Evaluating the Information Security Awareness of Smartphone Users
Ron Bitton, Kobi Boymgold, Rami Puzis, Asaf Shabtai
Abstract
Information security awareness (ISA) is a practice focused on the set of skills, which help a user successfully mitigate a social engineering attack. Previous studies have presented various methods for evaluating the ISA of both PC and mobile users. These methods rely primarily on subjective data sources such as interviews, surveys, and questionnaires that are influenced by human interpretation and sincerity. Furthermore, previous methods for evaluating ISA did not address the differences between classes of social engineering attacks. In this paper, we present a novel framework designed for evaluating the ISA of smartphone users to specific social engineering attack classes. In addition to questionnaires, the proposed framework utilizes objective data sources: a mobile agent and a network traffic monitor; both of which are used to analyze the actual behavior of users. We empirically evaluated the ISA scores assessed from the three data sources (namely, the questionnaires, mobile agent, and network traffic monitor) by conducting a long-term user study involving 162 smartphone users. All participants were exposed to four different security challenges that resemble real-life social engineering attacks. These challenges were used to assess the ability of the proposed framework to derive a relevant ISA score. The results of our experiment show that: (1) the selfreported behavior of the users differs significantly from their actual behavior; and (2) ISA scores derived from data collected by the mobile agent or the network traffic monitor are highly correlated with the users' success in mitigating social engineering attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ca79df2b-c192-46a9-a0d1-98deb3aeaf2bCited by top-tier papers3
- A Decade of Privacy-Relevant Android App Reviews: Large Scale TrendsOmer Akgul, Sai Teja Peddinti, Nina Taft, Michelle L. Mazurek et al.USENIX Security 2024 · 14 citations
- I Was Told to Install the Antivirus App, but I'm Not Sure I Need It: Understanding Smartphone Antivirus Software Adoption and User PerceptionsSeyoung Jin, Heewon Baek, Uichin Lee, Hyoungshick KimCHI 2025 · 2 citations
- Understanding How Users Prepare for and React to Smartphone TheftDivyanshu Bhardwaj, Sumair Ijaz Hashmi, Katharina Krombholz, Maximilian GollaUSENIX Security 2025
Builds on1
Related papers
- Detecting Asks in Social Engineering Attacks: Impact of Linguistic and Structural KnowledgeBonnie J. Dorr, Archna Bhatia, Adam Dalton, Brodie Mather et al.AAAI 2020
- Towards Measuring and Mitigating Social Engineering Software Download AttacksTerry Nelms, Roberto Perdisci, Manos Antonakakis, Mustaque AhamadUSENIX Security 2016 · 70 citations
- "We Even Borrowed Money From Our Neighbor": Understanding Mobile-based Frauds Through Victims' ExperiencesLubna Razaq, Tallal Ahmad, Samia Ibtasam, Muhammad Umer Ramzan et al.CSCW 2021 · 29 citations
- Are You Going to Answer That? Measuring User Responses to Anti-Robocall Application IndicatorsImani N. Sherman, Jasmine D. Bowers, Keith McNamara Jr., Juan E. Gilbert et al.NDSS 2020
- Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-EfficacyMarkus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela SasseUSENIX Security 2024 · 7 citations
