首页> 外文会议>International Conference on Advances in Big Data, Computing and Data Communication Systems >Assessment of Spear Phishing User Experience and Awareness: An Evaluation Framework Model of Spear Phishing Exposure Level (SPEL) in the Namibian Financial Industry
【24h】

Assessment of Spear Phishing User Experience and Awareness: An Evaluation Framework Model of Spear Phishing Exposure Level (SPEL) in the Namibian Financial Industry

机译:鱼叉式网络钓鱼用户体验和意识的评估:纳米比亚金融业鱼叉式网络钓鱼暴露水平(SPEL)的评估框架模型

获取原文

摘要

Social engineering has become a major threat to organisations’ IT systems. Users are normally the weakest links in security chains and they put their organisations at risk of internet attacks through various social engineering tricks implemented by online criminals. One of the thriving electronic social engineering attacks that is increasingly targeting electronic banking systems and users is spear phishing attack. Consequently, this research assessed user experience and awareness by evaluating users’ abilities to detect if a specific email is spear phishing. Moreover, the research proposes an evaluation framework for an effective assessment of the organisations’ exposure level to spear phishing threat. In the SPEL evaluation framework, two information security frameworks (ISO27001:2013) and (NIST SP 800 -53) were applied to identify threat vital signs within the organisation, whereas the Protection Motivation Theory (PMT) theory was used in the identification of the user vulnerability signs.
机译:社会工程已经成为组织IT系统的主要威胁。用户通常是安全链中最薄弱的环节,他们通过网络犯罪分子实施的各种社会工程手段,使组织面临互联网攻击的风险。越来越多的针对电子银行系统和用户的电子社会工程攻击是鱼叉式网络钓鱼攻击。因此,这项研究通过评估用户检测特定电子邮件是否为鱼叉式网络钓鱼的能力来评估用户的体验和意识。此外,研究提出了一个评估框架,用于有效评估组织对鱼叉式网络钓鱼威胁的暴露程度。在SPEL评估框架中,应用了两个信息安全框架(ISO27001:2013)和(NIST SP 800 -53)来识别组织内的威胁生命体征,而使用保护动机理论(PMT)理论来识别组织中的威胁生命体征。用户漏洞迹象。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号