...
【24h】

Social Attackability Metrics for Software Systems

机译:软件系统的社会可攻击性指标

获取原文

摘要

Software based system have become ubiquitous in modern day activities. Software system based system are being increasing attacked, leading to the need for software system administrators, and managers to have some metrics at predicting the social engineering attackability of a such system. Researchers have identified seven human traits/attributes that make human susceptible to social engineering attacks. Yet they did not model nor come up metrics. The author has published a conceptual a holistic predictive attackability metric model and corresponding metrics to assist the system designers. The model considers the technical metrics based on cohesion, coupling and complexity as used to predict attackability. It also consider the social metrics based on human traits that make the human operators become susceptible to social engineering attacks. The identified human traits are dishonesty, social compliance, Kindness,Time pressure, Herd mentality, greedeed and distraction. This paper considers only the social metrics part of the model.To measure human traits the authors relies on the HEXACO model and Big Five personality trait models. In these model the personality trait are measured using a ranking scale based on Lickert scale. Hence each trait is measured as a percentile. However, for purpose of this paper, to postulate the metric the author considered the discrete case. Why the value of trait take either a value of "1" or "0". To determine the relationship between traits between and attackability experts were asked to assess the trait versus attackability from which after aggregating for all traits a social attackability metrics was determined. To determine the predictive social attackability metrics each trait was considered to be equally likely to occur and hence a probability of 1/7 and this acts as factor to transform the social attackability metric into predictive attackability metrics.
机译:在当今的活动中,基于软件的系统已无处不在。基于软件系统的系统正受到越来越多的攻击,导致软件系统管理员和管理人员需要具有一些指标来预测此类系统的社会工程可攻击性。研究人员已经确定了七个使人类容易受到社会工程攻击的人类特征/属性。但是他们没有建模也没有提出指标。作者已经发布了概念性的整体预测攻击性度量模型和相应的度量,以协助系统设计人员。该模型基于内聚性,耦合性和复杂性来考虑技术指标,以预测可攻击性。它还考虑了基于人类特征的社会度量标准,这些特征使人类操作员容易受到社会工程攻击。识别出的人类特征是不诚实,社交顺从,善良,时间压力,从众心态,贪婪/需求和分心。本文仅考虑该模型的社会指标部分。为了衡量人的特质,作者依赖于HEXACO模型和五种人格特质模型。在这些模型中,使用基于Lickert量表的等级量表来测量人格特质。因此,每个特征都以百分位数衡量。但是,出于本文的目的,为了假定该度量标准,作者考虑了离散情况。为什么特征值取值为“ 1”或“ 0”。为了确定攻击者与攻击者之间的特征之间的关系,要求专家评估特征与攻击能力之间的关系,从中总结出所有特征后,确定社会攻击能力指标。为了确定预测性社会可攻击性指标,每个特征均被视为同等可能发生,因此概率为1/7,这是将社会可攻击性指标转换为预测性可攻击性指标的因素。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号