University of Technology Sydney
Human Decision-Making In Phishing Email Detection: A Dual Process And Cue-Utilisation Approach
Abstract
dc:description.abstractPhishing emails are the most common cyber security attack vector in Australia. This particular threat incurs huge costs to industry and falling victim can have substantial negative effects on peoples’ lives. Since technical solutions cannot intercept all such emails, users must detect these messages during their day-to-day email usage, meaning this problem remains one of human decision-making. This work is a structured program of experiments examining one of the major theories of human decision-making: dual-process theory, and then delves into a cue utilisation approach, as applied to this important, real-world problem. Within this framework, phishing emails are conflict problems where messages are constructed to powerfully cue ingrained, simple and fast heuristic responses (System 1) which are, however, in conflict with the answers provided by effortful, elaborative thought (System 2). Following this, System 2 thought is potentially protective against victimisation. However, System 2 processing, unlike System 1, is dependent on working memory. The initial experiments capitalise on this working memory requirement by manipulating how much System 2 processing was available to contribute to a problem by using a visual matrix task to impose cognitive load on participants as they attempted to detect phishing amongst legitimate emails distractors. In doing so we demonstrated that several central predictions of dual-process theories apply to the problem of phishing email detection. The second phase of this research investigated the role of diagnostic ‘cues’ in detecting illegitimate emails, how the use of these cues is impacted by cognitive load, and which cues are diagnostic. These experiments reveal surprising patterns of decision-making in phishing email detection, suggesting that phishing emails may be processed in a global manner. Finally, by applying k-means clustering to our previous data, we found that participants could be grouped into two distinct behavioural categories based on how they attended to features of the phishing emails. We also found that there were differences in the amount of direct cue-utilisation to outcome relationships between groups. This again suggests that global processing is taking place but suggests that there may be an individual difference as to global/local processing between participants. In this novel and ambitious attempt to apply a theoretical model of cognition to a complicated, real-world problem, we found that many of the central predictions of dual-process models hold true. Furthermore, when engaging with cue-utilisation theory, our experiments reveal surprising patterns of decision-making in phishing email detection.
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Conway, Daniel Edward
Rights
dc:rights- Statement dc:rights
-
- info:eu-repo/semantics/openAccess
- The author owns the copyright in this thesis including all reproduction and reuse rights for the work. The work may not be altered without the permission of the copyright owner. Attribution is essential when quoting or paraphrasing from this thesis.
- © 2025 Daniel Edward Conway
- au.edu.uts.lib/cph
- Language dc:language.iso
- en_US
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- http://hdl.handle.net/10453/189678
- OAI identifier oai:identifier
- oai:opus.lib.uts.edu.au:10453/189678