DocumentCode :
3708343
Title :
An analysis of social engineering principles in effective phishing
Author :
Ana Ferreira;Gabriele Lenzini
Author_Institution :
CINTESIS-Center for Health Technology and Services Research, University of Porto
fYear :
2015
fDate :
7/1/2015 12:00:00 AM
Firstpage :
9
Lastpage :
16
Abstract :
Phishing is a widespread practice and a lucrative business. It is invasive and hard to stop: a company needs to worry about all emails that all employees receive, while an attacker only needs to have a response from a key person, e.g., a finance or human resources´ responsible, to cause a lot of damages. Some research has looked into what elements make phishing so successful. Many of these elements recall strategies that have been studied as principles of persuasion, scams and social engineering. This paper identifies, from the literature, the elements which reflect the effectiveness of phishing, and manually quantifies them within a phishing email sample. Most elements recognised as more effective in phishing commonly use persuasion principles such as authority and distraction. This insight could lead to better automate the identification of phishing emails and devise more appropriate countermeasures against them.
Keywords :
"Electronic mail","Psychology","Security","Internet","Social network services","Decision making"
Publisher :
ieee
Conference_Titel :
Socio-Technical Aspects in Security and Trust (STAST), 2015 Workshop on
Electronic_ISBN :
2325-1697
Type :
conf
DOI :
10.1109/STAST.2015.10
Filename :
7351971
Link To Document :
بازگشت