首页> 外文会议>International Conference on Emerging Technologies >Social engineering: Revisiting end-user awareness and susceptibility to classic attack vectors
【24h】

Social engineering: Revisiting end-user awareness and susceptibility to classic attack vectors

机译:社会工程:重新了解最终用户对经典攻击媒介的认识和敏感性

获取原文

摘要

Social engineering relies on human vulnerability to exploit system security. Social engineering attacks are relatively harder to protect against as they mainly target the user, and not just hardware or software system defenses. End user awareness can be considered as one of the simplest yet most effective ways to protect the end user against social engineering vectors. The present study ascertains the level of user susceptibility to social engineering attacks in a cooperating corporate organization. Two attack scenarios, a spear-phishing campaign and a physical intrusion vector were designed targeting the organization's user population (employees) based on publicly available information from the Internet. Clues relating to social engineering techniques were included in the attacks to alert suspicious users. Despite the revealing signs of a social engineering campaign, the results indicated that a significantly high proportion (46-60%) of the users fell prey and failed to identify the attacks. It was observed that lack of user awareness remained the primary cause of the success of the attacks, requiring corrective action through post-incident training and regular IT security drills.
机译:社会工程学依靠人类的脆弱性来开发系统安全性。社会工程攻击相对较难防御,因为它们主要针对用户,而不仅仅是硬件或软件系统防御。最终用户的意识可以被认为是保护最终用户免受社会工程手段影响的最简单但最有效的方法之一。本研究确定了在合作的公司组织中用户对社会工程攻击的敏感性水平。根据来自Internet的公开信息,针对组织的用户群体(员工)设计了两种攻击方案,鱼叉式网络钓鱼活动和物理入侵媒介。攻击中包含与社会工程技术有关的线索,以提醒可疑用户。尽管有开展社会工程运动的迹象,但结果表明,很大一部分用户(46-60%)沦为猎物,无法识别攻击。据观察,缺乏用户意识仍然是攻击成功的主要原因,因此需要通过事后培训和定期的IT安全演习来采取纠正措施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号