A social engineering awareness and training workshop for STEM students and practitioners

Aunshul Rege, T. Nguyen, Rachel Bleiman
{"title":"A social engineering awareness and training workshop for STEM students and practitioners","authors":"Aunshul Rege, T. Nguyen, Rachel Bleiman","doi":"10.1109/ISEC49744.2020.9280596","DOIUrl":null,"url":null,"abstract":"The human element is often regarded as the weakest link in cybersecurity, yet awareness and training efforts focus primarily on the technical aspects of cybersecurity and downplay the relevance of the human factor. One way to exploit this human vulnerability is through social engineering, in which cybercriminals utilize persuasion and manipulation of human behavior and psychology to convince individuals to reveal information, provide access or perform an action. This paper offers a case study on efforts to design and develop a social engineering awareness and training program that was implemented at the 2019 National Science Foundation Cybersecurity Summit using the National Institute of Standards and Technology framework for program development. This program was developed to enhance the ability for individuals in the future and current workforce to protect their organization against vulnerabilities to social engineering attacks, through corresponding awareness and training. The authors share the different stages that are involved in producing a successful program: designing the program, developing the awareness and training material, and implementing the program. In addition, this paper details the challenges and lessons the authors experienced and learned, which can be used as a guide for other practitioners to develop social engineering awareness and training programs.","PeriodicalId":355861,"journal":{"name":"2020 IEEE Integrated STEM Education Conference (ISEC)","volume":"30 12","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE Integrated STEM Education Conference (ISEC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISEC49744.2020.9280596","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The human element is often regarded as the weakest link in cybersecurity, yet awareness and training efforts focus primarily on the technical aspects of cybersecurity and downplay the relevance of the human factor. One way to exploit this human vulnerability is through social engineering, in which cybercriminals utilize persuasion and manipulation of human behavior and psychology to convince individuals to reveal information, provide access or perform an action. This paper offers a case study on efforts to design and develop a social engineering awareness and training program that was implemented at the 2019 National Science Foundation Cybersecurity Summit using the National Institute of Standards and Technology framework for program development. This program was developed to enhance the ability for individuals in the future and current workforce to protect their organization against vulnerabilities to social engineering attacks, through corresponding awareness and training. The authors share the different stages that are involved in producing a successful program: designing the program, developing the awareness and training material, and implementing the program. In addition, this paper details the challenges and lessons the authors experienced and learned, which can be used as a guide for other practitioners to develop social engineering awareness and training programs.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
为STEM学生和从业者提供的社会工程意识和培训研讨会
人的因素通常被认为是网络安全中最薄弱的环节,然而意识和培训工作主要集中在网络安全的技术方面,而低估了人的因素的相关性。利用这一人类弱点的一种方法是通过社会工程,网络罪犯利用说服和操纵人类行为和心理来说服个人透露信息、提供访问权限或执行某项行动。本文提供了一个案例研究,介绍了在2019年国家科学基金会网络安全峰会上使用国家标准与技术研究所框架进行计划开发的社会工程意识和培训计划的设计和开发工作。该计划旨在通过相应的意识和培训,提高个人和当前劳动力的能力,以保护他们的组织免受社会工程攻击的脆弱性。作者分享了制定一个成功的计划所涉及的不同阶段:设计计划,开发意识和培训材料,以及实施计划。此外,本文还详细介绍了作者所经历和学习到的挑战和教训,可以作为其他实践者发展社会工程意识和培训计划的指南。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Improving method of instruction in classrooms Best Predictors for Major Food Allergy Reactions Math & Crafts, Educational Activities: Ancient Math Methods, Future Directions A social engineering awareness and training workshop for STEM students and practitioners Encouraging Higher Education STEM Careers Through Robotics Competitions
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1