Cyberfraud Flashcards
Fraud
-Intentional deception
-phishing- gain secret info/install malware- via email or face to face approach or long distance
Social engineering- manipulate people, make them perform some action- can be face to face or long distance
Social phishing
Context aware phishing
Experiments
Are special type of user studies
Goal: test hypothesis
Hypothesis: well-founded assumption about cause relation between iv and dv
How can causality be determined: random assignment to control group and experimental group
Control group: normal value of iv
Experimental group:experimental value of iv
Hypothesis: difference in dv between 2 groups
Reasons for clicking
Personalization
Curiosity
Risk underestimation
Lack of expert knowledge
Automatic reaction
Reasons for not clicking
Unknown sender
Fraud suspicion
Situation context
Life context
Privacy
False negative vs false positive
False negatives- dangerous message not detected
False positive-benign messages classified as dangerous
Why is phishing awareness difficult to maintain
-security aware behavior difficult to maintain
-many legitimate emails look phishy
-life and work practices clash with security behavior
Social norms clash with security behavior
Feasibility of anti phishing training
- no evidence it works in the real world
-some no effect at all
-training effect decline after 1-2 month
-cost of phishing attack per user a year-33cents
6 principles of influence
- Reciprocity- we protect your account, please helps us by clicking here
- Commitment and consistency- thank you for using our service, click here for benefits for loyal customers
- Social proof-x% of our customers say this product is good
- Authority- we are a well known company
- Liking - this is what customers say about out service
- scarcity- if u dont click here now we will have to close your account
Why do nigerian scammers say they are from nigeria
Someone who believes this can be made to believe anything.
Someone who does not fall is not worth the effort, because at some point they will most likely notice is a scam
Demographics of scam victims
No difference in gender
Almost no difference in age
Higher educational levels
Life changing events such as deaths, illnesses
Why is defense against social engineering difficult?
Human nature- we tend to trust each other
Trust bias vs deception bias
Really determined social engineer will get anyone