首页> 外文会议>SAI Computing Conference >A layered defense mechanism for a social engineering aware perimeter
【24h】

A layered defense mechanism for a social engineering aware perimeter

机译:社会工程意识围绕的分层防御机制

获取原文

摘要

While many cyber security organizations urge the corporate world to use defence-in-depth to create vigilant network perimeters, the human factor is often overlooked. Security evaluation frameworks focus mostly on critical assets of an organization and technical aspects of prevailing risks. There is consequently no specific framework to identify, categorize, analyse and mitigate social engineering related risks. This paper identifies the requirement for such a framework through an in-depth investigation of an actual organization and extensive analysis of existing methodologies. On the basis of this a layered defence strategy SERA is developed, starting with the basic building blocks for social-engineering aware risk analysis. A chronological attack classification framework is presented as an enhancement of existing frameworks on social engineering.
机译:虽然许多网络安全组织敦促企业界使用防御深度来创造警惕网络跨度,但人类因素往往被忽视。安全评估框架主要关注普遍风险的组织和技术方面的关键资产。因此,没有具体框架可以识别,分类,分析和缓解社会工程相关风险。本文通过深入调查实际组织和对现有方法的广泛分析,确定了这种框架的要求。在此基础上,从社会工程意识风险分析的基本构建块开始开发了层次的防御策略。按时间顺序攻击分类框架作为在社会工程上的现有框架的增强。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号