首页> 外文会议>International Conference on Cyber Warfare and Security >An Examination in Social Engineering: The Susceptibility of Disclosing Private Security Information in College Students
【24h】

An Examination in Social Engineering: The Susceptibility of Disclosing Private Security Information in College Students

机译:社会工程审查 - 披露大学生私人安全信息的易感性

获取原文

摘要

While security technology can be nearly impenetrable, the people behind the computer screens are often easily manipulated, which makes the human factor the biggest threat to cybersecurity. This study examined whether college students disclosed private information about themselves, and what type of information they shared. The study utilized pretexting, in which attackers impersonate individuals in certain roles and often involves extensive research to ensure credibility. The goal of pretexting is to create situations where individuals feel safe releasing information that they otherwise might not. The pretexts used for this study were based on the natural inclination to help, where people tend to want to help those in need, and reciprocity, where people tend to return favors given to them. Participants (N=51) answered survey questions that they thought were for a good cause or that would result in a reward. This survey asked for increasingly sensitive information that could be used maliciously to gain access to identification, passwords, or security questions. Upon completing the survey, participants were debriefed on the true nature of the study and were interviewed about why they were willing to share information via the survey. Some of the most commonly skipped questions included "Student ID number" and "What is your mother's maiden name?". General themes identified from the interviews included the importance of similarities between the researcher and the subject, the researcher's adherence to the character role, the subject's awareness of question sensitivity, and the overall differences between online and offline disclosure. Findings suggest that college students are more likely to disclose private information if the attacker shares a similar trait with the target or if the attacker adheres to the character role they are impersonating. Additionally, this study sheds light on the research limitations, emphasizes the relevance of the human factor in security and privacy, and offers recommendations for future research.
机译:虽然安全技术几乎不可能力,但是计算机屏幕背后的人往往很容易被操纵,这使得人类对网络安全的最大威胁。本研究审查了大学生是否披露了有关自己的私人信息,以及他们共享的信息类型。该研究利用预言,其中攻击者在某些角色中冒充个体,并且通常涉及广泛的研究,以确保可信度。前言的目标是在个人感到安全释放信息的情况下创造局面。用于本研究的借口基于自然的帮助,人们倾向于帮助有需要的人和互惠性,人们倾向于返回给他们的利益。参与者(n = 51)回答了他们认为是一个很好的事业的调查问题,或者会导致奖励。这项调查询问了越来越敏感的信息,可以恶意使用,以获得识别,密码或安全问题。完成调查后,参与者对研究的真实性质进行了汇报,并接受了他们愿意通过调查分享信息的原因。一些最常用的问题包括“学生证号码”和“你母亲的娘家姓名是什么?”。从面试中确定的一般主题包括研究人员与主题之间相似性的重要性,研究人员坚持性格角色,主题对问题敏感性的认识,以及在线和离线披露之间的总体差异。调查结果表明,如果攻击者与目标共享类似的特质,或者攻击者坚持他们冒充的角色角色,那么大学生更有可能披露私人信息。此外,这项研究揭示了研究限制,强调人类因素在安全和隐私方面的相关性,并为未来的研究提供了建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号