999精品在线视频,手机成人午夜在线视频,久久不卡国产精品无码,中日无码在线观看,成人av手机在线观看,日韩精品亚洲一区中文字幕,亚洲av无码人妻,四虎国产在线观看 ?

How Phishing Attacks Trick Our Brains網(wǎng)絡(luò)釣魚如何欺騙大腦

2020-02-28 18:50:01帕特里克·豪厄爾·奧尼爾陳偉濟
英語世界 2020年1期

帕特里克·豪厄爾·奧尼爾 陳偉濟

Why youre more of a sucker than you think. 為何你比自己想象的還容易受騙。

Its simple and effective: getting someone to click a malicious link in an email and enter private information such as a password is the most important skill in many hackers toolkits. Phishing1 is the most common form of cyberattack and still growing.

And the reason its so effective, according to research being done at Google and the University of Florida, is that it takes advantage of how the human brain works—and, crucially, how people fail to detect deception, depending on factors like emotional intelligence, cognitive motivation, mood, hormones, and even the victims personality.

“We are all susceptible to phishing because phishing tricks the way our brain makes decisions,” Daniela Oliveira, an associate professor at the University of Florida, said at the Black Hat cybersecurity conference in Las Vegas.

The problems begin with awareness: 45% of internet users dont even know what phishing is, according to Oliveira and Google researcher Elie Bursztein.

Mood plays a role: people who are feeling happy and not stressed are less likely to detect deception in front of them. Cortisol2, a stress hormone, increases vigilance and makes detecting a deception more likely. Serotonin3 and dopamine4, hormones associated with positive feelings, can lead to risky and unpredictable behavior that make people more vulnerable.

Phishers can also be exceptionally good at crafting messages meant to persuade a person to click. Authority is among the most common and effective weapons—for instance, an email that claims to be from the company CEO, asking an employee to provide some information by clicking a link. Other tools include a gain/loss framing—for instance, a refund opportunity from Amazon.

Some of the most pointed phishing emails play on emotion. After the devastating and record-breaking California wildfires in 2018, Google saw an instant wave of emails asking for money to help victims. Emotional cues—for instance, promises to match donations for people left homeless—impaired the recipients ability to focus on the content and the clues that the email was a deception. By triggering this emotional response, the hackers got people to suspend their skepticism.

That doesnt mean the only defense against phishing is to be a permanently stressed-out and cynical ball of anger. Healthier and more effective is to enable two-factor authentication for each of your important logins (email, online banking, social media, shopping sites, etc.). When its enabled, the system asks you for something in addition to a password when you log in, such as a code sent to your phone via text message, a code from an authenticator app, or a physical security key on a USB stick (the most secure method of all, according to recent research). That way, if youve inadvertently given your password to a hacker in a phishing scam, they still wont be able to log in to your account. Last year, Google said that fewer than 10% of its users had two-factor authentication enabled on their accounts.

騙人點擊郵件中的惡意鏈接并輸入密碼等個人信息是很多黑客最拿手的伎倆,這既簡單又有效。網(wǎng)絡(luò)釣魚是最為常見的網(wǎng)絡(luò)攻擊,而且日益嚴(yán)重。

谷歌和佛羅里達(dá)大學(xué)的研究認(rèn)為,其效果之所以如此顯著是因為網(wǎng)絡(luò)釣魚利用了人類的思維模式,最重要的是,利用了影響人們識別詐騙的各種因素,比如情商、認(rèn)知動機、情緒、激素,甚至受害者的人格。

“我們都容易被釣魚,因為網(wǎng)絡(luò)釣魚會欺騙我們大腦的決策機制。”佛羅里達(dá)大學(xué)副教授丹妮拉·奧利韋拉在拉斯維加斯黑帽安全技術(shù)大會上說。

首先是意識問題。奧利韋拉和谷歌研究員埃利·比爾斯坦的研究顯示,45%的互聯(lián)網(wǎng)用戶甚至不知網(wǎng)絡(luò)釣魚為何物。

情緒也有關(guān)系。心情暢快、無憂無慮時,人們識別眼前騙局的可能性更小。腎上腺皮質(zhì)素這種壓力激素能讓人提高警惕,有益于識別詐騙;而使人樂觀開心的血清素和多巴胺則可能導(dǎo)致魯莽冒失行為,讓人更容易上當(dāng)受騙。

