Social Engineering Threat Assessment Using a Multi-Layered Graph-Based Model - Université de technologie de Troyes Accéder directement au contenu
Chapitre D'ouvrage Année : 2017

Social Engineering Threat Assessment Using a Multi-Layered Graph-Based Model

Résumé

During this last decade, there have been major improvements in technological and operational security measures for the protection of information systems. This makes attacking the physical or technological infrastructure of an information system much more difficult than targeting humans operating them. The set of attacks that focus on deceiving humans is called social engineering. These attacks are rarely accounted for in vulnerability assessment models which usually focus on representing the internal states of information systems, while social engineering attack makes use of channels outside the gates of an information system (email, forums, on-line social networks, etc.). This paper introduces a comprehensive social engineering threat assessment model that represents different channels leveraged in social engineering attacks. It presents case studies where the model is used for assessing threats from specific attacks and from interactions on social media. In the first case study, a threat assessment method that relies on the presented model is introduced and used to detect malicious credit card resellers. The second case study concerns the assessment of threats from a recommendation based attack and a cross cite profile cloning attack. The last case study concerns the detection of vulnerable social media users based on their activities on two different platforms.
Fichier non déposé

Dates et versions

hal-02519466 , version 1 (26-03-2020)

Identifiants

Citer

Omar Jaafor, B. Birregah. Social Engineering Threat Assessment Using a Multi-Layered Graph-Based Model. Trends in Social Network Analysis, pp.107-133, 2017, 978-3-319-53420-6. ⟨10.1007/978-3-319-53420-6_5⟩. ⟨hal-02519466⟩
18 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More