首页> 外文会议>International Conference on Information Resources Management >Countermeasures for Social Engineering-based Malware Installation Attacks
【24h】

Countermeasures for Social Engineering-based Malware Installation Attacks

机译:基于社会工程的恶意软件安装攻击的对策

获取原文

摘要

Social engineering exploits vulnerabilities at different layers (i.e. technical, social layer) in an organizational defense structure. It is therefore important to understand how to defend against these attacks using a holistic defense approach including multiple countermeasures. The literature suggests a plethora of countermeasures, little research has however been done to assess their effectiveness in managing social engineering threats. In this paper we attempt to obtain a deeper understanding of how to defend against a type of social engineering attack that attempts to install malware on computers through e-mail or portable media. We explore commonly proposed countermeasures needed to prevent this type of attack, and if any dependencies between them exist. Through a combined method approach of surveying the literature and conducting semi-structured interviews with domain experts we identified a set of countermeasures that provide empirical input for future studies but could potentially also give organizations guidance on how to manage social engineering-based malware installation attacks.
机译:社会工程在组织防御结构中利用不同层次(即技术,社交层)的漏洞。因此,重要的是要了解如何使用包括多种对策的整体防御方法来防御这些攻击。然而,该文献表明了一流的对策,然而,对管理社会工程威胁的有效性,已经进行了很少的研究。在本文中,我们试图了解如何通过电子邮件或便携式媒体在计算机上安装恶意软件的社会工程攻击的更深入了解。我们探索防止这种类型的攻击所需的常见提议对策,以及它们之间的任何依赖项。通过一种综合方法来调查文献和与域专家进行半结构化访谈的方法,我们确定了一套对未来研究的实证投入的对策,但可能还可以为如何管理基于社会工程的恶意软件安装攻击提供指导。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号