Date of Award
Phishing attacks are challenging to detect and can have severe consequences. For example, in 2020 alone, phishing attacks cost organizations more than $1.8 billion. Numerous phishing training programs such as reading materials, training videos, and games aim to mitigate the incurred losses. However, regardless of the medium, nearly all existing training places the learner in the role of the victim.
We hypothesize placing the players as an attacker tasked with strategically creating emails will naturally lead to players better recognizing phishing emails. Based on this hypothesis, we have developed an interactive game that trains the users against phishing attacks as an attacker. Our players actively craft simulated emails that employ various phishing techniques rather than passively receiving emails and being asked to classify them. We conducted user testing with 11 participants, and our results showed that participants recognized and understood phishing emails better after playing the game.
Duwal, Saroj, ""The Best Defense is a Good Offense:" Teaching Phishing Defense Tactics Through a High Agency Playable Experience" (2022). University of New Orleans Theses and Dissertations. 2994.
Available for download on Saturday, May 27, 2023