The dark side of social networking sites:Understanding phishing risks

被引:34
作者
Silic, Mario [1 ,2 ]
Back, Andrea [1 ]
机构
[1] Univ St Gallen, Inst Informat Management, CH-9000 St Gallen, Switzerland
[2] Zagreb Sch Econ & Management, Zagreb, Croatia
关键词
Social networking sites; Field experiment; Deception; Employee psychology; SECURITY; INSIDER; DECEPTION; FACEBOOK; THREATS;
D O I
10.1016/j.chb.2016.02.050
中图分类号
B84 [心理学];
学科分类号
04 ; 0402 ;
摘要
LinkedIn, with over 1.5 million Groups, has become a popular place for business employees to create private groups to exchange information and communicate. Recent research on social networking sites (SNSs) has widely explored the phenomenon and its positive effects on firms. However, social net working's negative effects on information security were not adequately addressed. Supported by the credibility, persuasion and motivation theories, we conducted 1) a field experiment, demonstrating how sensitive organizational data can be exploited, followed by 2) a qualitative study of employees engaged in SNSs activities; and 3) interviews with Chief Information Security Officers (CIS0s). Our research has resulted in four main findings: 1) employees are easily deceived and susceptible to victimization on SNSs where contextual elements provide psychological triggers to attackers; 2) organizations lack mechanisms to control SNS online security threats, 3) companies need to strengthen their information security policies related to SNSs, where stronger employee identification and authentication is needed, and 4) SNSs have become important security holes where, with the use of social engineering techniques, malicious attacks are easily facilitated. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:35 / 43
页数:9
相关论文
共 78 条
[1]  
Abbasi A, 2010, MIS QUART, V34, P435
[2]  
Al Zamal Faiyaz, 2012, ICWSM, V270
[3]  
ALGARNI A, 2015, 36 INT C INF SYST IC
[4]  
Algarni A., 2014, P 18 PAC AS C INF SY
[5]  
ALOWIBDI JS, 2014, ADV SOC NETW AN MIN
[6]  
[Anonymous], 2007, AMCIS 2007 P
[7]  
[Anonymous], 2010, Human factors and information security: Individual, culture, and security environment
[8]  
[Anonymous], 2012, International Journal of Information and Network Security, DOI DOI 10.11591/IJINS.V1I2.426
[9]  
[Anonymous], 2006, P SIGCHI C HUM FACT
[10]  
[Anonymous], 2002, OKEEFE08IEC ELM