The Phishing Funnel Model: A Design Artifact to Predict User Susceptibility to Phishing Websites
Published Online:15 Feb 2021https://doi.org/10.1287/isre.2020.0973
References
- (2015) Predicting behavior. IEEE Intelligence Systems 30(3):35–43.Crossref, Google Scholar
- (2012a) Impact of anti-phishing tool performance on attack success rates. Proc. IEEE Internat. Conf. on Intelligence and Security Informatics (IEEE, Piscataway, NJ), 12–17.Google Scholar
- (2012b) Metafraud: A meta-learning framework for detecting financial fraud. Management Inform. Systems Quart. 36(4):1293–1327.Crossref, Google Scholar
- (2010) Detecting fake websites: The contribution of statistical learning theory. Management Inform. Systems Quart. 34(3):435–461.Crossref, Google Scholar
- (2011) Location, location, location: An analysis of profitability of position in online advertising markets. J. Marketing Res. 48(6):1057–1073.Crossref, Google Scholar
- (2013) Alice in warningland: A large-scale field study of browser security warning effectiveness. Proc. 22nd USENIX Security Sympos. (USENIX Association, Berkeley, CA).Google Scholar
- (2009) Effects of technical abilities and phishing knowledge on phishing websites detection. Proc. IASTED Internat. Conf on Software Engineering (ACTA Press, Calgary, AB, Canada), 120–125.Google Scholar
- (2016a) How users perceive and respond to security messages: A NeuroIS research agenda and empirical study. Eur. J. Inform. Systems 25(4):364–390.Crossref, Google Scholar
- (2016b) Your memory is working against you: How eye tracking and memory explain habituation to security warnings. Decision Support Systems 92(0):3–13.Crossref, Google Scholar
- (2009) Adoption of electronic health records in the presence of privacy concerns: The elaboration likelihood model and individual persuasion. Management Inform. Systems Quart. 33(2):339–370.Crossref, Google Scholar
- (2010) The impact of personal dispositions on information sensitivity, privacy concern and trust in disclosing health information online. Decision Support Systems 49(2):138–150.Crossref, Google Scholar
- (2009) Presentation bias is significant in determining user preference for search results A user study. J. Amer. Soc. Inform. Sci. Tech. 60(1):135–149.Crossref, Google Scholar
- (2015) Predictive analytics for readmission of patients with congestive heart failure. Inform. Systems Res. 26(1):19–39.Link, Google Scholar
- (2007) Quo vadis TAM? J. Assoc. Inform. Systems 8(4):7.Google Scholar
- (2009). Case studies of an insider framework. Proc. 42nd Hawaii Internat. Conf. on System Sciences (IEEE, New York), 1–10.Google Scholar
- (2015) What do systems users have to fear? Using fear appeals to engender threats and fear that motivate protective security behaviors. Management Inform. Systems Quart. 39(4):837–864.Crossref, Google Scholar
- (2011) Bridging the gap in computer security warnings: A mental model approach. IEEE Security Privacy 9(2):18–26.Crossref, Google Scholar
- (1998) A tutorial on support vector machines for pattern recognition. Data Mining Knowledge Discovery 2(2):121–167.Crossref, Google Scholar
- (2009) Mental models of privacy and security. IEEE Tech. Soc. Magazine 28(3):37–46.Crossref, Google Scholar
- (2018) Setting priorities in behavioral interventions: An application to reducing phishing risk. Risk Analysis 38(4):826–838.Crossref, Google Scholar
- (2005) The value of intrusion detection systems in information technology security architecture. Inform. Systems Res. 16(1):28–46.Link, Google Scholar
- (2012) Business intelligence and analytics: From big data to big impact. Management Inform. Systems Quart. 36(4):1165–1188.Crossref, Google Scholar
- (2011) Interface design elements for anti-phishing systems. Internat. Conf. on Design Science Research in Information Systems (Springer, Berlin), 253–265. Google Scholar
- (2015) Analysis of ordinal data with cumulative link models—Estimation with the R-package ordinal. https://mran.microsoft.com/snapshot/2017-12-11/web/packages/ordinal/vignettes/clm_intro.pdf.Google Scholar
