Roles of Feedback and Phishing Characteristics in Antiphishing Training Performance: Perspectives of Goal Setting and Skill Acquisition

被引:0
作者
Pan, Shihe [1 ]
Kwak, Dong-Heon [2 ]
Kuem, Jungwon [3 ]
Kim, Sung S. [4 ]
机构
[1] Tianjin University, China
[2] Kent State University, United States
[3] State University of New York at Albany, United States
[4] University of Wisconsin-Madison, United States
关键词
Antiphishing Training; Decision Avoidance; Detection Accuracy; Experiments; Feedback; Goal Setting; Hierarchical Linear Modeling; Perceived Detection Efficacy; Phishing; Phishing Cue Saliency; Skill Acquisition;
D O I
10.17705/1JAIS.00854
中图分类号
学科分类号
摘要
Because phishing attacks often exploit individuals’ inexperience in detecting them, it is important for managers to provide workers with proper feedback on their reactions to phishing scams. However, little is known about what types of feedback are more effective in facilitating antiphishing training behavior and performance. The objectives of this study are to identify (1) the determinants of decision avoidance and detection accuracy, (2) the contextual effect of type of feedback in antiphishing training, (3) the impacts of perceived detection efficacy on training outcomes, and (4) the interaction effects between feedback characteristics and perceived detection efficacy/phishing characteristics on training outcomes. Drawing upon goal-setting theory, skill acquisition theory, and antiphishing training literature, our model provides a theoretical account of how feedback characteristics (e.g., type, quantity), phishing characteristics (e.g., phishing cue saliency), and perceived detection efficacy affect antiphishing training outcomes (e.g., decision avoidance and detection accuracy). To empirically test the model, we performed four experiments with 652 subjects in the United States from three different online panels via Amazon Mechanical Turk, Esearch.com, and Clickworker.com. Our results indicate that example-based feedback is superior to abstract feedback in teaching how to correctly discern between phishing and legitimate emails in the context of link-embedded emails. We also show that perceived detection efficacy is essential for a better understanding of antiphishing training behavior and performance. Finally, we show an interaction effect between feedback quantity and phishing cue saliency on antiphishing training behavior and performance. © 2024 by the Association for Information Systems.
引用
收藏
页码:1037 / 1078
页数:41
相关论文
共 122 条
[1]  
Abbasi A., Dobolyi D., Vance A., Zahedi F. M., The phishing funnel model: A design artifact to predict user susceptibility to phishing websites, Information Systems Research, 32, 2, pp. 410-436, (2021)
[2]  
Al-Daeef M. M., Basir N., Saudi M. M., Security awareness training: A review, Proceedings of the World Congress on Engineering, (2017)
[3]  
Anderson C. J., The psychology of doing nothing: Forms of decision avoidance result from reason and emotion, Psychological Bulletin, 129, 1, pp. 139-167, (2003)
[4]  
Anderson J. R., Language, memory, and thought, (1976)
[5]  
Anderson J. R., Acquisition of cognitive skill, Psychological Review, 89, 4, pp. 369-406, (1982)
[6]  
Anderson J. R., Skill acquisition: Compilation of weak-method problem situations, Psychological Review, 94, 2, pp. 192-210, (1987)
[7]  
Anderson J. R., Cognitive psychology and its implications, (2010)
[8]  
Arachchilage N. A. G., Love S., Beznosov K., Phishing threat avoidance behaviour: An empirical investigation, Computers in Human Behavior, 60, pp. 185-197, (2016)
[9]  
Bagozzi R. P., Yi Y., On the evaluation of structural equation models, Journal of the Academy of Marketing Science, 16, 1, pp. 74-94, (1988)
[10]  
Bagozzi R. P., Bergami M., Leone L., Hierarchical representation of motives in goal setting, Journal of Applied Psychology, 88, 5, pp. 915-943, (2003)