Persuasion and Phishing: Analysing the Interplay of Persuasion Tactics in Cyber Threats
Kalam Khadka

TL;DR
This paper analyzes the use of persuasion tactics in phishing emails, identifying common principles and targets to improve detection and prevention methods in cybersecurity.
Contribution
It extends previous research by analyzing entire email contents for persuasion principles and examining phishing goals and targets using an ontological model.
Findings
Distraction is the most common persuasion principle in phishing emails.
Phishing targets individuals primarily for unauthorized access and financial gain.
The study highlights the importance of understanding persuasion tactics for better detection.
Abstract
This study extends the research of Ferreira and Teles (2019), who synthesized works by Cialdini (2007), Gragg (2003), and Stajano and Wilson (2011) to propose a unique list of persuasion principles in social engineering. While Ferreira and Teles focused on email subject lines, this research analyzed entire email contents to identify principles of human persuasion in phishing emails. This study also examined the goals and targets of phishing emails, providing a novel contribution to the field. Applying these findings to the ontological model by Mouton et al. (2014) reveals that when social engineers use email for phishing, individuals are the primary targets. The goals are typically unauthorized access, followed by financial gain and service disruption, with Distraction as the most commonly used compliance principle. This research highlights the importance of understanding human…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsMisinformation and Its Impacts · Spam and Phishing Detection · Information and Cyber Security
