User-Centred Security Education: A Game Design to Thwart Phishing Attacks
arXiv:1511.03459
Abstract
Phishing is an online identity theft that aims to steal sensitive information such as username, password and online banking details from its victims. Phishing education needs to be considered as a means to combat this threat. This paper reports on a design and development of a mobile game prototype as an educational tool helping computer users to protect themselves against phishing attacks. The elements of a game design framework for avoiding phishing attacks were used to address the game design issues. Game design principles served as guidelines for structuring and presenting information. Our mobile game design aimed to enhance the users' avoidance behaviour through motivation to protect themselves against phishing threats. A think-aloud study was conducted, along with a pre- and post-test, to assess the game design framework though the developed mobile game prototype. The study results showed a significant improvement of participants' phishing avoidance behaviour in their post-test assessment. Furthermore, the study findings suggest that participants' threat perception, safeguard effectiveness, self-efficacy, perceived severity and perceived susceptibility elements positively impact threat avoidance behaviour, whereas safeguard cost had a negative impact on it.
3 pages, International Conference: Redefining the R&D Needs for Australian Cyber Security on November 16, 2015
Cited by in corpus (6)
- Mobile device users' susceptibility to phishing attacks
- Serious Games for Cyber Security Education
- The risk factors affecting to the software quality failures in Sri Lankan Software industry
- Defending against Phishing Attacks: Taxonomy of Methods, Current Issues and Future Directions
- A Framework to Prevent QR Code Based Phishing Attacks
- The Impact of Project Management in Virtual Environment: A Software Industry Perspective