Introduction to URL Destination Perception and UI Design Challenges

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/21

flashcard set

Earn XP

Description and Tags

Flashcards based on the lecture notes regarding the empirical study of URL structures, user comprehension, and the difficulties of preventing phishing through UI design.

Last updated 4:47 AM on 8/18/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

22 Terms

1
New cards

URL Destination Problem

A design challenge where users are unable to accurately understand where a link leads based on the URL structure, often exploited in phishing attacks.

2
New cards

FBI Phishing Losses (20172017)

A reported total of over 29,000,00029,000,000 in United States financial losses due to phishing in the year 20172017.

3
New cards

poll poll pollman

An entity that estimated phishing incidents cost over 2,000,0002,000,000 per incident in the UK.

4
New cards

Spear Phishing Attacks on Google and Facebook

Specific targeted attacks that resulted in losses of approximately 100,000,000100,000,000 for these major organizations.

5
New cards

Top level domain

The rightmost part of a URL, such as .com.com, which indicates the highest level in the hierarchical domain name system.

6
New cards

Domain

The portion of a URL that identifies the actual site owner, situated to the left of the top level domain, such as mobile\text{mobile} in the URL facebook.mobile.com\text{facebook.mobile.com}.

7
New cards

Sub domain

A specific section of a larger domain, such as Facebook\text{Facebook} in facebook.mobile.com\text{facebook.mobile.com}, which is owned by the proprietor of the main domain.

8
New cards

Brand-first bias

A psychological tendency where 32.9%32.9\% of users assume a familiar brand name identifies the destination, regardless of its position in the URL structure.

9
New cards

incroom and suffering

Two browsers mentioned in the transcript as providing post-click supports through features like domain highlighting.

10
New cards

AMT and prolific

The two platforms used by researchers to recruit 5050 participants each for pre-studies on brand familiarity.

11
New cards

TrapBody and Pew Point

Examples of real organizations used in the study that participants were found to be very unfamiliar with.

12
New cards

Likert scale

A five-point response system used by researchers to measure users' perceptions of URL safety, providing a wider range of responses than simple yes/no questions.

13
New cards

Pure domain URLs

Simple structures like microsoft.com\text{microsoft.com} used as a baseline in the empirical evaluation of URL rating accuracy.

14
New cards

Latent class analysis

An advanced statistical method used to group participants into categories like power users, desktop users, and mobile users by combining multiple measures of technical skills.

15
New cards

Generalized line of mixed model

A statistical tool used to analyze prediction accuracy while accounting for participant differences and interactions with different URL structures.

16
New cards

Proportional logistic regression

The specific statistical method employed to analyze ordered data from the five-point safety ratings.

17
New cards

Power users

The most technically experienced user group who achieved only a 25%25\% accuracy rate in reading URLs when the organization name was in the sub domain.

18
New cards

Desktop users

A user group categorized by technical experience that achieved a 20%20\% accuracy rate in the URL reading study.

19
New cards

Mobile users

The user group with the lowest technical experience scores, achieving a 15.9%15.9\% accuracy rate in predicting URL destinations.

20
New cards

URL shorteners

Services like bit.ly that create links where the true destination is entirely hidden until the actual redirect happens.

21
New cards

Type of squatting

A phishing method using deceptive characters, such as Google with 3 os\text{Google with 3 os} or Cyrillic symbols such as the Russian e\text{e}, to imitate legitimate domains.

22
New cards

Certificate

Digital documentation that facilitates a TLS connection and can bind an organization's identity to a specific site.