{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T00:17:23Z","timestamp":1780359443386,"version":"3.54.1"},"reference-count":45,"publisher":"SAGE Publications","issue":"4","license":[{"start":{"date-parts":[[2017,1,6]],"date-time":"2017-01-06T00:00:00Z","timestamp":1483660800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"funder":[{"DOI":"10.13039\/100007703","name":"North Carolina State University","doi-asserted-by":"publisher","award":["402836"],"award-info":[{"award-number":["402836"]}],"id":[{"id":"10.13039\/100007703","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Hum Factors"],"published-print":{"date-parts":[[2017,6]]},"abstract":"<jats:sec>\n                    <jats:title>Objective:<\/jats:title>\n                    <jats:p>To evaluate the effectiveness of domain highlighting in helping users identify whether Web pages are legitimate or spurious.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Background:<\/jats:title>\n                    <jats:p>As a component of the URL, a domain name can be overlooked. Consequently, browsers highlight the domain name to help users identify which Web site they are visiting. Nevertheless, few studies have assessed the effectiveness of domain highlighting, and the only formal study confounded highlighting with instructions to look at the address bar.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Method:<\/jats:title>\n                    <jats:p>We conducted two phishing detection experiments. Experiment 1 was run online: Participants judged the legitimacy of Web pages in two phases. In Phase 1, participants were to judge the legitimacy based on any information on the Web page, whereas in Phase 2, they were to focus on the address bar. Whether the domain was highlighted was also varied. Experiment 2 was conducted similarly but with participants in a laboratory setting, which allowed tracking of fixations.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Results:<\/jats:title>\n                    <jats:p>Participants differentiated the legitimate and fraudulent Web pages better than chance. There was some benefit of attending to the address bar, but domain highlighting did not provide effective protection against phishing attacks. Analysis of eye-gaze fixation measures was in agreement with the task performance, but heat-map results revealed that participants\u2019 visual attention was attracted by the highlighted domains.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Conclusion:<\/jats:title>\n                    <jats:p>Failure to detect many fraudulent Web pages even when the domain was highlighted implies that users lacked knowledge of Web page security cues or how to use those cues.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Application:<\/jats:title>\n                    <jats:p>Potential applications include development of phishing prevention training incorporating domain highlighting with other methods to help users identify phishing Web pages.<\/jats:p>\n                  <\/jats:sec>","DOI":"10.1177\/0018720816684064","type":"journal-article","created":{"date-parts":[[2017,1,7]],"date-time":"2017-01-07T11:18:44Z","timestamp":1483787924000},"page":"640-660","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":30,"title":["Is Domain Highlighting Actually Helpful in Identifying Phishing Web Pages?"],"prefix":"10.1177","volume":"59","author":[{"given":"Aiping","family":"Xiong","sequence":"first","affiliation":[{"name":"Purdue University, West Lafayette, Indiana"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Robert W.","family":"Proctor","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, Indiana"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weining","family":"Yang","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, Indiana"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ninghui","family":"Li","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, Indiana"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"179","published-online":{"date-parts":[[2017,1,6]]},"reference":[{"key":"bibr1-0018720816684064","unstructured":"Aaron G., Rasmussen R., Routt A. (2014). Global phishing survey: Trends and domain name use in 2h2013. Retrieved from http:\/\/docs.apwg.org\/reports\/APWG_GlobalPhishingSurvey_2H2013.pdf"},{"key":"bibr2-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/2435349.2435362"},{"key":"bibr3-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.198"},{"key":"bibr4-0018720816684064","unstructured":"Bright P. (2011a). Another fraudulent certificate raises the same old questions about certificate authorities. Retrieved from http:\/\/arstechnica.com\/security\/2011\/08\/earlier-this-year-an-iranian\/"},{"key":"bibr5-0018720816684064","unstructured":"Bright P. (2011b). Independent Iranian hacker claims responsibility for Comodo hack. Retrieved from http:\/\/arstechnica.com\/security\/2011\/03\/independent-iranian-hacker-claims-responsibility-for-comodo-hack\/"},{"key":"bibr6-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1177\/0018720816665025"},{"key":"bibr7-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1456424.1456434"},{"key":"bibr8-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1016\/j.apergo.2013.10.005"},{"key":"bibr9-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1073001.1073009"},{"key":"bibr10-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1124772.1124861"},{"key":"bibr11-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1143120.1143131"},{"key":"bibr12-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1299015.1299019"},{"key":"bibr13-0018720816684064","volume-title":"Eye