TY - JOUR
T1 - Re-evaluation of PhishI game and its utilisation in eliciting security requirements
AU - Fatima, Rubia
AU - Yasin, Affan
AU - Liu, Lin
AU - Wang, Jianmin
N1 - Publisher Copyright:
© 2024 Inderscience Enterprises Ltd.
PY - 2024
Y1 - 2024
N2 - The COVID-19 pandemic has sparked considerable alarm amongst the general community and has significantly affected the societal attitudes and perceptions. In the current era, social engineers are applying various strategies to exploit human weakness. Phishing, a social engineering technique, is one of the most widely used and effective ways to undermine human assets. In this research study, firstly, we aim to educate the participants regarding phishing attacks; secondly, the dangers associated with excessive online sharing; and thirdly, how to utilise game scenarios developed by the participants to elicit security requirements. We have employed various research methods, such as, survey, observation, personas development, and scenario-based technique to achieve these objectives. Our re-evaluation results show that the PhishI game effectively educates participants regarding phishing attacks and dangers associated with disclosing excessive online information.
AB - The COVID-19 pandemic has sparked considerable alarm amongst the general community and has significantly affected the societal attitudes and perceptions. In the current era, social engineers are applying various strategies to exploit human weakness. Phishing, a social engineering technique, is one of the most widely used and effective ways to undermine human assets. In this research study, firstly, we aim to educate the participants regarding phishing attacks; secondly, the dangers associated with excessive online sharing; and thirdly, how to utilise game scenarios developed by the participants to elicit security requirements. We have employed various research methods, such as, survey, observation, personas development, and scenario-based technique to achieve these objectives. Our re-evaluation results show that the PhishI game effectively educates participants regarding phishing attacks and dangers associated with disclosing excessive online information.
KW - awareness
KW - human factor
KW - online information disclosure
KW - phishing attack
KW - security requirements elicitation
KW - serious game
KW - social engineering
UR - http://www.scopus.com/inward/record.url?scp=85193346864&partnerID=8YFLogxK
U2 - 10.1504/IJICS.2024.138492
DO - 10.1504/IJICS.2024.138492
M3 - Article
AN - SCOPUS:85193346864
SN - 1744-1765
VL - 23
SP - 294
EP - 321
JO - International Journal of Information and Computer Security
JF - International Journal of Information and Computer Security
IS - 3
ER -