- (2007) Support vector ordinal regression. Neural Comput. 19(3):792–815.Crossref, Google Scholar
- (2004) Fighting internet auction fraud: An assessment and proposal. IEEE Comput . 37(10):31–37.Crossref, Google Scholar
- (2019) Seeing the forest and the trees: A meta-analysis of the antecedents to information security policy compliance. Management Inform. Systems Quart. 43(2):525–554.Crossref, Google Scholar
- (2008). A framework for reasoning about the Human in the Loop. Proc. 1st Conf. on Usability, Psychology, and Security (USENIX Association, Berkeley, CA).Google Scholar
- (2014) Understanding compliance with bring your own device policies utilizing protection motivation theory: Bridging the intention-behavior gap. J. Inform. Systems 28(1):209–226.Crossref, Google Scholar
- (2012) Insider threat study: Illicit cyber activity involving fraud in the U.S. financial services sector. Report, Software Engineering Institute, Carnegie Mellon University, Pittsburgh, PA.Google Scholar
- (1989) Perceived usefulness, perceived ease of use, and user acceptance of information technology. Management Inform. Systems Quart. 13(3):319–340.Crossref, Google Scholar
- (2019) Alerting users about phishing attacks. Internat. Conf. on Human-Computer Interaction (Springer, Cham, Switzerland), 134–148.Google Scholar
- (2006) Why phishing works. Proc. SIGCHI Conf. on Human Factors in Computing Systems (ACM, New York), 581–590.Google Scholar
- (2006) Why spoofing is serious Internet fraud. Commun. ACM 49(10):76–82.Crossref, Google Scholar
- (2006). Decision strategies and susceptibility to phishing. Proc. Sympos. on Usable Privacy and Security (USENIX Association, Berkeley, CA), 79–90.Google Scholar
- (2007). Behavioral response to phishing risk. Proc. ACM Anti-Phishing Working Groups Annu. eCrime Researchers Summit (ACM, New York), 37–44.Google Scholar
- (2008). You’ve been warned: An empirical study of the effectiveness of web browser phishing warnings. Proc. ACM SIGCHI Conf. on Human Factors in Computing Systems (ACM, New York), 1065–1074.Google Scholar
- (2012) Inference-based naive Bayes: Turning naive Bayes cost-sensitive. IEEE Trans. Knowledge. Data Engrg. 25(10):2302–2313.Crossref, Google Scholar
- (2006) An introduction to ROC analysis. Pattern Recognit. Lett. 27(8):861–874.Crossref, Google Scholar
- , et al. (2015) Improving SSL warnings. Proc. ACM Conf. on Human Factors in Computing Systems, 2893–2902.Google Scholar
- (2000) A meta-analysis of research on protection motivation theory. J. Appl. Soc. Psychol. 30(2):407–429.Crossref, Google Scholar
- (2011) Managing Forward: Customer Satisfaction as a Predictive Metric for Banks. U.S. ForeSee Results 2011 Online Banking Study (ACM, New York), http://bankblog.optirate.com/wp-content/uploads/2011/07/u.s.-foresee-results-2011-online-banking-study.pdf.Google Scholar
- Gartner (2011) Magic quadrant for web fraud detection, April 19, 2011. https://www.gartner.com/en/documents/1641814/magic-quadrant-for-web-fraud-detection.Google Scholar
- (1997) Gender differences in the perception and use of email: An extension to the technology acceptance model. Management Inform. Systems Quart. 21(4):389–400.Crossref, Google Scholar
- (2014) Editor’s comments: Design science research in top information systems journals. Management Inform. Systems Quart. 38(1):iii–viii.Google Scholar
- (2000) Perils of Internet fraud: An empirical investigation of deception and trust with experienced Internet consumers. IEEE Trans. Systems Man Cybernetics Part A 30(4):395–410.Google Scholar
- (2003) Consumer and business deception on the internet: Content analysis of documentary evidence. Internat. J. Electron. Commerce 7(4):93–118.Crossref, Google Scholar
- (2013) Positioning and presenting design science research for maximum impact. Management Inform. Systems Quart. 37(2):337–355.Crossref, Google Scholar
