WEKO3
アイテム
クイッシングメール閲覧時のユーザ思考プロセスの解明
https://ipsj.ixsq.nii.ac.jp/records/2007206
https://ipsj.ixsq.nii.ac.jp/records/200720634b65543-cb00-44f6-b27c-1c3358b273a6
| 名前 / ファイル | ライセンス | アクション |
|---|---|---|
|
2028年2月24日からダウンロード可能です。
|
Copyright (c) 2026 by the Information Processing Society of Japan
|
|
| 非会員:¥660, IPSJ:学会員:¥330, SPT:会員:¥0, DLIB:会員:¥0 | ||
| Item type | SIG Technical Reports(1) | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 公開日 | 2026-02-24 | |||||||||||||
| タイトル | ||||||||||||||
| 言語 | ja | |||||||||||||
| タイトル | クイッシングメール閲覧時のユーザ思考プロセスの解明 | |||||||||||||
| タイトル | ||||||||||||||
| 言語 | en | |||||||||||||
| タイトル | Understanding User Cognitive Processes in Quishing Email Interactions | |||||||||||||
| 言語 | ||||||||||||||
| 言語 | jpn | |||||||||||||
| キーワード | ||||||||||||||
| 主題Scheme | Other | |||||||||||||
| 主題 | SPT | |||||||||||||
| 資源タイプ | ||||||||||||||
| 資源タイプ識別子 | http://purl.org/coar/resource_type/c_18gh | |||||||||||||
| 資源タイプ | technical report | |||||||||||||
| 著者所属 | ||||||||||||||
| 早稲田大学 | ||||||||||||||
| 著者所属 | ||||||||||||||
| 早稲田大学 | ||||||||||||||
| 著者所属 | ||||||||||||||
| 早稲田大学/国立研究開発法人産業技術総合研究所 | ||||||||||||||
| 著者所属 | ||||||||||||||
| 早稲田大学/理化学研究所革新知能統合研究センター/国立研究開発法人情報通信研究機構 | ||||||||||||||
| 著者所属(英) | ||||||||||||||
| en | ||||||||||||||
| Waseda University | ||||||||||||||
| 著者所属(英) | ||||||||||||||
| en | ||||||||||||||
| Waseda University | ||||||||||||||
| 著者所属(英) | ||||||||||||||
| en | ||||||||||||||
| Waseda University / AIST | ||||||||||||||
| 著者所属(英) | ||||||||||||||
| en | ||||||||||||||
| Waseda University / RIKEN AIP / NICT | ||||||||||||||
| 著者名 |
高原,祥二郎
× 高原,祥二郎
× 山岸,伶
× 飯島,涼
× 森,達哉
|
|||||||||||||
| 論文抄録 | ||||||||||||||
| 内容記述タイプ | Other | |||||||||||||
| 内容記述 | フィッシング攻撃が深刻化する中,QRコードを悪用したフィッシング(以下,クイッシング)は,既存の検知回避性能と遷移先の不可視性により被害が拡大している.しかし,ユーザの認知過程に関する定性的知見は不十分である.本研究はクイッシングメール閲覧時のユーザの思考プロセスに着目し,誤った判断を引き起こす要因を明らかにすることを目的とした.参加者16名に良性・悪性を含む8通のメールを提示し,ディセプションスタディとシンクアラウド法を用いて詳細な思考過程を記録した.タスク終了後に半構造化インタビューを実施し,主題分析によりデータをコーディングした.結果としてクイッシングの認知不足と知識の欠如による判断の困難化,URLの不可視性による自動化された行動,スキャン後のURL確認ステップの省略といった特徴的な思考プロセスが確認された.得られた結果をもとにスキャンアプリの設計指針,メールソフトウェアおよび教育や事例共有の充実の必要性の示唆を提示した. | |||||||||||||
| 論文抄録(英) | ||||||||||||||
| 内容記述タイプ | Other | |||||||||||||
| 内容記述 | As phishing attacks increase, ”quishing” (QR-code phishing) is spreading rapidly because it can easily bypass standard security filters and hide malicious links from users. Despite this growing threat, insights into user cognitive processes during quishing encounters remain under-explored. This study investigates the factors leading to erroneous security judgments through a deception study with 16 participants. Using the think-aloud method, we analyzed participants' real-time thought processes as they interacted with eight benign and malicious emails, followed by semi-structured interviews and thematic analysis. We identified three key cognitive patterns leading to errors: 1. Low awareness hindering threat judgment. 2. Hidden URLs triggering automated actions. 3. Lack of verification after scanning the code. Based on these insights, we discuss implications for the design of QR-code applications, email clients and user education, including the sharing of real-world quishing examples. | |||||||||||||
| 書誌レコードID | ||||||||||||||
| 収録物識別子タイプ | NCID | |||||||||||||
| 収録物識別子 | AA12628305 | |||||||||||||
| 書誌情報 |
研究報告セキュリティ心理学とトラスト(SPT) 巻 2026-SPT-62, 号 5, p. 1-8, 発行日 2026-02-24 |
|||||||||||||
| ISSN | ||||||||||||||
| 収録物識別子タイプ | ISSN | |||||||||||||
| 収録物識別子 | 2188-8671 | |||||||||||||
| Notice | ||||||||||||||
| SIG Technical Reports are nonrefereed and hence may later appear in any journals, conferences, symposia, etc. | ||||||||||||||
| 出版者 | ||||||||||||||
| 言語 | ja | |||||||||||||
| 出版者 | 情報処理学会 | |||||||||||||