Cyberfraud Flashcards

1
Q

Fraud

A

-Intentional deception
-phishing- gain secret info/install malware- via email or face to face approach or long distance

Social engineering- manipulate people, make them perform some action- can be face to face or long distance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Social phishing

A

Context aware phishing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Experiments

A

Are special type of user studies

Goal: test hypothesis

Hypothesis: well-founded assumption about cause relation between iv and dv

How can causality be determined: random assignment to control group and experimental group

Control group: normal value of iv

Experimental group:experimental value of iv

Hypothesis: difference in dv between 2 groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Reasons for clicking

A

Personalization
Curiosity
Risk underestimation
Lack of expert knowledge
Automatic reaction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Reasons for not clicking

A

Unknown sender
Fraud suspicion
Situation context
Life context
Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

False negative vs false positive

A

False negatives- dangerous message not detected

False positive-benign messages classified as dangerous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Why is phishing awareness difficult to maintain

A

-security aware behavior difficult to maintain
-many legitimate emails look phishy
-life and work practices clash with security behavior
Social norms clash with security behavior

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Feasibility of anti phishing training

A
  • no evidence it works in the real world
    -some no effect at all
    -training effect decline after 1-2 month
    -cost of phishing attack per user a year-33cents
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

6 principles of influence

A
  1. Reciprocity- we protect your account, please helps us by clicking here
  2. Commitment and consistency- thank you for using our service, click here for benefits for loyal customers
  3. Social proof-x% of our customers say this product is good
  4. Authority- we are a well known company
  5. Liking - this is what customers say about out service
  6. scarcity- if u dont click here now we will have to close your account
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why do nigerian scammers say they are from nigeria

A

Someone who believes this can be made to believe anything.
Someone who does not fall is not worth the effort, because at some point they will most likely notice is a scam

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Demographics of scam victims

A

No difference in gender
Almost no difference in age
Higher educational levels
Life changing events such as deaths, illnesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Why is defense against social engineering difficult?

A

Human nature- we tend to trust each other

Trust bias vs deception bias

Really determined social engineer will get anyone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly