首页> 外文学位 >Why don't people report phishing emails? Finding the reasons, improving motivations, and securing cyberspace
【24h】

Why don't people report phishing emails? Finding the reasons, improving motivations, and securing cyberspace

机译:人们为什么不举报网络钓鱼电子邮件?寻找原因,改善动力并确保网络空间安全

获取原文
获取原文并翻译 | 示例

摘要

Antiphishing training efforts are effective to the extent to which individuals are able to correctly identify phishing emails. Even for individuals with advanced knowledge in cyber security, however, it is hardly possible that individuals detect all types of phishing emails. Failure of detecting phishing emails can result in falling for phishing attacks. In this daunting situation, a plain reporting phishing emails can bring about a breakthrough into antiphishing efforts. However, the reporting rate of phishing emails is so far very low, and has been little studied in the social sciences. The current study aims to uncover motivational processes of engaging in reporting phishing emails using the Social Cognitive Theory with two antecedents---awareness of reporting phishing emails and cyber risk beliefs. Three models are examined, which are the social cognitive model of intent to report phishing emails as a baseline model, the baseline model with awareness of reporting phishing emails, and the baseline model with cyber risk beliefs, are tested individually using structural equation analysis of data from 386 college students at a large northeastern university in the United States. Interestingly enough, the concerted efforts of examining the three models reveal that intent to report phishing emails is driven by a proactive approach to cyber security which involves causal relationships among perceived antiphishing self-efficacy, concern for mishandling of reports, and self-reaction of meticulous attention to cyber security behaviors, which also indicate a doubtful mode of cognition and action. The similar results are found in the tests for the second and third model. In addition, the second model uncovers that awareness of reporting phishing emails has the strongest direct effect on intent to report phishing emails; the third model reemphasizes that intent to report phishing emails is driven by a doubtful mode of cognition and action. An unexpected finding reveals that a motivational process of intent not to report phishing emails is driven by a causal path among perceived antiphishing self-efficacy, positive intangible outcomes, and compliance with cyber security behavioral tips, which is called an avoidance/passive approach to cyber security. Implications for future research on the behavior of reporting phishing emails are discussed.
机译:网络钓鱼培训工作在个人能够正确识别网络钓鱼电子邮件的范围内是有效的。但是,即使对于具有高度网络安全知识的个人,也几乎不可能检测到所有类型的网络钓鱼电子邮件。未检测到网络钓鱼电子邮件可能会导致网络钓鱼攻击下降。在这种艰巨的情况下,简单地报告网络钓鱼电子邮件可以带来反钓鱼努力方面的突破。但是,迄今为止,网络钓鱼电子邮件的报告率非常低,并且在社会科学领域还很少进行研究。当前的研究旨在发现使用社交认知理论和两个先决条件参与报告网络钓鱼电子邮件的动机过程-报告网络钓鱼电子邮件的意识和网络风险信念。使用模型的数据结构分析分别测试了三种模型,分别是意图将网络钓鱼电子邮件报告为基线模型的社会认知模型,具有报告网络钓鱼电子邮件意识的基线模型以及具有网络风险信念的基线模型。来自美国一所大型东北大学的386名大学生。有趣的是,检查这三种模型的共同努力表明,报告网络钓鱼电子邮件的意图是由积极主动的网络安全方法驱动的,该方法涉及感知到的网络钓鱼自我效能,对报告处理不当的关注以及细致的自我反应之间的因果关系。注意网络安全行为,这也表明人们对认知和行为的怀疑方式。在第二个和第三个模型的测试中发现了相似的结果。另外,第二种模型发现,报告网络钓鱼电子邮件的意识对报告网络钓鱼电子邮件的意图具有最强的直接影响。第三个模型再次强调,报告网络钓鱼电子邮件的意图是由可疑的认知和行为模式驱动的。一项意外发现表明,不举报网络钓鱼电子邮件的动机性过程是由感知到的网络钓鱼自我效能,积极的无形结果以及对网络安全行为提示的遵从性之间的因果关系驱动的,这被称为对网络的回避/被动方法安全。讨论了对网络钓鱼电子邮件举报行为的未来研究的意义。

著录项

  • 作者

    Kwak, Youngsun.;

  • 作者单位

    State University of New York at Buffalo.;

  • 授予单位 State University of New York at Buffalo.;
  • 学科 Communication.;Web studies.
  • 学位 Ph.D.
  • 年度 2017
  • 页码 123 p.
  • 总页数 123
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号