Published Online:September 2012
Product Name:The IUP Journal of Information Technology
Product Type:Article
Product Code:
Author Name:Swapan Purkait
Availability:YES
Subject/Domain:Engineering
Download Format:PDF
Pages:32
Exploring the Factors That Influence an Internet User’s Ability to Correctly Identify Phishing Websites Swapan Purkait* The Internet has become a very important medium of communication. Internet access is no longer limited to technical people only. All ages are now connected online, and they use Internet for conducting a wide range of business. Because of the growth of the Internet and so many users connected, collecting personal information through a phishing website is also easy for a fraudster. They use websites that look similar to those of legitimate organizations and exploit the end-user’s lack of knowledge of web browser clues and security indicators. This research study was conducted to empirically investigate the factors that influence Internet user’s ability to correctly identify phishing websites. Quantitative data was collected by simulating a phishing attack where participants were required to complete a task by signing into one of their e-mail accounts online. The impact of age, gender, education, awareness of phishing and previous encounter with phishing had on their ability to correctly identify the phishing website was measured. We found that many Internet users do not understand phishing attacks or realize how sophisticated such attacks can be. However, we found users who were victims of phishing in past did well to identify the phishing website. Keywords: Phishing, Anti-phishing, Cyber crime, Internet security, User awareness
The word phishing has been derived from ‘fishing’.The idea of phishing is similar to that of fishing, where a bait is thrown to an unsuspected user, in order to lure him to visit a fictitious website, where the site captures the personal and confidential data of the user (James, 2006).In most cases, the bait is either an e-mail or an instant messaging site, which will take the user to hostile phishing websites, mostly to an exact replica of a financial institution’s website (Knight, 2005).The fake website will have similar look and feel of the original one and will be asking for the sensitive information like user name, password, credit card details, etc.