User-Centred Security Education: A Game Design to Thwart Phishing Attacks Nalin Asanka Gamagedara Arachchilage Australian Centre for Cyber Security University of New South wales at the Australian Defence Force Academy
[email protected]
1. Overview Security exploit can include cyber threats.
2. Game Design Issues
• • One such a cyber threat is phishing and well known as identity theft. • Automated anti-phishing tools are not entirely reliable in detecting phishing attacks. • “Human” is the weakest link in information security. • Education is needed to combat against phishing threat. • The aim of this research study focuses on a design and development of a game for mobile platforms to educate individuals about phishing attacks.
The elements of a game design framework were incorporated into the mobile game prototype design context.
Research Question: How does one design and develop a game that, through motivation, enhances users’ avoidance behaviour in order to protect themselves against phishing attacks?
3. Game Design
•
4. Methodology Investigated the participants’ impact on the game design framework introduced after their engagement with the game play activity.
• Employed a usability study using System Usability Scale (SUS) to assess the subjective satisfaction of the mobile game prototype interface. • Then, a think-aloud study was conducted along with a pre- and post-test in order to evaluate the game design framework.
6. Conclusion
5. Results
• This research focused on a design and development of a game for mobile platforms to educate computer users to thwart phishing attacks.
• The mobile game prototype was somewhat effective (There was a statistically significant increase (28 %) in the post-test) in teaching people to thwart phishing attacks. • The overall game prototype aimed to enhance users’ avoidance behavior through their motivation to protect themselves against phishing attacks.
References
• Satisfaction of the mobile game prototype application (SUS) - 84 % • Participants played mobile game increased their score by 28% ((Pre-test: M= 56.00, SD=17.911 and Post-test: M=84.00, SD=13.139), t(19)= -7.97, p