Re-evaluation of PhishI game and its utilisation in eliciting security requirements

Rubia Fatima, Affan Yasin, Lin Liu*, Jianmin Wang

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

The COVID-19 pandemic has sparked considerable alarm amongst the general community and has significantly affected the societal attitudes and perceptions. In the current era, social engineers are applying various strategies to exploit human weakness. Phishing, a social engineering technique, is one of the most widely used and effective ways to undermine human assets. In this research study, firstly, we aim to educate the participants regarding phishing attacks; secondly, the dangers associated with excessive online sharing; and thirdly, how to utilise game scenarios developed by the participants to elicit security requirements. We have employed various research methods, such as, survey, observation, personas development, and scenario-based technique to achieve these objectives. Our re-evaluation results show that the PhishI game effectively educates participants regarding phishing attacks and dangers associated with disclosing excessive online information.

Original languageEnglish
Pages (from-to)294-321
Number of pages28
JournalInternational Journal of Information and Computer Security
Volume23
Issue number3
DOIs
Publication statusPublished - 2024
Externally publishedYes

Keywords

  • awareness
  • human factor
  • online information disclosure
  • phishing attack
  • security requirements elicitation
  • serious game
  • social engineering

Fingerprint

Dive into the research topics of 'Re-evaluation of PhishI game and its utilisation in eliciting security requirements'. Together they form a unique fingerprint.

Cite this