I don't need an expert! Making URL phishing features human comprehensible

要旨

Judging the safety of a URL is something that even security experts struggle to do accurately without additional information. In this work, we aim to make experts' tools accessible to non-experts and assist general users in judging the safety of URLs by providing them with a usable report based on the information professionals use. We designed the report by iterating with 8 focus groups made up of end users, HCI experts, and security experts to ensure that the report was usable as well as accurately interpreted the information. We also conducted an online evaluation with 153 participants to compare different report-length options. We find that the longer comprehensive report allows users to accurately judge URL safety (93% accurate) and that summaries still provide benefit (83% accurate) compared to domain highlighting (65% accurate).

著者
Kholoud Althobaiti
The University of Edinburgh, Edinburgh, United Kingdom
Nicole Meng
University of Edinburgh, Edinburgh, United Kingdom
Kami Vaniea
University of Edinburgh, Edinburgh, United Kingdom
DOI

10.1145/3411764.3445574

論文URL

https://doi.org/10.1145/3411764.3445574

動画

会議: CHI 2021

The ACM CHI Conference on Human Factors in Computing Systems (https://chi2021.acm.org/)

セッション: Developers / Authentication / Privacy Risks from Children to Adults

[A] Paper Room 12, 2021-05-12 17:00:00~2021-05-12 19:00:00 / [B] Paper Room 12, 2021-05-13 01:00:00~2021-05-13 03:00:00 / [C] Paper Room 12, 2021-05-13 09:00:00~2021-05-13 11:00:00
Paper Room 12
11 件の発表
2021-05-12 17:00:00
2021-05-12 19:00:00
日本語まとめ
読み込み中…