Phishing in an academic community: A study of user susceptibility and behavior
dc.contributor.author | Diaz, Alejandra | |
dc.contributor.author | Sherman, Alan T. | |
dc.contributor.author | Joshi, Anupam | |
dc.date.accessioned | 2020-07-22T17:41:35Z | |
dc.date.available | 2020-07-22T17:41:35Z | |
dc.date.issued | 2019-08-13 | |
dc.description.abstract | We present an observational study on the relationship between demographic factors and phishing susceptibility at the University of Maryland, Baltimore County (UMBC). In spring 2018, we delivered phishing attacks to 450 randomly selected students on three different days (1,350 students total) to examine user click rates and demographics among UMBC’s undergraduates. Participants were initially unaware of the study. We deployed the billing problem, contest winner, and expiration date phishing tactics. Experiment 1 impersonated banking authorities; Experiment 2 enticed users with monetary rewards; and Experiment 3 threatened users with account cancelation. We found correlations resulting in lowered susceptibility based on college affiliation, academic year progression, cyber training, involvement in cyber clubs or cyber scholarship programs, time spent on the computer, and age demographics. We found no significant correlation between gender and susceptibility. Contrary to our expectations, we observed a reverse correlation between phishing awareness and student resistance to clicking. Students who identified themselves as understanding the definition of phishing had a higher susceptibility rate than did their peers who were merely aware of phishing attacks, with both groups having a higher susceptibility rate than those with no knowledge whatsoever. Approximately 70% of survey respondents who opened a phishing email clicked on it, with 60% of student having clicked overall. | en_US |
dc.description.sponsorship | The authors thank Professors Bimal Sinha and Nagaraj Neerchal for their counsel on statistical tests and models. We would also like to thank Jack Seuss, Andy Johnston, Mark Cather, and the DoIT staff for their support and help throughout the project. Sherman was supported in part by the National Science Foundation under SFS grant 1241576 and by the U.S. Department of Defense under CAE grant [H98230-17-1-0349]. Joshi was supported by an award from IBM. | en_US |
dc.description.uri | https://www.tandfonline.com/doi/abs/10.1080/01611194.2019.1623343 | en_US |
dc.format.extent | 16 pages | en_US |
dc.genre | journal articles | en_US |
dc.identifier | doi:10.13016/m2ujqr-omq1 | |
dc.identifier.citation | To cite this article: Alejandra Diaz, Alan T. Sherman & Anupam Joshi (2020) Phishing in an academic community: A study of user susceptibility and behavior, Cryptologia, 44:1, 53-67, DOI: 10.1080/01611194.2019.1623343 | en_US |
dc.identifier.uri | https://doi.org/10.1080/01611194.2019.1623343 | |
dc.identifier.uri | http://hdl.handle.net/11603/19222 | |
dc.language.iso | en_US | en_US |
dc.publisher | Taylor & Francis | en_US |
dc.relation.isAvailableAt | The University of Maryland, Baltimore County (UMBC) | |
dc.relation.ispartof | UMBC Computer Science and Electrical Engineering Department Collection | |
dc.relation.ispartof | UMBC Faculty Collection | |
dc.rights | This item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author. | |
dc.rights | Attribution-NonCommercial-NoDerivs 2.0 Generic | * |
dc.rights.uri | https://creativecommons.org/licenses/by-nc-nd/2.0/ | * |
dc.subject | UMBC Ebiquity Research Group | |
dc.title | Phishing in an academic community: A study of user susceptibility and behavior | en_US |
dc.type | Text | en_US |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Phishing in an academic community A study of user susceptibility and behavior.pdf
- Size:
- 2.73 MB
- Format:
- Adobe Portable Document Format
- Description:
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 2.56 KB
- Format:
- Item-specific license agreed upon to submission
- Description: