首页> 外文会议>International conference on information resources management: managing IT in a consumerized IT world >Countermeasures for Social Engineering-based Malware Installation Attacks
【24h】

Countermeasures for Social Engineering-based Malware Installation Attacks

机译:基于社会工程的恶意软件安装攻击的对策

获取原文
获取原文并翻译 | 示例

摘要

Social engineering exploits vulnerabilities at different layers (i.e. technical, social layer) in an organizational defense structure. It is therefore important to understand how to defend against these attacks using a holistic defense approach including multiple countermeasures. The literature suggests a plethora of countermeasures, little research has however been done to assess their effectiveness in managing social engineering threats. In this paper we attempt to obtain a deeper understanding of how to defend against a type of social engineering attack that attempts to install malware on computers through e-mail or portable media. We explore commonly proposed countermeasures needed to prevent this type of attack, and if any dependencies between them exist. Through a combined method approach of surveying the literature and conducting semi-structured interviews with domain experts we identified a set of countermeasures that provide empirical input for future studies but could potentially also give organizations guidance on how to manage social engineering-based malware installation attacks.
机译:社交工程利用组织防御结构中不同层(即技术层,社会层)的漏洞。因此,重要的是要了解如何使用包括多种对策在内的整体防御方法来防御这些攻击。文献提出了许多对策,但是,很少有研究评估其对付社会工程威胁的有效性。在本文中,我们试图对如何防御试图通过电子邮件或便携式媒体在计算机上安装恶意软件的一种社会工程学攻击获得更深入的了解。我们探讨了为防止这种类型的攻击以及它们之间是否存在任何依赖关系而提出的通常提出的对策。通过调查文献并与领域专家进行半结构式访谈的组合方法,我们确定了一套对策,这些对策可为将来的研究提供经验输入,但也可能为组织提供有关如何管理基于社会工程学的恶意软件安装攻击的指南。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号