2020
DOI: 10.1109/access.2020.2992807
|View full text |Cite
|
Sign up to set email alerts
|

Defining Social Engineering in Cybersecurity

Abstract: Social engineering has posed a serious security threat to infrastructure, user, data and operations of cyberspace. Nevertheless, there are many conceptual deficiencies (such as inconsistent conceptual intensions, a vague conceptual boundary, confusing instances, overgeneralization and abuse) of the term making serious negative impacts on the understanding, analysis and defense of social engineering attacks. In this paper, an in-depth literature survey is conducted, the original meaning of social engineering in… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
54
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
4
3
2

Relationship

0
9

Authors

Journals

citations
Cited by 81 publications
(54 citation statements)
references
References 57 publications
0
54
0
Order By: Relevance
“…The lack of a structured definition has led to works that have focused solely on defining the term. One such work by Wang, Sun and Zhu has defined Social Engineering in cyber-security as a type of attack wherein the attacker(s) exploit human vulnerabilities by means of social interaction to breach cyber security, with or without the use of technical means and technical vulnerabilities [ 4 ]. Going forward, this paper will be using this definition by Wang et al, as the standard definition for the term ’Social Engineering Attack’ (SEA) in this study.…”
Section: Introductionmentioning
confidence: 99%
“…The lack of a structured definition has led to works that have focused solely on defining the term. One such work by Wang, Sun and Zhu has defined Social Engineering in cyber-security as a type of attack wherein the attacker(s) exploit human vulnerabilities by means of social interaction to breach cyber security, with or without the use of technical means and technical vulnerabilities [ 4 ]. Going forward, this paper will be using this definition by Wang et al, as the standard definition for the term ’Social Engineering Attack’ (SEA) in this study.…”
Section: Introductionmentioning
confidence: 99%
“…Social engineering can be traced back to 1984 [6]. It can be referred to as the "psychological manipulation of people into performing actions or divulging confidential information that cannot be effectively dealt with using traditional security methods", as these "do not investigate the exploitation of human vulnerabilities" [8].…”
Section: Literature Reviewmentioning
confidence: 99%
“…Thirty percent of large companies indicated that social engineering attacks can cost more than 100,000 USD per instance. In 2018, 85% of organizations were attacked, an increase by 16%, and the average annual cost reached 1.4 million USD [6]. A study conducted by [7] indicated that the FBI's data gives an average cost of 130,000 USD and that costs can extend to millions of dollars in some cases.…”
Section: Introductionmentioning
confidence: 99%
“…In connection with phishing and the exploitation of human error sources, social engineering is frequently mentioned in the scientific literature (Wang et al, 2020). While phishing attacks are the gateways for criminals to access sensitive data, social engineering tactics are used as the underlying methodology and act as an enabler.…”
Section: Organizational Aspects Of Cybersecuritymentioning
confidence: 99%