论文标题
基于互联网的社会工程攻击,防御和心理学:一项调查
Internet-based Social Engineering Attacks, Defenses and Psychology: A Survey
论文作者
论文摘要
社会工程攻击是一个主要的网络威胁,因为它们通常是攻击者闯入原本防御良好的网络,窃取受害者的证书并造成财务损失的第一步。这个问题已得到适当的关注,许多出版物提出针对他们的辩护。尽管如此,情况仍未改善。在本文中,我们旨在通过研究问题的根本原因来理解和解释这一现象。为此,我们通过提出的独特镜头来研究有关攻击和防御的文献 - {\ em心理因素(PFS)和技术(PTS)}。我们发现攻击和防御之间存在很大的差异:攻击通过利用PTS故意利用PF,但防御措施很少考虑这些问题,而是更喜欢技术解决方案。这解释了为什么现有防御能力有限。这促使我们提出了一个路线图,以采用更系统的方法来设计有效的防御措施,以防止社会工程攻击。
Social engineering attacks are a major cyber threat because they often serve as a first step for an attacker to break into an otherwise well-defended network, steal victims' credentials, and cause financial losses. The problem has received due amount of attention with many publications proposing defenses against them. Despite this, the situation has not improved. In this paper, we aim to understand and explain this phenomenon by looking into the root cause of the problem. To this end, we examine the literature on attacks and defenses through a unique lens we propose -- {\em psychological factors (PFs) and techniques (PTs)}. We find that there is a big discrepancy between attacks and defenses: Attacks have deliberately exploited PFs by leveraging PTs, but defenses rarely take either of these into consideration, preferring technical solutions. This explains why existing defenses have achieved limited success. This prompts us to propose a roadmap for a more systematic approach towards designing effective defenses against social engineering attacks.