arrow
Return

A Risk Analysis Framework for Social Engineering Attack Based on User Profiling

delete2020-07-01
delete15
delete
OA
AI
Z
Zi‐Wei Ye *
Y
Yuanbo Guo
A
Ankang Ju
F
Fushan Wei
张瑞杰 cover
张瑞杰 (Ruijie Zhang)
J
Jun Ma
DOI:10.4018/JOEUC.2020070104delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Social engineering attacks are becoming serious threats to cloud service. Social engineering attackers could get Cloud service custom privacy information or attack virtual machine images directly. Existing security analysis instruments are difficult to quantify the social engineering attack risk, resulting in invalid defense guidance for social engineering attacks. In this article, a risk analysis framework for social engineering attack is proposed based on user profiling. The framework provides a pathway to quantitatively calculate the possibility of being compromised by social engineering attack and potential loss, so as to effectively complement current security assessment instruments. The frequency of related operations is used to profile and group users for respective risk calculation, and other features such as security awareness and capability of protection mechanism are also considered. Finally, examples are given to illustrate how to use the framework in actual scenario and apply it to security assessment.
Keywords:
Authority
Cloud Security
Network Security Assessment
Operating Frequency
Risk Analysis
Social Engineering
User Profiling
Vulnerability
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Organizational and End User Computing cover
Journal of Organizational and End User Computing
IF:
3.4
Papers:
561
Citations:
1.2K

Organization

P
pla information engineering university
Scholars:
2.8K
Papers: 1.6K
Citations: 2