论文标题

黑客的人类维度:通过社交媒体的社会工程

A Human Dimension of Hacking: Social Engineering through Social Media

论文作者

Wilcox, Heidi, Bhattacharya, Maumita

论文摘要

通过针对组织员工的社交媒体渠道进行的社会工程正在成为最具挑战性的信息安全威胁之一。由于依靠人类天真或错误的攻击方法,社会工程违反了传统的安全工作。现在通过在线社交网络提供给社会工程师的大量信息正在促进攻击方法,这些方法依靠某种形式的人为错误来渗透到公司网络中。而对组织信息安全目标的重要性是引入相关的综合政策和指南,但观点和实践因全球地区而异。本文确定了这种区域变化,然后在澳大利亚组织(公共和私人)中对社交媒体进行了有关信息安全前景和实践的详细调查。结果检测到了不同的观点和实践,表明需要进一步的工作来有效保护由于采用社交媒体而导致的安全威胁。

Social engineering through social media channels targeting organizational employees is emerging as one of the most challenging information security threats. Social engineering defies traditional security efforts due to the method of attack relying on human naiveté or error. The vast amount of information now made available to social engineers through online social networks is facilitating methods of attack which rely on some form of human error to enable infiltration into company networks. While, paramount to organisational information security objectives is the introduction of relevant comprehensive policy and guideline, perspectives and practices vary from global region to region. This paper identifies such regional variations and then presents a detailed investigation on information security outlooks and practices, surrounding social media, in Australian organisations (both public and private). Results detected disparate views and practices, suggesting further work is needed to achieve effective protection against security threats arsing due to social media adoption.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源