Roles of Feedback and Phishing Characteristics in Antiphishing Training Performance: Perspectives of Goal Setting and Skill Acquisition

被引:0
作者
Pan, Shihe [1 ]
Kwak, Dong-Heon [2 ]
Kuem, Jungwon [3 ]
Kim, Sung S. [4 ]
机构
[1] Tianjin Univ, Tianjin, Peoples R China
[2] Kent State Univ, Kent, OH USA
[3] SUNY Albany, Albany, NY USA
[4] Univ Wisconsin Madison, Madison, WI USA
来源
JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS | 2024年 / 25卷 / 04期
关键词
Phishing; Antiphishing Training; Feedback; Phishing Cue Saliency; Perceived Detection Efficacy; Goal Setting; Skill Acquisition; Decision Avoidance; Detection Accuracy; Experiments; Hierarchical Linear Modeling; INFORMATION-SYSTEMS; MANIPULATION CHECKS; TASK COMPLEXITY; POWER; SECURITY; MOTIVATION; DECISIONS; DESIGN; IMPACT; DESIRABILITY;
D O I
10.17705/1jais.00854
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Because phishing attacks often exploit individuals' inexperience in detecting them, it is important for managers to provide workers with proper feedback on their reactions to phishing scams. However, little is known about what types of feedback are more effective in facilitating antiphishing training behavior and performance. The objectives of this study are to identify (1) the determinants of decision avoidance and detection accuracy, (2) the contextual effect of type of feedback in antiphishing training, (3) the impacts of perceived detection efficacy on training outcomes, and (4) the interaction effects between feedback characteristics and perceived detection efficacy/phishing characteristics on training outcomes. Drawing upon goal-setting theory, skill acquisition theory, and antiphishing training literature, our model provides a theoretical account of how feedback characteristics (e.g., type, quantity), phishing characteristics (e.g., phishing cue saliency), and perceived detection efficacy affect antiphishing training outcomes (e.g., decision avoidance and detection accuracy). To empirically test the model, we performed four experiments with 652 subjects in the United States from three different online panels via Amazon Mechanical Turk, Esearch.com, and Clickworker.com. Our results indicate that examplebased feedback is superior to abstract feedback in teaching how to correctly discern between phishing and legitimate emails in the context of link-embedded emails. We also show that perceived detection efficacy is essential for a better understanding of antiphishing training behavior and performance. Finally, we show an interaction effect between feedback quantity and phishing cue saliency on antiphishing training behavior and performance.
引用
收藏
页数:43
相关论文
共 121 条