Business Services Industry
Teaching Consumers On-Line Safety Easiest When They Take the Bait
Business Wire, Oct 15, 2008
APWG and Carnegie Mellon Team Up to Deliver Safety Instruction in 'Teachable Moment' When Consumers Fall for Phishing Scams
ATLANTA -- The Anti-Phishing Working Group (APWG) and Carnegie Mellon University's Supporting Trust Decisions Project have established a phishing page redirect initiative that protects global online consumers who have been tricked into clicking links in scam emails by delivering them to Web pages that instruct them on the dangers of phishing - and how to avoid them. The program was announced today at the APWG conference in Atlanta.
The AWPG/Carnegie Mellon Phishing Education Landing Page program builds on the philosophy of using the "teachable moment" to warn users immediately after they've fallen for a phishing lure and then give them on-line safety instruction precisely at a time when they are receptive to it. Phishing sites are designed to resemble Web sites of legitimate businesses, such as banks and online retailers, to trick people into revealing credit card numbers, bank accounts or login names and passwords. Actionable messaging will help consumers to avoid falling victim to these scams a second time.
"We are excited about the opportunity to educate consumers as they are falling victim to a phishing site," said Dr. Laura Mather, Managing Director of Operational Policy for the APWG and CEO of Silver Tail Systems. "We see this initiative as having real impact in helping people understand when they have received a phishing communication so that they can protect themselves going forward."
This education-at-time-of-action is accomplished by leveraging the URLs of the phishing sites themselves after anti-phishing investigators have identified the sites and shut them down. Instead of leaving the URL file blank, returning a 'PAGE NOT FOUND' message to consumers following phishing links, they will be served a page of instruction on how to avoid phishing and reduce the risk of falling victim to electronic crime. (Redirect scripts placed at the sanitized phishing URL will automatically forward the advisory content.)
"Our research has shown that most Internet users don't know very much about online scams and don't realize that there are some simple things they can do to protect themselves," said Dr. Lorrie Cranor, an associate professor of computer science and engineering & public policy at Carnegie Mellon and director of the Supporting Trust Decisions Project.
Ponnurangam Kumaraguru, a computer science Ph.D. student who is leading the effort to design and evaluate anti-phishing training materials at Carnegie Mellon added, "Nobody wants to spend their time taking on-line safety courses. But we've demonstrated that users are receptive to on-line safety instruction immediately after they fall for a phishing attack and they tend to remember this instruction."
The phishing education landing page developed by APWG and Carnegie Mellon teaches would-be victims not to give out personal information upon email request and to use a skeptical eye in judging online communications.
The implementation of the program depends on the participation of both takedown service providers and the ISPs and other companies whose servers have been co-opted to host phishing sites. The APWG is already successfully recruiting companies that perform phishing site takedowns, victimized brandholders and trade associations to encourage ISPs and other organizations that remove phish sites to use the APWG's education landing page program.
The program is based on a similar program initiated by Bank of America in 2007. The APWG/Carnegie Mellon program builds on Bank of America's ideas by creating a page that can be used for phishing site against any brand. Bank of America has already implemented the APWG/Carnegie Mellon program.
"Bank of America is committed to providing its customers with industry leading security tools and advice to protect them and enhance their overall customer experience. Educating our customers about the risks of identity theft and fraud is critical," says David Shroyer, SVP for eCommerce Online Security at Bank of America.
"We know from experience that an educated customer is the best defense against fraud, and with this program we are educating our customers at the point of incidence, and letting customers know that we are working to protect them," Mr. Shroyer said.
The APWG/Carnegie Mellon scheme will augment the usual procedure for communicating to the hosting organization about phishing sites. Instead of asking that the site be disabled and file content associated with the phishing URL removed, the takedown provider or victimized brandholder would request that the URL be preserved and a redirect script send the duped user to a webpage hosted by the APWG.
The education landing page will automatically determine whether the user is using a PC or laptop or handheld device and vend the device-appropriate page. Users of PDAs and Web-enabled cell phones will receive a page exclusively of text. People using PCs and laptops will receive an enhanced page of text, graphics and a number of links to online resources.
Most Recent Business Articles
- Multiple criteria evaluation and optimization of transportation systems
- Multi-criteria analysis procedure for sustainable mobility evaluation in urban areas
- A two-leveled multi-objective symbiotic evolutionary algorithm for the hub and spoke location problem
- Multi-criteria analysis for evaluating the impacts of intelligent speed adaptation
- The development of Taiwan arterial traffic-adaptive signal control system and its field test: a Taiwan experience
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- Design a commission plan that drives sales - Sales Commissions
- Too Young to Rent a Car? - 25-years-old the minimum age for car renting - Brief Article
- Getting the global view: Nestle, led by Peter Brabeck-Letmathe, climbs to the #1 spot in this year's Best Companies for Leaders



