As technology matures, new threats rise and take the place of the “traditional” issues (insecure infrastructure, insecurely developed software, etc.), threats that revolve around exploiting human vulnerabilities instead of technical vulnerabilities. One of the most famous threats that have risen in the area of Information Security is Social Engineering.The goal of this study is to take an interpretive approach on Social Engineering, by using Cialdini’s principles of influence.
In order to be able to interpret the attacks, the study examines documented attacks (by Kevin Mitnick), abstracts them, categorizes them into four main categories (Gain Physical Access, Install Malware, Information Extraction, Perform an Action), models them by graphically depicting the execution path of the attack and finally interprets how the victims were influenced (or manipulated) to assist the attacker(s).
This study is executed using the Literature Review methodology, following the eight steps proposed by Okoli. During the execution of the study the author examines the principles of Influence, Social Engineering models and additional psychological principles used in Social Engineering.
The author, based on the findings in the literature, creates Social Engineering attack models and interprets the findings.The importance of the study is that it explains how the well-known principles of Influence are used in Social Engineering attacks.
The psychological findings and the models created lead the author to believe that there is a possibility for them to be used as a framework for solving Social Engineering attacks.
Today, more than ever, security threats and security risks are an important area of every organization’s practices, independent of the field the organization is targeting. Most (or all) of the security risks have already been identified so far, and have been addressed by one (or combination) of the following approaches: technology, policy, or education (training).
File Type: PDF
File Size: 2.29 MB
Direct Link Mega:
Direct Link AnonFiles:
Direct Link Mediafire:
Direct Link Solidfiles:
Direct Link Sabercathost:
Direct Link Tusfiles: