• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Zheng, Kangfeng (Zheng, Kangfeng.) | Wu, Tong (Wu, Tong.) | Wang, Xiujuan (Wang, Xiujuan.) | Wu, Bin (Wu, Bin.) | Wu, Chunhua (Wu, Chunhua.)

收录:

EI Scopus SCIE

摘要:

Social engineering has been increasingly used during the past few years. Social engineering attacks have resulted in great financial losses. Research on social engineering models and frameworks is still in its elementary stage. An appropriate social engineering framework can interpret all the attack components and their relationships clearly, which will contribute to the defense of social engineering attacks. In this tutorial paper, existing social engineering models and frameworks are summarized and a new social engineering framework is proposed involving the concept of the session and dialogue. An entire social engineering attack is defined as a social engineering session (SES). A social engineering dialogue (SED) refers to a specific attack phase, which is included in a SES. A SES contains several well-organized SEDs. Then, the attack graph is used to formalize the proposed social engineering framework. The SED is treated as an atomic attack during the whole SES. The human weaknesses that an attacker can exploit are described as vulnerabilities, the information, and trust that an attacker owns as permissions. Finally, three real-world social engineering cases are analyzed using the proposed framework and attack graph. The analyses illustrate the usability of the proposed framework and provide a better understanding of various social engineering attacks.

关键词:

attack graph information security Social engineering social engineering dialogue (SED) social engineering session (SES)

作者机构:

  • [ 1 ] [Zheng, Kangfeng]Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
  • [ 2 ] [Wu, Tong]Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
  • [ 3 ] [Wu, Bin]Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
  • [ 4 ] [Wu, Chunhua]Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
  • [ 5 ] [Wang, Xiujuan]Beijing Univ Technol, Fac Informat Technol, Beijing 100124, Peoples R China

通讯作者信息:

  • [Wu, Tong]Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China

电子邮件地址:

查看成果更多字段

相关关键词:

相关文章:

来源 :

IEEE ACCESS

ISSN: 2169-3536

年份: 2019

卷: 7

页码: 67781-67794

3 . 9 0 0

JCR@2022

JCR分区:1

被引次数:

WoS核心集被引频次: 7

SCOPUS被引频次: 19

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 1

归属院系:

在线人数/总访问数:54/3268083
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司