KIT | KIT-Bibliothek | Impressum | Datenschutz

Vision: What the hack is going on? A first look at how website owners became aware that their website was hacked

Hennig, Anne ORCID iD icon 1; Thi Thanh Vuong, Nhu; Mayer, Peter ORCID iD icon 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)

Abstract (englisch):

Websites are an essential part of today's business activities. Content Management Systems (CMS) are known for the fact that even laypersons can create good-looking websites with simple means and without huge costs. But if websites are not maintained regularly, they are prone to vulnerabilities. Such vulnerabilities can be abused, e.g., for third party redirects. Informing website owner about this type of attack is challenging. To gain more information about how website owners are informed about vulnerabilities on their websites, we invited 156 website owners to participate in an online survey. We asked those who had fixed the third party redirect before we could inform them, how they became aware of the attack. The participants could choose to answer the questionnaire via a link to an online platform, or to send their answers back to us via e-mail. Only 11 people answered our questionnaire, and only four people were already aware of the attack before our invitation e-mail. Based on these four answers, we assumed that we can confirm previous research with respect to the design of a vulnerability notification. Nevertheless, it would be interesting to see if -- with a bigger sample -- we can also confirm our findings that a) online surveys, even if they can only be accessed by clicking an unknown link, are preferred over responding via e-mail, b) the number of responses can be increased by sending out several reminder, and c) a sender attributed with higher authority increases the response rate. ... mehr


Verlagsausgabe §
DOI: 10.5445/IR/1000160718
Veröffentlicht am 26.10.2023
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsmonat/-jahr 10.2023
Sprache Englisch
Identifikator ISBN: 979-8-4007-0814-5
KITopen-ID: 1000160718
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in EuroUSEC '23: Proceedings of the 2023 European Symposium on Usable Security
Veranstaltung European Workshop on Usable Security (EuroUSEC 2023), Kopenhagen, Dänemark, 16.10.2023 – 17.10.2023
Verlag Association for Computing Machinery (ACM)
Seiten 312-317
Nachgewiesen in Scopus
Dimensions
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page