2018
DOI: 10.1016/j.cose.2018.02.020
|View full text |Cite
|
Sign up to set email alerts
|

Detecting semantic social engineering attacks with the weakest link: Implementation and empirical evaluation of a human-as-a-security-sensor framework

Abstract: The notion that the human user is the weakest link in information security has been strongly, and, we argue, rightly contested in recent years. Here, we take a step further showing that the human user can in fact be the strongest link for detecting attacks that involve deception, such as application masquerading, spearphishing, WiFi evil twin and other types of semantic social engineering. Towards this direction, we have developed a human-as-a-security-sensor framework and a practical implementation in the for… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
54
0

Year Published

2019
2019
2022
2022

Publication Types

Select...
3
2

Relationship

0
5

Authors

Journals

citations
Cited by 75 publications
(54 citation statements)
references
References 21 publications
0
54
0
Order By: Relevance
“…Human users are considered as the weakest link in the information security domain. 9 One of the possible reasons is that human trust each other and share personal information rather quickly. Various research studies tried to propose unique solutions that may be effective in guarding social engineering attacks or helpful in mitigating the danger: (a) One of the research studies aims to verify whether priming through cues and warnings is effective in countering the habit to disclose personal information.…”
Section: Literature Reviewmentioning
confidence: 99%
See 4 more Smart Citations
“…Human users are considered as the weakest link in the information security domain. 9 One of the possible reasons is that human trust each other and share personal information rather quickly. Various research studies tried to propose unique solutions that may be effective in guarding social engineering attacks or helpful in mitigating the danger: (a) One of the research studies aims to verify whether priming through cues and warnings is effective in countering the habit to disclose personal information.…”
Section: Literature Reviewmentioning
confidence: 99%
“…For online shoppers, 89.8% of them gave away information regarding their purchase and 91.4% shared the name of the online shop from where they usually buy. Further, multivariate analysis showed that priming and warnings alone are not effective in mitigating human's tendency to disclose information online 2 ; (b) Another study, 9 Heartfield et al proposed a concept that human can be used as a security sensor. The basic idea was to create a prototype application which will be installed on participant's windows platform.…”
Section: F I G U R E 1 Research Protocolmentioning
confidence: 99%
See 3 more Smart Citations