Internet-Based Social Engineering Psychology, Attacks, and Defenses: A Survey

IF 23.2 1区 计算机科学 Q1 ENGINEERING, ELECTRICAL & ELECTRONIC Proceedings of the IEEE Pub Date : 2024-03-01 DOI:10.1109/JPROC.2024.3379855
Theodore Tangie Longtchi;Rosana Montañez Rodriguez;Laith Al-Shawaf;Adham Atyabi;Shouhuai Xu
{"title":"Internet-Based Social Engineering Psychology, Attacks, and Defenses: A Survey","authors":"Theodore Tangie Longtchi;Rosana Montañez Rodriguez;Laith Al-Shawaf;Adham Atyabi;Shouhuai Xu","doi":"10.1109/JPROC.2024.3379855","DOIUrl":null,"url":null,"abstract":"Internet-based social engineering (SE) attacks are a major cyber threat. These attacks often serve as the first step in a sophisticated sequence of attacks that target, among other things, victims’ credentials and can cause financial losses. The problem has received mounting attention in recent years, with many publications proposing defenses against SE attacks. Despite this, the situation has not improved. In this article, we aim to understand and explain this phenomenon by investigating the root cause of the problem. To this end, we examine Internet-based SE attacks and defenses through a unique lens based on psychological factors (PFs) and psychological techniques (PTs). We find that there is a key discrepancy between attacks and defenses: SE attacks have deliberately exploited 46 PFs and 16 PTs in total, but existing defenses have only leveraged 16 PFs and seven PTs in total. This discrepancy may explain why existing defenses have achieved limited success and prompt us to propose a systematic roadmap for future research.","PeriodicalId":20556,"journal":{"name":"Proceedings of the IEEE","volume":"112 3","pages":"210-246"},"PeriodicalIF":23.2000,"publicationDate":"2024-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the IEEE","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10493072/","RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"ENGINEERING, ELECTRICAL & ELECTRONIC","Score":null,"Total":0}
引用次数: 0

Abstract

Internet-based social engineering (SE) attacks are a major cyber threat. These attacks often serve as the first step in a sophisticated sequence of attacks that target, among other things, victims’ credentials and can cause financial losses. The problem has received mounting attention in recent years, with many publications proposing defenses against SE attacks. Despite this, the situation has not improved. In this article, we aim to understand and explain this phenomenon by investigating the root cause of the problem. To this end, we examine Internet-based SE attacks and defenses through a unique lens based on psychological factors (PFs) and psychological techniques (PTs). We find that there is a key discrepancy between attacks and defenses: SE attacks have deliberately exploited 46 PFs and 16 PTs in total, but existing defenses have only leveraged 16 PFs and seven PTs in total. This discrepancy may explain why existing defenses have achieved limited success and prompt us to propose a systematic roadmap for future research.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于互联网的社交工程心理、攻击和防御:调查
基于互联网的社交工程 (SE) 攻击是一种主要的网络威胁。这些攻击通常是一连串复杂攻击的第一步,攻击目标包括受害者的凭据,并可能造成经济损失。近年来,这一问题受到越来越多的关注,许多出版物都提出了针对 SE 攻击的防御措施。尽管如此,情况仍未得到改善。在本文中,我们旨在通过调查问题的根源来理解和解释这一现象。为此,我们通过基于心理因素(PFs)和心理技术(PTs)的独特视角来研究基于互联网的 SE 攻击和防御。我们发现,攻击和防御之间存在着关键的差异:SE 攻击总共故意利用了 46 个 PF 和 16 个 PT,但现有防御总共只利用了 16 个 PF 和 7 个 PT。这种差异可以解释为什么现有的防御措施只能取得有限的成功,并促使我们为未来的研究提出一个系统的路线图。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
Proceedings of the IEEE
Proceedings of the IEEE 工程技术-工程:电子与电气
CiteScore
46.40
自引率
1.00%
发文量
160
审稿时长
3-8 weeks
期刊介绍: Proceedings of the IEEE is the leading journal to provide in-depth review, survey, and tutorial coverage of the technical developments in electronics, electrical and computer engineering, and computer science. Consistently ranked as one of the top journals by Impact Factor, Article Influence Score and more, the journal serves as a trusted resource for engineers around the world.
期刊最新文献
Front Cover Table of Contents IEEE Membership Future Special Issues/Special Sections of the Proceedings TechRxiv
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1