A Taxonomy of Attacks and a Survey of Defence Mechanisms for Semantic Social Engineering Attacks

被引:103
作者
Heartfield, Ryan [1 ]
Loukas, George [1 ]
机构
[1] Univ Greenwich, Old Royal Naval Coll, Comp & Informat Syst, Greenwich SE10 9LS, England
关键词
Security; Social Engineering; Computer crime; social engineering attacks; semantic attacks; survey; CYBER SECURITY; AWARENESS;
D O I
10.1145/2835375
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Social engineering is used as an umbrella term for a broad spectrum of computer exploitations that employ a variety of attack vectors and strategies to psychologically manipulate a user. Semantic attacks are the specific type of social engineering attacks that bypass technical defences by actively manipulating object characteristics, such as platform or system applications, to deceive rather than directly attack the user. Commonly observed examples include obfuscated URLs, phishing emails, drive-by downloads, spoofed websites and scareware to name a few. This article presents a taxonomy of semantic attacks, as well as a survey of applicable defences. By contrasting the threat landscape and the associated mitigation techniques in a single comparative matrix, we identify the areas where further research can be particularly beneficial.
引用
收藏
页数:39
相关论文
共 185 条
[1]   An overview of social engineering malware: Trends, tactics, and implications [J].
Abraham, Sherly ;
Chengalur-Smith, InduShobha .
TECHNOLOGY IN SOCIETY, 2010, 32 (03) :183-196
[2]  
Abu-Nimeh S., 2006, PHISHING ATTACKS MOB
[3]  
Aburrous M., 2008, P 3 INT C INF COMM T
[4]  
Acquisti A., 2007, P SIGCHI C HUM FACT
[5]  
Adelsbach A, 2005, LECT NOTES COMPUT SC, V3439, P204
[6]  
Aggarwal A., 2012, ecrime researchers summit (ecrime), 2012, P1, DOI DOI 10.1109/ECRIME.2012.6489521
[7]  
Agten Pieter, 2015, P 22 NETW DISTR SYST
[8]  
Algarni A, 2013, INT CONF INTERNET, P508, DOI 10.1109/ICIST.2013.6747602
[9]  
Ali S.M., 2014, International Journal of Applied, V4
[10]   SoK: The Evolution of Sybil Defense via Social Networks [J].
Alvisi, Lorenzo ;
Clement, Allen ;
Epasto, Alessandro ;
Lattanzi, Silvio ;
Panconesi, Alessandro .
2013 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2013, :382-396