Users are the last line of defense as phishing emails pass filter mechanisms. At the same time, phishing emails are designed so that they are challenging to identify by users. To this end, attackers employ techniques, such as eliciting stress, targeting helpfulness, or exercising authority, due to which users often miss being manipulated out of malicious intent. This work builds on the assumption that manipulation techniques, even if going unnoticed by users, still lead to changes in their behavior. In this work, we present the outcomes of an online study in which we collected gaze and mouse movement data during an email sorting task. Our findings show that phishing emails lead to significant differences across behavioral features but depend on the nature of the email. We discuss how our findings can be leveraged to build security mechanisms protecting users and companies from phishing.
翻译:用户作为网络钓鱼邮件绕过过滤机制后的最后一道防线,而钓鱼邮件本身的设计使其难以被用户识别。为此,攻击者采用诸如引发压力、利用助人心理或行使权威等技术手段,导致用户往往在无意识中被恶意操纵。本研究基于一个假设:即便用户未能察觉操纵技术,这些技术仍会引发其行为变化。我们通过在线实验收集了用户在邮件分类任务中的注视点与鼠标移动数据,研究结果表明:钓鱼邮件会导致行为特征出现显著差异,但具体差异取决于邮件性质。本文探讨了如何利用这些发现构建保护用户和企业免受钓鱼攻击的安全机制。