首页> 外文期刊>Journal of Investigative Psychology and Offender Profiling >On the anatomy of social engineering attacksA literature-based dissection of successful attacks
【24h】

On the anatomy of social engineering attacksA literature-based dissection of successful attacks

机译:关于社会工程学攻击的剖析-基于文献的成功攻击剖析

获取原文
获取原文并翻译 | 示例
       

摘要

The aim of this study was to explore the extent to which persuasion principles are used in successful social engineering attacks. Seventy-four scenarios were extracted from 4 books on social engineering (written by social engineers) and analysed. Each scenario was split into attack steps, containing single interactions between offender and target. For each attack step, persuasion principles were identified. The main findings are that (a) persuasion principles are often used in social engineering attacks, (b) authority (1 of the 6 persuasion principles) is used considerably more often than others, and (c) single-principle attack steps occur more often than multiple-principle ones. The social engineers identified in the scenarios more often used persuasion principles compared to other social influences. The scenario analysis illustrates how to exploit the human element in security. The findings support the view that security mechanisms should include not only technical but also social countermeasures.
机译:这项研究的目的是探索在成功的社会工程学攻击中使用说服原则的程度。从社会工程学的四本书(由社会工程师撰写)中提取了74个场景并进行了分析。每个场景都分为攻击步骤,其中包含犯罪者与目标之间的单个交互。对于每个攻击步骤,都要确定说服原则。主要发现是:(a)说服原则在社会工程学攻击中经常被使用;(b)权威(6个说服原则中的1个)比其他人更频繁地使用;以及(c)单原理攻击步骤更常发生比多原则的与其他社会影响相比,在方案中确定的社会工程师更常使用说服原则。场景分析说明了如何利用安全中的人为因素。调查结果支持以下观点:安全机制不仅应包括技术对策,还应包括社会对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号