| | This Article | |
| |
| |
| | Share | |
| |
| |
| | Bibliographic References | |
| |
| |
| | Add to: | |
| |
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
| |
| | Search | |
| |
| |
| | |
Why and How to Perform Fraud Experiments
March/April 2008 (vol. 6 no. 2)
pp. 66-68
The authors argue that user studies are vital in order to improve our understanding of online fraud and other sociotechnical security problems. They then provide an overview of common approaches and describe how to carry out the approach that they believe results in the most accurate measurements, the so-called naturalistic phishing experiment. They give examples of such experiments, and illustrate ethical and technical issues that may arise for such experiments.
1. 66 M. Jakobsson and J. Ratkiewicz, "Designing Ethical Phishing Experiments: A Study of (ROT13) rOnl Auction Query Features," Proc. 15th Int'l Conf. World Wide Web, ACM Press, 2006, pp. 513–522.2. R. Dhamija and J.D. Tygar, "The Battle against Phishing: Dynamic Security Skins," Proc. 2005 Symp. Usable Privacy and Security, ACM Press, 2006, pp. 77–83.3. M. Jakobsson et al., "What Instills Trust? A Qualitative Study of Phishing," Proc. 1st Int'l Workshop on Usable Security, Springer-Verlag, 2007; www.informatics.indiana.edu/markus/papers trust_USEC.pdf.4. S. Srikwan and M. Jakobsson, "Using Cartoons to Teach Internet Security," Cryptologia, vol. 32, no. 2, 2008; . 5. V. Anandpara et al., "Phishing IQ Tests Measure Fear, not Ability," Proc. 1st Int'l Workshop on Usable Security, Springer-Verlag, 2007; www.informatics.indiana.edu/markus/papers phish6.pdf.6. P. Finn and M. Jakobsson, "Designing and Conducting Phishing Experiments," IEEE Technology and Society, special issue on usability and security, vol. 26, no. 1, 2007, pp. 46–58.7. T. Jagatic et al., "Social Phishing," Comm. ACM, vol. 5, no. 10, 2007, pp. 94–100; http://portal.acm.orgcitation.cfm?doid=1290958.1290968 .
Index Terms:
deceit, debriefing, ethics, experiment, fraud, naturalistic, phishing, subject-expectancy bias
Citation:
Markus Jakobsson, Nathaniel Johnson, Peter Finn, "Why and How to Perform Fraud Experiments," IEEE Security and Privacy, vol. 6, no. 2, pp. 66-68, Mar./Apr. 2008, doi:10.1109/MSP.2008.52