首页> 外文会议>Conference on Signal Processing, Sensor/Information Fusion, and Target Recognition >Long lasting effects of awareness training methods on reducing overall cyber security risk
【24h】

Long lasting effects of awareness training methods on reducing overall cyber security risk

机译:意识训练方法对减少整体网络安全风险的持久影响

获取原文

摘要

Social Engineering holds one of the most critical threats to public and private organizations. In this paper we focus onphishing threats by measuring the positive impact that awareness methods may provide to them in a long-term period tocompanies and public bodies. The assessment criterion uses two phishing attacks in a period of 18 weeks. The phishingattack comprises a hook mail containing a link to a credentials harvesting website. Users’ reaction and user agentfingerprints are used in order to calculate a risk score for each victim. By applying chi square – tests it was found thatthere is a statistically significant score improvement for participants that were trained via the awareness methods.Furthermore, a risk analysis is conducted to identify, quantify and prioritize potential risks that could negatively affectthe end-user’s operations. The main idea concerning this proposed technique is the fact that the assessment methods canassist the employees to develop skills and abilities in order to use the digital world safely, avoiding phishing attacks. Therisk analysis findings indicate that the awareness approach has significant improvement in long term lasting riskreduction. The study was conducted as part of the European Horizon 2020 DOGANA project which aims to deployeffective mitigation strategies and lead to reduce the risk created by modern Social Engineering 2.0 attack techniques.The results obtained in this paper corroborate the results obtained by the EU funded project SAINT from theeconometric analysis and modeling of the cybercrime and cyber security markets.
机译:社会工程持有公共和私人组织最关键的威胁之一。在本文中,我们专注于通过测量意识方法可以在长期期间向他们提供的积极影响来挑逗威胁公司和公共机构。评估标准在18周的时间内使用两个网络钓鱼攻击。网络钓鱼攻击包括包含收集网站凭据的链接的钩邮件。用户反应和用户代理使用指纹以计算每个受害者的风险分数。通过应用Chi Square - 测试发现通过提高认识方法培训的参与者存在统计上显着的分数改进。此外,进行风险分析以识别,量化和优先考虑可能产生负面影响的潜在风险最终用户的操作。关于这种提出的技术的主要观点是评估方法可以协助员工培养技能和能力,以便安全地使用数字世界,避免网络钓鱼攻击。这风险分析结果表明,意识方法在长期持久风险方面具有显着改善减少。该研究是作为欧洲地平线2020 Dogana项目的一部分进行的,旨在部署有效的缓解策略,导致减少现代社会工程2.0攻击技术创造的风险。本文获得的结果证实了由欧盟资助的项目获得的结果网络犯罪和网络安全市场的计量经济分析与建模。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号