arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

谁会陷入SMiSh骗局?通过调查数据学习针对移动消息攻击开展意识培训的最佳目标

Who Falls for SMiSh? Learning Through Survey Data Where to Best Target Awareness Training for Mobile Messaging Attacks

Cori Faklaris, Sarah Tabassum, Heather Richter Lipford

arXiv 2608.24669首次发表:更新:

AI 中文总结

该研究通过两项针对美国成年手机用户的大规模调查,发现年轻人和大学生易受SMiShing攻击,建议研究人员、监管机构及电信公司为相关群体开展针对性意识培训。

AI 中文摘要

随着手机普及率的激增,涉及这些设备的诈骗也随之增多。其中一种被称为SMiShing(或smishing,即短信钓鱼)的诈骗,名称来源于短消息服务(SMS),涉及诈骗者通过手机短信发送钓鱼链接。尽管SMiShing十分普遍,但目前缺乏关于谁最易受此类攻击影响的数据。针对其邮件对应形式——钓鱼(phishing)的现有研究表明,易感性可能因人口统计学和背景因素而异。在两项大规模调查中,我们采用一种先前发表的模拟方法,从具有代表性的美国成年手机用户样本中收集数据。我们的研究结果显示,年轻人和大学生特别容易受攻击。参与者难以正确识别合法消息,第二项研究提供了金融消息变体的对比数据。研究人员、监管机构和电信公司可通过为24岁以下人群和高校客户创建针对移动设备的干预措施,并添加验证与警告来帮助用户。

英文摘要

As mobile phone adoption has surged, so have scams involving these devices. One such scam, known as SMiShing (or smishing) after Short Message Service (SMS), involves fraudsters sending phishing links via mobile texts. Despite the prevalence of SMiShing, there is a lack of data on who is most vulnerable to these attacks. Prior research on phishing (its email counterpart) suggests that susceptibility may vary by demographic and contextual factors. In two large-scale surveys, we use a previously published simulation method to collect data from representative samples of U.S. adult mobile phone users. Our findings indicate that younger individuals and college students are particularly vulnerable. Participants struggled to correctly identify legitimate messages, with the second study providing comparisons of financial message variants. Researchers, regulators, and telecoms can help users by creating mobile-specific interventions for under-24 and university customers and adding verifications and warnings.

CommentsRevised for SOUPS 2025

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