999精品在线视频,手机成人午夜在线视频,久久不卡国产精品无码,中日无码在线观看,成人av手机在线观看,日韩精品亚洲一区中文字幕,亚洲av无码人妻,四虎国产在线观看 ?

How Phishing Attacks Trick Our Brains網絡釣魚如何欺騙大腦

2020-02-28 18:50:01帕特里克·豪厄爾·奧尼爾陳偉濟
英語世界 2020年1期

帕特里克·豪厄爾·奧尼爾 陳偉濟

Why youre more of a sucker than you think. 為何你比自己想象的還容易受騙。

Its simple and effective: getting someone to click a malicious link in an email and enter private information such as a password is the most important skill in many hackers toolkits. Phishing1 is the most common form of cyberattack and still growing.

And the reason its so effective, according to research being done at Google and the University of Florida, is that it takes advantage of how the human brain works—and, crucially, how people fail to detect deception, depending on factors like emotional intelligence, cognitive motivation, mood, hormones, and even the victims personality.

“We are all susceptible to phishing because phishing tricks the way our brain makes decisions,” Daniela Oliveira, an associate professor at the University of Florida, said at the Black Hat cybersecurity conference in Las Vegas.

The problems begin with awareness: 45% of internet users dont even know what phishing is, according to Oliveira and Google researcher Elie Bursztein.

Mood plays a role: people who are feeling happy and not stressed are less likely to detect deception in front of them. Cortisol2, a stress hormone, increases vigilance and makes detecting a deception more likely. Serotonin3 and dopamine4, hormones associated with positive feelings, can lead to risky and unpredictable behavior that make people more vulnerable.

Phishers can also be exceptionally good at crafting messages meant to persuade a person to click. Authority is among the most common and effective weapons—for instance, an email that claims to be from the company CEO, asking an employee to provide some information by clicking a link. Other tools include a gain/loss framing—for instance, a refund opportunity from Amazon.

Some of the most pointed phishing emails play on emotion. After the devastating and record-breaking California wildfires in 2018, Google saw an instant wave of emails asking for money to help victims. Emotional cues—for instance, promises to match donations for people left homeless—impaired the recipients ability to focus on the content and the clues that the email was a deception. By triggering this emotional response, the hackers got people to suspend their skepticism.

That doesnt mean the only defense against phishing is to be a permanently stressed-out and cynical ball of anger. Healthier and more effective is to enable two-factor authentication for each of your important logins (email, online banking, social media, shopping sites, etc.). When its enabled, the system asks you for something in addition to a password when you log in, such as a code sent to your phone via text message, a code from an authenticator app, or a physical security key on a USB stick (the most secure method of all, according to recent research). That way, if youve inadvertently given your password to a hacker in a phishing scam, they still wont be able to log in to your account. Last year, Google said that fewer than 10% of its users had two-factor authentication enabled on their accounts.

騙人點擊郵件中的惡意鏈接并輸入密碼等個人信息是很多黑客最拿手的伎倆,這既簡單又有效。網絡釣魚是最為常見的網絡攻擊,而且日益嚴重。

谷歌和佛羅里達大學的研究認為,其效果之所以如此顯著是因為網絡釣魚利用了人類的思維模式,最重要的是,利用了影響人們識別詐騙的各種因素,比如情商、認知動機、情緒、激素,甚至受害者的人格。

“我們都容易被釣魚,因為網絡釣魚會欺騙我們大腦的決策機制。”佛羅里達大學副教授丹妮拉·奧利韋拉在拉斯維加斯黑帽安全技術大會上說。

首先是意識問題。奧利韋拉和谷歌研究員埃利·比爾斯坦的研究顯示,45%的互聯網用戶甚至不知網絡釣魚為何物。

情緒也有關系。心情暢快、無憂無慮時,人們識別眼前騙局的可能性更小。腎上腺皮質素這種壓力激素能讓人提高警惕,有益于識別詐騙;而使人樂觀開心的血清素和多巴胺則可能導致魯莽冒失行為,讓人更容易上當受騙。

