Dissecting Social Engineering Attacks Through the Lenses of Cognition

被引:9
作者
Burda, Pavlo [1 ]
Allodi, Luca [1 ]
Zannone, Nicola [1 ]
机构
[1] Eindhoven Univ Technol, Eindhoven, Netherlands
来源
2021 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2021) | 2021年
关键词
social engineering; cognitive science; SUSCEPTIBILITY; VULNERABILITY; ATTENTION; SECURITY; JUDGMENT;
D O I
10.1109/EuroSPW54576.2021.00024
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we present, showcase, and analize a novel framework to dissect Social Engineering (SE) attacks. The framework is based on extant theories in the cognitive sciences, and is meant as an instrument for researchers and practitioners alike to structure and analyze SE attacks of varying sophistication, isolating specific features and their effects at the cognitive level, and providing a common structure for comparisons across different attacks. We showcase the framework against attacks reproduced in the academic literature as well as against real (highly-targeted) SE attacks reported in the wild, isolating and relating effects and techniques adopted by the attackers to the target's cognitive process. We discuss implications for research and practice of the proposed framework.
引用
收藏
页码:149 / 160
页数:12
相关论文
共 51 条
[1]  
Agrafiotis I, 2015, COMPUT FRAUD SECUR, P9
[2]   The Need for New Antiphishing Measures Against Spear-Phishing Attacks [J].
Allodi, Luca ;
Chotza, Tzouliano ;
Panina, Ekaterina ;
Zannone, Nicola .
IEEE SECURITY & PRIVACY, 2020, 18 (02) :23-34
[3]  
[Anonymous], 2003, ART DECEPTION CONTRO
[4]   How conscious experience and working memory interact [J].
Baars, BJ ;
Franklin, S .
TRENDS IN COGNITIVE SCIENCES, 2003, 7 (04) :166-172
[5]   The conscious access hypothesis: origins and recent evidence [J].
Baars, BJ .
TRENDS IN COGNITIVE SCIENCES, 2002, 6 (01) :47-52
[6]   The episodic buffer: a new component of working memory? [J].
Baddeley, A .
TRENDS IN COGNITIVE SCIENCES, 2000, 4 (11) :417-423
[7]  
Burda P., 2020, ARES
[8]   Spear phishing in a barrel: Insights from a targeted phishing campaign [J].
Burns, A. J. ;
Johnson, M. Eric ;
Caputo, Deanna D. .
JOURNAL OF ORGANIZATIONAL COMPUTING AND ELECTRONIC COMMERCE, 2019, 29 (01) :24-39
[9]  
CIALDINI R, 2016, PRE SUASION REVOLUTI
[10]  
Cialdini Robert B., 2021, Influence: The psychology ofpersuasion