KIT | KIT-Bibliothek | Impressum | Datenschutz

Influence of URL Formatting on Users' Phishing URL Detection

Mossano, Mattia 1; Kulyk, Oksana; Berens, Benjamin Maximillian ORCID iD icon 1; Häußler, Elena Marie 2; Volkamer, Melanie 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)
2 Karlsruher Institut für Technologie (KIT)

Abstract:

Despite technical advances in anti-phishing protection, in many cases the detection of phishing URLs largely depends on users manually inspecting the links found in suspicious emails. One solution proposed to support users in doing so is to use a URL formatting that focuses their attention on critical URL parts, such as domain and top-level-domain (called “who-area”). While this solution has been implemented in several software products (e.g., browsers web address bar), research on its effectiveness with regard to phishing URL detection is currently limited. To investigate the extent to which different kinds of URL formatting support users to detect phishing URLs, we conducted an online study (n = 200) using interactive email screenshots with tooltips showing two previously evaluated URL formatting (called “Who-Area Highlighting” and “Who-Area Only”). A group with unmodified URLs (called “Plain URL”) acted as control. We did not find any significant difference between the URL formatting within our sample, with successful phishing URL detection rates ranging from 71% (for the unmodified URL) to 76% (for showing only the URL who-area). ... mehr


Preprint §
DOI: 10.5445/IR/1000163039
Veröffentlicht am 16.10.2023
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 16.10.2023
Sprache Englisch
Identifikator ISBN: 979-84-00-70814-5
KITopen-ID: 1000163039
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Proceedings of the 2023 European Symposium on Usable Security
Veranstaltung European Workshop on Usable Security (EuroUSEC 2023), Kopenhagen, Dänemark, 16.10.2023 – 17.10.2023
Verlag Association for Computing Machinery (ACM)
Seiten 318–333
Nachgewiesen in Dimensions
Scopus
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page