IADIS International Journal on Computer Science and Information Systems

Published by IADIS (International Association for Development of the Information Society) • ISSN (Online): 1646-3692 • ISSN (Print): 1646-3692
100% Open Access
Double-Blind Peer Review
Crossref DOI Persistent IDs
Open Access Peer-Reviewed Original Research

Evaluating User Vulnerabilities Vs Phisher Skills in Spear Phishing

Mathew Nicho *
Hussein Fakhry *
Uche Egbue *
* 1College of Technological Innovation, Zayed University, Dubai, UAE 2School of Computing and Digital Media, Robert Gordon University, United Kingdom (Portugal)
* 1College of Technological Innovation, Zayed University, Dubai, UAE 2School of Computing and Digital Media, Robert Gordon University, United Kingdom (Portugal)
* 1College of Technological Innovation, Zayed University, Dubai, UAE 2School of Computing and Digital Media, Robert Gordon University, United Kingdom (Portugal)

Abstract

Spear phishing emails pose great danger to employees of organizations due to the inherent weakness of the employees in identifying the threat from spear phishing cues, as well as the spear phisher’s skill in crafting contextually convincing emails. This r aises the main question of which construct (user vulnerabilities or phisher skills ) has a greater influence on the vulnerable user . Researchers have provided enough evidence of user vulnerabilities, namely the desire for monetary gain, curio sity of the computer user, carelessness on the part of the user, the trust placed in the purported sender by the user, and a lack of awareness on the part of the computer user. However, there is a lack of research on the magnitude of each of these factors in influencing an unsuspecting user to fall for a phishing or spear phishing attack which we explored in this paper. While user vulnerabilities pose major risk, the effect of the spear phisher’s ability in skillfully crafting convincing emails (using fear appeals, urgency of action, and email contextualization) to trap even skillful IT security personnel is a n area that need s to be explored. Therefore, we explore d the relationships between the two major constructs namely ‘user vulnerabilities’ and ‘email contextualization’, through the theory of planned behavior with the objective to find out the major factor s that lead to computer users biting the phishers ’ bait. In this theoretical version of the paper, we provided the resulting two constructs that needed to be tested.

Keywords

Spear phishing User Vulnerabilities Email Contextualization
Full-Text PDF Available

Read Complete Peer-Reviewed Manuscript

Includes full econometric models, data tables, policy recommendations, declarations, and citations.

Declarations & Ethics

Funding: This research received academic dissemination support through ESCAP / JournalsHub publishing programs.
Conflicts of Interest: The authors declare no competing financial or institutional interests.
Peer Review: Double-blind peer reviewed by international subject specialists.
License: Creative Commons Attribution 4.0 International (CC BY 4.0).
How to Cite This Article
APA / MLA / BibTeX
Nicho, et al. (2018). Evaluating User Vulnerabilities Vs Phisher Skills in Spear Phishing. IADIS International Journal on Computer Science and Information Systems, 13(2). https://doi.org/10.33965/ijcsis_2018_v13i2_08
Nicho, et al. "Evaluating User Vulnerabilities Vs Phisher Skills in Spear Phishing." IADIS International Journal on Computer Science and Information Systems, vol. 13, no. 2, 2018. https://doi.org/10.33965/ijcsis_2018_v13i2_08
Nicho, et al. "Evaluating User Vulnerabilities Vs Phisher Skills in Spear Phishing." IADIS International Journal on Computer Science and Information Systems 13, no. 2 (2018). https://doi.org/10.33965/ijcsis_2018_v13i2_08