首页> 外文会议>AAAI Conference on Artificial Intelligence;Innovative Applications of Artificial Intelligence Conference >Draining the Water Hole: Mitigating Social Engineering Attacks with CyberTWEAK
【24h】

Draining the Water Hole: Mitigating Social Engineering Attacks with CyberTWEAK

机译:排出水洞:用CyberTweak缓解社会工程攻击

获取原文

摘要

Cyber adversaries have increasingly leveraged social engineering attacks to breach large organizations and threaten the well-being of today's online users. One clever technique, the "watering hole" attack, compromises a legitimate website to execute drive-by download attacks by redirecting users to another malicious domain, We introduce a game-theoretic model that captures the salient aspects for an organization protecting itself from a watering hole attack by altering the environment information in web traffic so as to deceive the attackers. Our main contributions are (1) a novel Social Engineering Deception (SED) game model that features a continuous action set for the attacker, (2) an in-depth analysis of the SED model to identify computationally feasible real-world cases, and (3) the CyberTWEAK algorithm which solves for the optimal protection policy. To illustrate the potential use of our framework, we built a browser extension based on our algorithms which is now publicly available online. The CyberTWEAK extension will be vital to the continued development and deployment of countermeasures for social engineering.
机译:网络对手越来越努力利用社会工程袭击,违反大型组织并威胁到今天的在线用户的福祉。一个巧妙的技术,“浇水孔”攻击,妥协通过将用户重定向到另一个恶意域来执行驱动器的行车下载攻击,我们介绍了一个游戏理论模型,捕获了一个组织免受浇水的突出方面的游戏理论模型通过改变Web流量中的环境信息来挖掘孔攻击,以欺骗攻击者。我们的主要贡献是(1)新的社会工程欺骗(SED)游戏模型,为攻击者提供了连续的动作,(2)对SED模型的深入分析,以识别计算可行的现实案例,以及( 3)用于解决最佳保护政策的Cyber​​TWeAk算法。为了说明我们的框架的潜在使用,我们基于我们的算法建立了浏览器扩展,该算法现在在线公开提供。 Cyber​​Tweak延伸将对社会工程的持续开发和部署至关重要。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号