VeriSMS: A Message Verification System for Inclusive Patient Outreach against Phishing Attacks

要旨

Patient outreach enables timely communication between patients and healthcare providers but is vulnerable to phishing/spoofing attacks. In this paper, we work with a U.S.-based healthcare provider to design an inclusive method to address this threat. We present VeriSMS which allows patients to call a voice agent to verify whether the received (sensitive) messages are indeed sent by their healthcare provider. We design the system to be inclusive: it is accessible to patients who only have access to SMS and phone call capabilities. We perform a two-part user study to refine the system design (N=15) and confirm users can correctly understand the system and use it to identify spoofed/phishing messages (N=35). A key insight from our study is to not exclusively optimize for strong security but to tailor the designs based on user habits. Our result confirms the effectiveness and usability of VeriSMS and its ability to significantly increase adversaries' costs.

著者
Chenkai Wang
University of Illinois at Urbana-Champaign, Urbana, Illinois, United States
Zhuofan Jia
University of Illinois at Urbana-Champaign, Urbana, Illinois, United States
Hadjer Benkraouda
University of Illinois at Urbana-Champaign, Urbana, Illinois, United States
Cody Zevnik
OSF Healthcare, Peoria, Illinois, United States
Nicholas Heuermann
OSF Healthcare, Peoria, Illinois, United States
Roopa Foulger
OSF Healthcare, Peoria, Illinois, United States
Jonathan A.. Handler
OSF Healthcare, Peoria, Illinois, United States
Gang Wang
University of Illinois at Urbana-Champaign, Urbana, Illinois, United States
論文URL

https://doi.org/10.1145/3613904.3642027

動画

会議: CHI 2024

The ACM CHI Conference on Human Factors in Computing Systems (https://chi2024.acm.org/)

セッション: Security Systems

317
5 件の発表
2024-05-15 18:00:00
2024-05-15 19:20:00