網(wǎng)絡(luò)釣魚黑客還特別善于編造虛假信息來說服人點擊鏈接。權(quán)威性是最常用、最有效的武器之一,比如一封聲稱來自公司CEO的郵件,要求員工通過點擊鏈接提供某些信息。其他手段包括獲利或損失騙局設(shè)計,比如亞馬遜的退款機會。

有些針對性很強的釣魚郵件欺騙人們的感情。2018年爆發(fā)加利福尼亞史上破壞性最強的野火之后,谷歌注意到短時間內(nèi)出現(xiàn)了一大波為受害者募捐的郵件。情感的暗示——比如承諾將捐款撥發(fā)給無家可歸的人——削弱了收件人的注意力,使其未能關(guān)注郵件內(nèi)容和表明郵件是騙局的各種線索。通過激發(fā)這種情感反應(yīng),黑客讓人忘卻了疑慮。

但這并不意味著防范網(wǎng)絡(luò)釣魚的唯一方法是永遠(yuǎn)憂心忡忡、滿腔怒火。把每一個重要登錄(郵箱、網(wǎng)上銀行、社交媒體、購物網(wǎng)站等)設(shè)置成雙重驗證才是更為明智有效的方法。設(shè)置后,登錄時系統(tǒng)會要求輸入除密碼外的其他信息,比如通過短信發(fā)送到手機的驗證碼、來自身份驗證應(yīng)用程序的驗證碼或U盾物理安全密鑰(新近研究認(rèn)為最為安全的方式)。這樣,即使你疏忽大意未識破釣魚騙局把密碼給了黑客,他們也無法登錄你的賬戶。去年,谷歌說,只有不到10%的用戶把自己的賬戶設(shè)置成雙重驗證。

(譯者為“《英語世界》杯”翻譯大賽獲獎?wù)撸?/p>

主站蜘蛛池模板: 国产精品成人观看视频国产 | 国产成人精品男人的天堂下载| 二级特黄绝大片免费视频大片| 国产成人h在线观看网站站| 国产美女91呻吟求| 91精品亚洲| 国产成人精品无码一区二| 91丨九色丨首页在线播放| 久久香蕉欧美精品| 伊人久久精品无码麻豆精品| 国产aⅴ无码专区亚洲av综合网| 激情成人综合网| 亚洲无码高清视频在线观看 | 亚洲免费福利视频| 久久午夜夜伦鲁鲁片无码免费| 女人18毛片水真多国产| 伊在人亚洲香蕉精品播放| 国产午夜人做人免费视频| 99久久国产综合精品2020| 国产高清在线精品一区二区三区 | swag国产精品| 国产真实乱人视频| 国产真实二区一区在线亚洲| 免费观看无遮挡www的小视频| 99re在线视频观看| 在线a网站| 国产网站免费观看| 精品一区二区三区自慰喷水| 精品三级在线| 女高中生自慰污污网站| 日韩黄色精品| 色香蕉网站| Aⅴ无码专区在线观看| 日本高清视频在线www色| 欧美色亚洲| 欧美伊人色综合久久天天| 凹凸国产分类在线观看| 在线观看91香蕉国产免费| 日本三级欧美三级| 日韩欧美中文字幕在线精品| 久久福利片| 熟妇丰满人妻av无码区| 91 九色视频丝袜| 69av在线| 欧美一级特黄aaaaaa在线看片| 亚洲第一天堂无码专区| 精品乱码久久久久久久| 日韩免费视频播播| 国产精品福利在线观看无码卡| 美女视频黄频a免费高清不卡| 国产成人久视频免费| 国产91小视频| 日韩在线播放欧美字幕| 浮力影院国产第一页| 国产乱论视频| 亚洲中文字幕精品| 97国产在线观看| 亚洲无码日韩一区| 亚洲成a∧人片在线观看无码| 国产毛片片精品天天看视频| 日韩精品亚洲一区中文字幕| 精品久久久久久中文字幕女| 色老头综合网| 婷婷色丁香综合激情| 永久免费精品视频| 又大又硬又爽免费视频| 国产在线欧美| 91区国产福利在线观看午夜| 日韩精品资源| 国产在线观看91精品亚瑟| 91久久夜色精品国产网站| 国内精品视频| 免费看a毛片| 91久久青青草原精品国产| 国产va视频| 久久久久国产精品熟女影院| 国内嫩模私拍精品视频| 欧美在线精品一区二区三区| 国产一级α片| 欧美伦理一区| 国产免费一级精品视频 | 无码精品国产VA在线观看DVD|