- (2002) Gene selection for cancer classification using support vector machines. Machine Learning 46(1-3):389–422.Crossref, Google Scholar
- (2005) Spam: It’s not for inboxes anymore. IEEE Comput. 38(10):28–34.Google Scholar
- (2014) Security services as coping mechanisms: An investigation into user intention to adopt an email authentication service. Inform. Systems J. 24(1):61–84.Crossref, Google Scholar
- (2009) So long, and no thanks for the externalities: The rational rejection of security advice by users. Proc. Workshop on New Security Paradigms, 133–144.Google Scholar
- (2008) Security and identification indicators for browsers against spoofing and phishing attacks. ACM Trans. Internet Tech. 8(4):1–36.Google Scholar
- (2004) Design science in information systems research. Management Inform. Systems Quart. 28(1):75–105.Crossref, Google Scholar
- (2012) The state of phishing attacks. Commun. ACM 55(1):74–81.Crossref, Google Scholar
- (2007) Social phishing. Commun. ACM 50(10):94–100.Crossref, Google Scholar
- (2016) More harm than good? How security messages that interrupt make us vulnerable. Inform. Systems Res. 27(4):880–896.Link, Google Scholar
- (2010) Technology dominance in complex decision making: The case of aided credibility assessment. J. Management Inform. Systems 27(1):175–202.Crossref, Google Scholar
- (1995) Principles and Practice of Marketing (McGraw-Hill, New York).Google Scholar
- (1979) Prospect theory: An analysis of decision under risk. Econometrica 47(2):263–292.Crossref, Google Scholar
- (2011) Web Analytics 2.0: The Art of Online Accountability and Science of Customer Centricity (Wiley Publishing, New York). Google Scholar
- (2009) A behavioral analysis of passphrase design and effectiveness. J. Assoc. Inform. Systems 10(2):63–89.Google Scholar
- (2013) “Comply or die” is dead: Long live security-aware principal agents. Internat. Conf. on Financial Cryptography and Data Security (Springer, Berlin), 70–82.Google Scholar
- (2018) Advanced customer analytics: Strategic value through integration of relationship-oriented big data. J. Management Inform. Systems 35(2):540–574.Crossref, Google Scholar
- (2006) SVMs for the blogosphere: Blog identification and splog detection. AAAI Spring Sympos.: Computational Approaches to Analyzing Weblogs, 92–99.Google Scholar
- (2015). Phishing is a $3.7-million annual cost for average large company. CSO (August 26). Accessed October 7, 2018, https://www.csoonline.com/article/2975807/phishing-is-a-37-million-annual-cost-for-average-large-company.html Google Scholar
- (2008) Locking the door but leaving the computer vulnerable: Factors inhibiting home users’ adoption of software firewalls. Decision Support Systems 46(1):254–264.Crossref, Google Scholar
- (2010) Teaching Johnny not to fall for phish. ACM Trans. Internet Tech. 10(2):1–31.Google Scholar
- (2011) Cisco: Targeted attacks cost organizations $1.29 billion annually. Security Week (June 30). Accessed August 14, 2016, https://www.securityweek.com/cisco-targeted-attacks-cost-organizations-129-billion-annually.Google Scholar
- (2007) Usability evaluation of anti-phishing toolbars. J. Comput. Virology 3(2):163–184.Crossref, Google Scholar
- (2014) Toward a contingency approach with whitelist-and blacklist-based anti-phishing applications: What do usability tests indicate? Behav. Inform. Tech. 33(11):1136–1147.Crossref, Google Scholar
- (2009) A Novel Anti-Phishing Framework Based on Honeypots (IEEE, New York). Google Scholar
- (2009) Avoidance of information technology threats: A theoretical perspective. Management Inform. Systems Quart. 33(1):71–90.Crossref, Google Scholar
- (2006) An antiphishing strategy based on visual similarity assessment. IEEE Internet Comput. 10(2):58–65.Crossref, Google Scholar
- (2012) Can visible cues in search results indicate vendors’ reliability? Decision Support Systems 52(3):768–775.Crossref, Google Scholar
