返回
A Session and Dialogue-Based Social Engineering Framework
DOI:10.1109/ACCESS.2019.2919150.png)
摘要
En 中文
Social engineering has been increasingly used during the past few years. Social engineering attacks have resulted in great financial losses. Research on social engineering models and frameworks is still in its elementary stage. An appropriate social engineering framework can interpret all the attack components and their relationships clearly, which will contribute to the defense of social engineering attacks. In this tutorial paper, existing social engineering models and frameworks are summarized and a new social engineering framework is proposed involving the concept of the session and dialogue. An entire social engineering attack is defined as a social engineering session (SES). A social engineering dialogue (SED) refers to a specific attack phase, which is included in a SES. A SES contains several well-organized SEDs. Then, the attack graph is used to formalize the proposed social engineering framework. The SED is treated as an atomic attack during the whole SES. The human weaknesses that an attacker can exploit are described as vulnerabilities, the information, and trust that an attacker owns as permissions. Finally, three real-world social engineering cases are analyzed using the proposed framework and attack graph. The analyses illustrate the usability of the proposed framework and provide a better understanding of various social engineering attacks.
Keyword:
Social engineering
social engineering session (SES)
social engineering dialogue (SED)
attack graph
information security
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
Shaping intention to resist social engineering through transformational leadership, information security culture and awareness
COMPUTERS & SECURITY
IF5.4
A Study on Learning Activities in Korean Textbooks on the Sociocultural Perspective of Communication
Phishlimiter: A Phishing Detection and Mitigation Approach Using Software-Defined NetworkingPhishlimiter: 使用软件定义网络的网络钓鱼检测和缓解方法
IEEE ACCESS
IF3.6
Mind your SMSes: Mitigating social engineering in second factor authentication
COMPUTERS & SECURITY
IF5.4

