Close

Presentation

Do Default Effects Shape Cyber Attack Decisions? Lessons from an Empirical Study
DescriptionUnderstanding the cognitive biases involved in cyber attacker behavior can help develop countermeasures which leverage predictable mental shortcuts. This paper analyzes the impact of one of such biases: default effect, on decisions in the context of cyber attacks. Three types of this bias are explicit defaults, association effects, and position effects. The research involved an experiment that included 85 participants who displayed cybersecurity knowledge based on a screening assessment performed prior to participation. The subjects performed established behavioral tasks as well as cyber-adapted scenarios concerning choosing the right host, selecting appropriate ports, and selecting a password for spraying attempts. Our experimental findings revealed that explicit defaults mimic the traditional behavioral principles as the opt-out approach increased compliance significantly more than the opt-in approach. For cyber tasks, the association effect was found to be always present and extremely influential on participant decisions, whereas participants preferred those options that were semantically related to the contextual cues provided. In contrast, position effects failed to emerge if there were semantically meaningful cues available. The results offer us actionable insights on how to design cyber deception systems that leverage predictable attacker heuristics.