- (2010) Moving toward black hat research in information systems security: An editorial introduction to the special issue. Management Inform. Systems Quart. 34(3):431–433.Crossref, Google Scholar
- (1995) An integrative model of organizational trust. Acad. Management Rev. 20(3):709–734.Crossref, Google Scholar
- McAfee (2013) McAfee threats report. First quarter . McAfee (April 10). Accessed March 23, 2017, http://www.mcafee.com/us/resources/reports/rp-quarterly-threat-q1-2013.pdf.Google Scholar
- (1980) Regression models for ordinal data. J. Royal Statist. Soc. B 42(2):109–127.Google Scholar
- (2002) Developing and validating trust measures for e-commerce: An integrative typology. Inform. Systems Res. 13(3):334–359.Link, Google Scholar
- (1998) Initial trust formation in new organizational relationships. Acad. Management Rev. 23(3):473–490.Crossref, Google Scholar
- (2005) Gender and age differences in employee decisions about new technology: An extension to the theory of planned behavior. IEEE Trans. Engrg. Management 52(1):69–84.Crossref, Google Scholar
- (2013) Security analytics will be the next big thing in IT security. Network World (May 31). Accessed March 23, 2017, https://www.networkworld.com/article/2166806/security-analytics-will-be-the-next-big-thing-in-it-security.html.Google Scholar
- , et al. (2017) Dissecting spear phishing emails for older vs young adults: On the interplay of weapons of influence and life domains in predicting susceptibility to phishing. Proc. 2017 CHI Conf. on Human Factors in Computing Systems (ACM, New York), 6412–6424.Google Scholar
- (2009) A Personality Based Model for Determining Susceptibility to Phishing Attacks (University of Arkansas, Little Rock).Google Scholar
- (2004) Building effective online marketplaces with institution-based trust. Inform. Systems Res. 15(1):37–59.Link, Google Scholar
- (2006) Using technology acceptance model to explain how attitudes determine Internet usage: The role of perceived access barriers and demographics. J. Bus. Res. 59:999–1007.Crossref, Google Scholar
- (2015) A taxonomy of evaluation methods for information systems artifacts. J. Management Inform. Systems 32(3):229–267.Crossref, Google Scholar
- (2009) Web page classification: Features and algorithms. ACM Comput. Survey 41(2):1–31.Crossref, Google Scholar
- (2011) Trends in circumventing web-malware detection. Technical report, Google, https://static.googleusercontent.com/media/research.google.com/en//archive/papers/rajab-2011a.pdf, http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.357.2542.Google Scholar
- (2009) Choice and chance: A conceptual model of paths to information security compromise. Inform. Systems Res. 20(1):121–139.Link, Google Scholar
- (2017) 2017 cost of cyber crime study. Technical report, Ponemon Institute, North Traverse City, MI, https://www.accenture.com/_acnmedia/PDF-62/Accenture-2017CostCybercrime-US-FINAL.pdf#zoom=50.Google Scholar
- (1997) Protection motivation theory. Gochman DS, ed. Handbook of Health Behavior Research 1: Personal and Social Determinants. (Plenum Press), 113–132.Google Scholar
- (2010) Cyber Security, Cyber Crime and Cyber Forensics: Applications and Perspectives (Information Science Reference/IGI Global, Hershey, PA).Google Scholar
- (2020) The influence of professional subculture on information security policy violations: A field study in a healthcare context. Inform. Systems. Res. 31(4):1240–1259Link, Google Scholar
- (2000) Inside risks: Semantic network attacks. Commun. ACM 43(12):168.Crossref, Google Scholar
- (2003) Ranking with large margin principle: Two approaches. Adv. Neural Inform. Processing Systems 15:961–968.Google Scholar
- (2010) Who falls for phish?: A demographic analysis of phishing susceptibility and effectiveness of interventions. Proc. SIGCHI Conf. on Human Factors in Computing Systems (ACM, New York), 373–382.Google Scholar
- (2015) Cybersecurity: Recognizing the risk and protecting against attacks. NC Banking Inst. 19:345.Google Scholar
