The Phishing Email Suspicion Test (PEST) a lab-based task for evaluating the cognitive mechanisms of phishing detection

21Citations
Citations of this article
107Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Phishing emails constitute a major problem, linked to fraud and exploitation as well as subsequent negative health outcomes including depression and suicide. Because of their sheer volume, and because phishing emails are designed to deceive, purely technological solutions can only go so far, leaving human judgment as the last line of defense. However, because it is difficult to phish people in the lab, little is known about the cognitive and neural mechanisms underlying phishing susceptibility. There is therefore a critical need to develop an ecologically valid lab-based measure of phishing susceptibility that will allow evaluation of the cognitive mechanisms involved in phishing detection. Here we present such a measure based on a task, the Phishing Email Suspicion Test (PEST), and a cognitive model to quantify behavior. In PEST, participants rate a series of phishing and non-phishing emails according to their level of suspicion. By comparing suspicion scores for each email to its real-world efficacy, we find initial support for the ecological validity of PEST – phishing emails that were more effective in the real world were more effective at deceiving people in the lab. In the proposed computational model, we quantify behavior in terms of participants’ overall level of suspicion of emails, their ability to distinguish phishing from non-phishing emails, and the extent to which emails from the recent past bias their current decision. Together, our task and model provide a framework for studying the cognitive neuroscience of phishing detection.

References Powered by Scopus

The Psychophysics Toolbox

15195Citations
N/AReaders
Get full text

Why phishing works

946Citations
N/AReaders
Get full text

Decision by sampling

539Citations
N/AReaders
Get full text

Cited by Powered by Scopus

The Role of User Behaviour in Improving Cyber Security Management

47Citations
N/AReaders
Get full text

The Importance of Conceptualising the Human-Centric Approach in Maintaining and Promoting Cybersecurity-Hygiene in Healthcare 4.0

25Citations
N/AReaders
Get full text

Improving malicious email detection through novel designated deep-learning architectures utilizing entire email

24Citations
N/AReaders
Get full text

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Cite

CITATION STYLE

APA

Hakim, Z. M., Ebner, N. C., Oliveira, D. S., Getz, S. J., Levin, B. E., Lin, T., … Wilson, R. C. (2021). The Phishing Email Suspicion Test (PEST) a lab-based task for evaluating the cognitive mechanisms of phishing detection. Behavior Research Methods, 53(3), 1342–1352. https://doi.org/10.3758/s13428-020-01495-0

Readers' Seniority

Tooltip

PhD / Post grad / Masters / Doc 25

74%

Researcher 6

18%

Professor / Associate Prof. 2

6%

Lecturer / Post doc 1

3%

Readers' Discipline

Tooltip

Computer Science 23

61%

Psychology 9

24%

Engineering 4

11%

Neuroscience 2

5%

Save time finding and organizing research with Mendeley

Sign up for free