I Don't Need an Expert! Making URL Phishing Features Human Comprehensible
Kholoud Althobaiti, Nicole Meng, Kami Vaniea
Abstract
Judging the safety of a URL is something that even security experts struggle to do accurately without additional information. In this work, we aim to make experts’ tools accessible to non-experts and assist general users in judging the safety of URLs by providing them with a usable report based on the information professionals use. We designed the report by iterating with 8 focus groups made up of end users, HCI experts, and security experts to ensure that the report was usable as well as accurately interpreted the information. We also conducted an online evaluation with 153 participants to compare different report-length options. We find that the longer comprehensive report allows users to accurately judge URL safety (93% accurate) and that summaries still provide benefit (83% accurate) compared to domain highlighting (65% accurate).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b3734311-7c0d-4c0b-88a5-e1f771aef984Cited by top-tier papers7
- "It's Stored, Hopefully, on an Encrypted Server": Mitigating Users' Misconceptions About FIDO2 Biometric WebAuthnLeona Lassak, Annika Hildebrandt, Maximilian Golla, Blase UrUSENIX Security 2021 · 48 citations
- How WEIRD is Usable Privacy and Security Research?Ayako Akiyama Hasegawa, Daisuke Inoue, Mitsuaki AkiyamaUSENIX Security 2024 · 26 citations
- Better Together: The Interplay Between a Phishing Awareness Video and a Link-centric Phishing Support ToolBenjamin Maximilian Berens, Florian Schaub, Mattia Mossano, Melanie VolkamerCHI 2024 · 8 citations
- Judging Phishing Under Uncertainty: How Do Users Handle Inaccurate Automated Advice?Tarini Saka, Kalliopi Vakali, Adam D. G. Jenkins, Nadin Kokciyan et al.CHI 2025 · 1 citation
- You Know Why, but Still Rely: The Impact of Explainable AI on Trust, Task Load, and Performance in Cybersecurity Decision-MakingNeele Roch, Hannah Sievers, Noé Zufferey, Verena ZimmermannUSENIX Security 2026
Builds on4
- I Think They're Trying to Tell Me Something: Advice Sources and Selection for Digital SecurityElissa M. Redmiles, Amelia R. Malone, Michelle L. MazurekS&P 2016 · 151 citations
- How Experts Detect Phishing Scam EmailsRick WashCSCW 2020 · 76 citations
- What is this URL's Destination? Empirical Evaluation of Users' URL ReadingSara Albakry, Kami Vaniea, Maria K. WoltersCHI 2020 · 48 citations
- Measuring Identity Confusion with Uniform Resource LocatorsJoshua Reynolds, Deepak Kumar, Zane Ma, Rohan Subramanian et al.CHI 2020 · 30 citations
Related papers
- Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIsPeter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha FahlCHI 2020 · 39 citations
- The Role of Professional Product Reviewers in Evaluating Security and PrivacyWentao Guo, Jason Walter, Michelle L. MazurekUSENIX Security 2023
- A Qualitative Study on How Usable Security and HCI Researchers Judge the Size and Importance of Odds Ratio and Cohen's d Effect SizesAnna-Marie Ortloff, Julia Angelika Grohs, Simon Lenau, Matthew SmithCHI 2025 · 5 citations
- URL Inspection Tasks: Helping Users Detect Phishing Links in EmailsDaniele Lain, Yoshimichi Nakatsuka, Kari Kostiainen, Gene Tsudik et al.USENIX Security 2025
- A Comprehensive Quality Evaluation of Security and Privacy Advice on the WebElissa M. Redmiles, Noel Warford, Amritha Jayanti, Aravind Koneru et al.USENIX Security 2020
