首页> 外文会议>International Workshop on Security in Information Systems >Towards a Social Engineering Test Framework
【24h】

Towards a Social Engineering Test Framework

机译:走向社会工程测试框架

获取原文

摘要

A growing number of hacking attacks use social engineering techniques to exploit the human factor of computer systems. They include versatile sophisticated approaches like reciprocity, authority or manipulation techniques to capitalize on in general positives of humans such as helpfulness. These attacking techniques are used in the private as well as in the business context. In the latter they form a main tool for industrial espionage. While there exist evaluation standards for security critical software and hardware as well as their operational environment, due to our knowledge there is no evaluation standard available in order to evaluate vulnerability of organizations with respect to social engineering. This paper will present a framework to evaluate this kind of vulnerability. This framework includes white-box as well as black-box tests. The framework enables organizations to elaborate the level of resistance as well as to identify concrete vulnerabilities. These can be used to implement concrete measures to improve the situation, i.e. the level of resistance.
机译:越来越多的黑客攻击利用社会工程技术利用计算机系统的人类因素。它们包括多才多艺的复杂方法,如互惠,权威或操纵技术,以利用人类的普遍性,如乐于助人。这些攻击技术用于私人以及业务环境中。在后者中,他们形成了工业间谍的主要工具。虽然存在安全性关键软件和硬件以及其操作环境的评估标准,但由于我们的知识,没有可用的评估标准,以便在社会工程方面评估组织的脆弱性。本文将提出一个评估这种漏洞的框架。此框架包括白盒以及黑匣子测试。该框架使组织能够详细说明阻力水平以及识别具体漏洞。这些可用于实施具体措施,以改善情况,即抵抗程度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号