been utilized on social networks. Kneber and Zeus are just two of these attacks that were used to steal financial and law enforcement data (Wilson, 2011). Such threats can be from individuals such as Cosmo or groups such as Shadowcrew, an infamous hacker community (Cave, 2012; Lu, et.al, 2010). In May 2012, Cosmo and the rest of UGNazi hacked into one billing agency and subsequently posted 500,000 active credit card details online. In June 2012, Cosmo and others were arrested as part of a multi-state FBI sting targeting credit card fraud.Phishing attacks are highly targeted email designed to induce the recipient into divulging passwords, providing account information, or using malware to directly cause financial losses (Wikipedia, 2012). Estimates are that more than 500 million phishing emails are received each day (Sadeh, 2012).Smishing, a combination of the abbreviations for text messages (SMS or Short Message Service) and phishing, is a technique and security concern with regard to mobile devices (Serrano, 2011). It is estimated that each day in 2012, approximately 45 million spam text messages, triple the level in 2011, were sent to North American cell phones (Kirchheimer, 2012). According to Cloudmark, an anti-spam software company, at least 70% of this spam is designed to defraud the recipient.Unfortunately, attacks appear to be increasing. In April 2009, for example, only 21% of firms reported malware attacks and 21% reported phishing (Cluley, 2010). However, a 2011 Information Week Strategic Security Survey of 219 business technical and security professionals found that 78% of firms had malware attacks and 46% of firms experienced phishing (Davis, 2012). Moreover, the 2012 Data Encryption Survey of 506 business technology professionals found, for example, that databases are largely unprotected with only 33% having encryption at the database level (Davis, 2012). In addition, from April 2005 to October 2012, there have been more than 563 million documented data breaches in the U.S. (Privacy Rights Clearinghouse, 2012). These breaches include unintended disclosure, hacking or malware, payment card fraud, and so on. The cost of each breach was estimated to be $214 per compromised record in 2010 (Ponemon, 2011).One of the more publicized breaches occurred with Wired reporter Mat Honan (Acohido, 2012). Hackers tricked an Amazon phone representative into revealing the last four digits of Honan's credit card and then used this data to persuade an Apple representative to reset Honan's Apple ID password. This enabled the hacker to wipe clean Honan's iPhone, iPad, and MacBook, thus destroying all of his files. …