Using stage theorizing to make anti-phishing recommendations more effective
Tambe Ebot, A. C. (2018). Using stage theorizing to make anti-phishing recommendations more effective. Information and Computer Security, 26(4), 401-419. https://doi.org/10.1108/ics-06-2017-0040
Julkaistu sarjassa
Information and Computer SecurityTekijät
Päivämäärä
2018Tekijänoikeudet
© Emerald Publishing Limited 2018
Purpose
This paper aims to review the behavioral phishing literature to understand why anti-phishing recommendations are not very effective and to propose ways of making the recommendations more effective. The paper also examines how the concept of stages from health communication and psychology can be used to make recommendations against phishing more effective.
Design/methodology/approach
This literature review study focused on the behavioral phishing literature that has relied on human subjects. Studies were excluded for reasons that included lacking practical recommendations and human subjects.
Findings
The study finds that phishing research does not consider where victims are residing in qualitatively different stages. Consequently, the recommendations do not often match the specific needs of different victims. This study proposes a prototype for developing stage theories of phishing victims and identifies three stages of phishing victims from analyzing the previous phishing research.
Research limitations/implications
This study relied on published research on phishing victims. Future research can overcome this problem by interviewing phishing victims. Further, the authors’ recommendation that phishing researchers categorize phishing victims into stages and develop targeted messages is not based on direct empirical evidence. Nonetheless, evidence from cancer research and health psychology suggests that targeted messaging is efficacious and cost-effective. Thus, the impact of targeted messaging in phishing could be quite large.
Practical implications
The study recommends categorizing individuals into stages, based on their security knowledge and online behaviors, and other similar characteristics they may possess. A stage approach will consider that individuals who at one time clicked on a phishing link because they lacked the requisite security knowledge, after receiving security training, may click on a link because they are overconfident.
Originality/value
The paper explains why proposing anti-phishing recommendations, based on a “one-size fits all” approach has not been very effective (e.g. because it simplifies why people engage in different behaviors). The proposals introduce a new approach to designing and deploying anti-phishing recommendations based on the concept of stages.
...
Julkaisija
Emerald Publishing LimitedISSN Hae Julkaisufoorumista
2056-4961Julkaisu tutkimustietojärjestelmässä
https://converis.jyu.fi/converis/portal/detail/Publication/28276455
Metadata
Näytä kaikki kuvailutiedotKokoelmat
Lisenssi
Samankaltainen aineisto
Näytetään aineistoja, joilla on samankaltainen nimeke tai asiasanat.
-
Explaining two forms of Internet crime from two perspectives : toward stage theories for phishing and Internet scamming
Tambe Ebot, Alain Claude (University of Jyväskylä, 2017)The two studies in this dissertation examine two pervasive and common forms of Internet crimes from two different perspectives: (1) phishing from the victims’ perspective and (2) Internet scamming from the offenders’ ... -
Toward a stage theory of adaptive social media use : explaining change in facebook use
Koskelainen, Tiina (Jyväskylän yliopisto, 2018) -
The success of communication in the Adventures of Joe Fin campaign : self-evaluated effects on health behaviour
Mäkilä, Martta (2010)Yli puolet suomalaisista liikkuu terveytensä kannalta riittämättömästi. Keski-ikäiset miehet ovat yksi vähiten liikkuvista väestöryhmistä. Kunnossa kaiken ikää -ohjelman SuomiMies seikkailee -kampanja alkoi vuonna 2007, ... -
Theorizing expectations as enablers of intangible assets in public relations : normative, predictive, and destructive
Olkkonen, Laura; Luoma-aho, Vilma (Sage Publications Ltd., 2019)Expectations intersect with many areas of public relations, yet conceptual and theoretical understandings of expectations have not been strong in public relations research. In fact, expectations are often discussed at a ... -
Theories of Context, Theorizing Context
Kovala, Urpo (Walter de Gruyter GmbH, 2014)Theories of meaning, even outspokenly textualist ones, have always dealt with the question of relevant context as well, to some extent at least. In many fields of research, the idea of an encompassing theory of context has ...
Ellei toisin mainittu, julkisesti saatavilla olevia JYX-metatietoja (poislukien tiivistelmät) saa vapaasti uudelleenkäyttää CC0-lisenssillä.