網絡釣魚黑客還特別善于編造虛假信息來說服人點擊鏈接。權威性是最常用、最有效的武器之一,比如一封聲稱來自公司CEO的郵件,要求員工通過點擊鏈接提供某些信息。其他手段包括獲利或損失騙局設計,比如亞馬遜的退款機會。

有些針對性很強的釣魚郵件欺騙人們的感情。2018年爆發加利福尼亞史上破壞性最強的野火之后,谷歌注意到短時間內出現了一大波為受害者募捐的郵件。情感的暗示——比如承諾將捐款撥發給無家可歸的人——削弱了收件人的注意力,使其未能關注郵件內容和表明郵件是騙局的各種線索。通過激發這種情感反應,黑客讓人忘卻了疑慮。

但這并不意味著防范網絡釣魚的唯一方法是永遠憂心忡忡、滿腔怒火。把每一個重要登錄(郵箱、網上銀行、社交媒體、購物網站等)設置成雙重驗證才是更為明智有效的方法。設置后,登錄時系統會要求輸入除密碼外的其他信息,比如通過短信發送到手機的驗證碼、來自身份驗證應用程序的驗證碼或U盾物理安全密鑰(新近研究認為最為安全的方式)。這樣,即使你疏忽大意未識破釣魚騙局把密碼給了黑客,他們也無法登錄你的賬戶。去年,谷歌說,只有不到10%的用戶把自己的賬戶設置成雙重驗證。

(譯者為“《英語世界》杯”翻譯大賽獲獎者)

主站蜘蛛池模板: 久久精品亚洲热综合一区二区| 日本高清视频在线www色| 亚洲福利片无码最新在线播放| av色爱 天堂网| 伊人色综合久久天天| 国产区91| 成AV人片一区二区三区久久| 午夜欧美在线| 99re视频在线| 亚洲一区色| 国产午夜一级毛片| 国产亚卅精品无码| 久久一日本道色综合久久| 91丝袜在线观看| 美女高潮全身流白浆福利区| 女人18毛片一级毛片在线| 日本午夜网站| 中文天堂在线视频| 免费国产高清精品一区在线| 国产精品亚洲αv天堂无码| 久久青草热| 亚洲国产日韩视频观看| 麻豆国产原创视频在线播放| 欧美成人综合在线| 亚洲日韩图片专区第1页| 国产精品熟女亚洲AV麻豆| 精品久久人人爽人人玩人人妻| 午夜三级在线| 色偷偷综合网| 亚洲男人天堂2020| 91麻豆国产视频| 99久久国产自偷自偷免费一区| 国产区免费精品视频| 中国一级毛片免费观看| 久久国产精品娇妻素人| 久久久久久久久18禁秘| 日韩亚洲高清一区二区| 性69交片免费看| 青草国产在线视频| 国产精品第页| 2020国产免费久久精品99| 国产精品第页| 草草影院国产第一页| 亚洲第一天堂无码专区| 久久久久国产精品免费免费不卡| 免费无遮挡AV| 免费观看无遮挡www的小视频| 国产精品无码翘臀在线看纯欲| 亚洲视频在线观看免费视频| 91色在线观看| 色婷婷电影网| 亚洲欧洲国产成人综合不卡| 熟女日韩精品2区| 国产门事件在线| 日韩a级片视频| 久久精品人人做人人综合试看| 免费A级毛片无码无遮挡| 国产精品久久自在自线观看| 亚洲国产中文精品va在线播放| 亚洲人成网7777777国产| 国产色网站| 18禁不卡免费网站| 亚洲an第二区国产精品| 波多野结衣一二三| 在线五月婷婷| 中文字幕精品一区二区三区视频 | 国产丝袜啪啪| 影音先锋丝袜制服| 狠狠色成人综合首页| 亚洲精品不卡午夜精品| 中文字幕啪啪| 国产v精品成人免费视频71pao| 99久久精品国产自免费| 乱人伦中文视频在线观看免费| 99热这里只有精品在线播放| 色窝窝免费一区二区三区| 999国内精品视频免费| 国产亚洲精品自在线| 国产va欧美va在线观看| 亚洲欧美在线综合一区二区三区| 欧美成人日韩| 人妻丰满熟妇αv无码|