- (2011) Predictive analytics in information systems research. Management Inform. Systems Quart. 35(3):553–572.Crossref, Google Scholar
- (2010) Neutralization: New insights into the problem of employee information systems security policy violations. Management Inform. Systems Quart. 34(3):487–502.Crossref, Google Scholar
- (2009). Crying wolf: An empirical study of SSL warning effectiveness. Proc. USENIX Security Sympos. (USENIX Association, Berkeley, CA), 399–416.Google Scholar
- Symantec (2012) Norton cybercrime report: The human impact. Symantec (April 10). Accessed March 23, 2017, http://us.norton.com/content/en/us/home_homeoffice/media/pdf/cybercrime_report/Norton_USA-Human%20Impact-A4_Aug4-2.pdf.Google Scholar
- (2014) How big data are changing the security analytics landscape. TechRepublic (January 2). Accessed March 23, 2017, https://www.techrepublic.com/blog/big-data-analytics/how-big-data-is-changing-the-security-analytics-landscape/.Google Scholar
- (2015) Increasing accountability through user-interface design artifacts: A new approach to address the problem of access-policy violations. Management Inform. Systems Quart. 39(2):345–366.Crossref, Google Scholar
- (2014) Using measures of risk perception to predict information security behavior: Insights from electroencephalography (EEG). J. Assoc. Inform. Systems 15(10):679–722.Google Scholar
- (2018) Tuning out security warnings: A longitudinal examination of habituation through fMRI, eye tracking, and field experiments. Management Inform. Systems Quart. 42(2):355–380.Crossref, Google Scholar
- (2003) User acceptance of information technology: Toward a unified view. Management Inform. Systems Quart. 27(3):397–423.Crossref, Google Scholar
- Verizon (2016) Data breach investigations report. Accessed March 23, 2017, http://www.verizonenterprise.com/DBIR/2016/ Google Scholar
- (2011) Why do people get phished? Testing individual differences in phishing vulnerability within an integrated, information processing model. Decision Support Systems 51(3):576–586.Crossref, Google Scholar
- (2011) Cloak and dagger: Dynamics of web search cloaking. Proc. 18th ACM Conf. on Computer and Communications Security (ACM, New York), 477–490.Google Scholar
- (2015) Insider threats in a financial institution: Analysis of attack-proneness of information systems applications. Management Inform. Systems Quart. 39(1):91–112.Crossref, Google Scholar
- (2016) Overconfidence in phishing email detection. J. Assoc. Inform. Systems 17(11):759.Google Scholar
- (2017) Coping responses in phishing detection: An investigation of antecedents and consequences. Inform. Systems Res. 28(2):378–396.Link, Google Scholar
- (2012) Phishing susceptibility: An investigation into the processing of a targeted spear phishing email. IEEE Trans. Professional Comm. 55(4):345–362.Crossref, Google Scholar
- (2010) The influence of experiential and dispositional factors in phishing: An empirical investigation of the deceived. J. Management Inform. Systems 27(1):273–303.Crossref, Google Scholar
- (2014) Influence techniques in phishing attacks: An examination of vulnerability and resistance. Inform. Systems Res. 25(2):385–400.Link, Google Scholar
- (2006) Do security toolbars actually prevent phishing attacks? Proc. SIGCHI Conf. on Human Factors in Computing Systems (ACM, New York), 601–610.Google Scholar
- (2008) Dynamics of trust revision: Using health infomediaries. J. Management Inform. Systems 24(4):225–248.Crossref, Google Scholar
- (2015) Fake-website detection tools: Identifying elements that promote individuals’ use and enhance their performance. J. Assoc. Inform. Systems 16(6):448.Google Scholar
- (2014) A domain-feature enhanced classification model for detection of phishing e-business websites. Inform. Management 51(7):845–853.Crossref, Google Scholar
- (2007) Phinding phish: Evaluating anti-phishing tools. Proc. 14th Annual Network and Distributed System Security Sympos. 1–16.Google Scholar