tracking methodology: Theory and practice","author":"Duchowski A.","year":"2007"},{"key":"bibr14-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/2702123.2702442"},{"key":"bibr15-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242660"},{"key":"bibr16-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2006.50"},{"key":"bibr17-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2005.11.004"},{"key":"bibr18-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1023\/B:GRUP.0000021839.04093.5d"},{"key":"bibr19-0018720816684064","unstructured":"Herzberg A., Gbara A. (2004). Trustbar: Protecting (even naive) Web users from spoofing and phishing attacks (Cryptology ePrint Archive Report 2004\/155). Retrieved from http:\/\/eprint.iacr.org\/2004\/155."},{"key":"bibr20-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1290958.1290968"},{"key":"bibr21-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1207\/s15516709cog2503_2"},{"key":"bibr22-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2013.032213.00009"},{"key":"bibr23-0018720816684064","volume-title":"A real-word evaluation of anti-phishing training","author":"Kumaraguru P.","year":"2009"},{"key":"bibr24-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1978942.1979244"},{"key":"bibr25-0018720816684064","doi-asserted-by":"publisher","DOI":"10.4324\/9781410611147"},{"key":"bibr26-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1037\/0033-2909.98.1.185"},{"key":"bibr27-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1016\/j.apergo.2013.05.008"},{"key":"bibr28-0018720816684064","unstructured":"Microsoft Inc. (2007). Microsoft Security Bulletin MS01-017: Erroneous VeriSign-issued digital certificates pose spoofing hazard. Retrieved from https:\/\/support.microsoft.com\/en-us\/kb\/293818."},{"key":"bibr29-0018720816684064","doi-asserted-by":"crossref","unstructured":"Miyamoto D., Iimura T., Blanc G., Tazaki H., Kadobayashi Y. (2014). EyeBit: Eye-tracking approach for enforcing phishing prevention habits. In Proceedings of the 3rd International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS). Retrieved from http:\/\/www.necoma-project.eu\/m\/filer_public\/d2\/46\/d24651e7-1f35-4846-b8c3-52f3d941a58e\/miyamoto-badgers2014.pdf","DOI":"10.1109\/BADGERS.2014.14"},{"key":"bibr30-0018720816684064","unstructured":"Netcraft. (2013). Phishing alerts for SSL certificate authorities. Retrieved from http:\/\/www.netcraft.com\/anti-phishing\/certificate-authority-phishing-alerts\/"},{"key":"bibr31-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813660"},{"key":"bibr32-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1029533.1029577"},{"key":"bibr33-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.02.008"},{"key":"bibr34-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1177\/0018720815585906"},{"key":"bibr35-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1080\/17470210902816461"},{"key":"bibr36-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/355112.355131"},{"key":"bibr37-0018720816684064","unstructured":"Sheng S., Wardman B., Warner G., Cranor L. F., Hong J., Zhang C. (2009). An empirical analysis of phishing blacklists. In Proceedings of the 6th Conference on Email and Anti-Spam, CEAS\u201909. Retrieved from http:\/\/repository.cmu.edu\/cgi\/viewcontent.cgi?article=1286&context=hcii"},{"key":"bibr38-0018720816684064","volume-title":"Eyelink 1000 user\u2019s manual","author":"SR Research","year":"2009"},{"key":"bibr39-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2007.437"},{"key":"bibr40-0018720816684064","first-page":"399","volume-title":"Proceedings of the USENIX Security Symposium","author":"Sunshine J.","year":"2009"},{"key":"bibr41-0018720816684064","doi-asserted-by":"publisher","DOI":"10.4018\/IJCBPL.2015100101"},{"key":"bibr42-0018720816684064","first-page":"137","volume-title":"Proceedings of Graphics Interface 2005","author":"Whalen T.","year":"2005"},{"key":"bibr43-0018720816684064","unstructured":"Whittaker C., Ryner B., Nazif M. (2010). Large-scale automatic classification of phishing pages. In Proceedings of the Network and Distributed System Security Symposium, NDSS 2010. Retrieved from https:\/\/www.isoc.org\/isoc\/conferences\/ndss\/10\/pdf\/08.pdf"},{"key":"bibr44-0018720816684064","doi-asserted-by":"publisher","DOI":"10.4018\/jthi.2008010105"},{"key":"bibr45-0018720816684064","doi-asserted-by":"publisher","DOI":"10.1145\/1124772.1124863"}],"container-title":["Human Factors: The Journal of the Human Factors and Ergonomics Society"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0018720816684064","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0018720816684064","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0018720816684064","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T07:51:18Z","timestamp":1777449078000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0018720816684064"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,1,6]]},"references-count":45,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2017,6]]}},"alternative-id":["10.1177\/0018720816684064"],"URL":"https:\/\/doi.org\/10.1177\/0018720816684064","relation":{},"ISSN":["0018-7208","1547-8181"],"issn-type":[{"value":"0018-7208","type":"print"},{"value":"1547-8181","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,1,6]]}}}