Many Phish in the C: A Coexisting-Choice-Criteria Model of Security Behavior

11/15/2018
by   Iain Embrey, et al.
0

Normative decision theory proves inadequate for modeling human responses to the social-engineering campaigns of Advanced Persistent Threat (APT) attacks. Behavioral decision theory fares better, but still falls short of capturing social-engineering attack vectors, which operate through emotions and peripheral-route persuasion. We introduce a generalized decision theory, under which any decision will be made according to one of multiple coexisting choice criteria. We denote the set of possible choice criteria by C. Thus the proposed model reduces to conventional Expected Utility theory when | C_EU|=1, whilst Dual-Process (thinking fast vs. thinking slow) decision making corresponds to a model with | C_DP|=2. We consider a more general case with | C|≥ 2, which necessitates careful consideration of _how_, for a particular choice-task instance, one criterion comes to prevail over others. We operationalize this with a probability distribution that is conditional upon traits of the decision maker as well as upon the context and the framing of choice options. Whereas existing Signal Detection Theory (SDT) models of phishing detection commingle the different peripheral-route persuasion pathways, in the present descriptive generalization the different pathways are explicitly identified and represented. A number of implications follow immediately from this formulation, ranging from the conditional nature of security-breach risk to delineation of the prerequisites for valid tests of security training. Moreover, the model explains the `stepping-stone' penetration pattern of APT attacks, which has confounded modeling approaches based on normative rationality.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/12/2020

Morshed: Guiding Behavioral Decision-Makers towards Better Security Investment in Interdependent Systems

We model the behavioral biases of human decision-making in securing inte...
research
03/04/2022

Quantification of emotions in decision making

The problem of quantification of emotions in the choice between alternat...
research
02/21/2023

Crowd simulation incorporating a route choice model and similarity evaluation using real large-scale data

Modeling and simulation approaches that express crowd movement with math...
research
03/03/2023

Calibration of Quantum Decision Theory: Aversion to Large Losses and Predictability of Probabilistic Choices

We present the first calibration of quantum decision theory (QDT) to a d...
research
01/28/2023

A customizable approach to assess software quality through Multi-Criteria Decision Making

Over the years, Software Quality Engineering has increased interest, dem...
research
03/07/2023

Investigating day-to-day route choices based on multi-scenario laboratory experiments. Part I: Route-dependent attraction and its modeling

In the area of urban transportation networks, a growing number of day-to...
research
01/30/2013

Implementing Resolute Choice Under Uncertainty

The adaptation to situations of sequential choice under uncertainty of d...

Please sign up or login with your details

Forgot password? Click here to reset