Volume 1, Number 2 (2016)
Year Launched: 2016
Social Engineering: I-E based Model of Human Weakness to Investigate Attack and Defense

Volume 1, Issue 2, December 2016    |    PP. 34-57    |PDF (274 K)|    Pub. Date: December 20, 2016
156 Downloads     2046 Views  

Wenjun Fan, Department of Telematics Engineering, ETSI Telecommunication Technical University of Madrid, Madrid, Spain
Kevin Lwakatare, Department of Computer Science, TUT Centre for Digital Forensics and Cyber Security Tallinn University of Technology, Tallinn, Estonia
Rong Rong, IE Business School, Madrid, Spain

Social engineering is the attack aimed to manipulate dupe to divulge sensitive information or perform actions to help the adversary bypassing the secure perimeter in front of the information-related resources in order to complete attacking goals. Though there are a number of security tools, such as firewalls and intrusion detection systems, which can be used to protect the machines from being attacked, there is a lack of widely accepted mechanism to prevent dupe from fraud. However, the human element is often the weakest link in an information security chain, particularly, in a human-centered environment. In this paper, we reveal that the human psychological weaknesses result in the main vulnerabilities that can be exploited by social engineering attacks, and also, we capture two essential levels, internal characteristics of human nature and external circumstance influences, to discover the root cause of the human weaknesses. We unveil that the internal characteristics of human nature can be converted into weaknesses by external circumstance influences. So, we propose the I-E based model of human weakness for social engineering investigation. Based on this model, we analyzed the vulnerabilities exploited by different techniques of social engineering, and also, we conclude several defense approaches to strengthen the human weaknesses. This work can help the security researchers to gain insights into social engineering from a different perspective, and especially, enhance research for the current and future social engineering defense mechanisms.

Social Engineering, Semantic Attacks, Information Security, Data Privacy, Hacking Techniques, Human Weaknesses

Cite this paper
Wenjun Fan, Kevin Lwakatare, Rong Rong, Social Engineering: I-E based Model of Human Weakness to Investigate Attack and Defense, SCIREA Journal of Information Science and Systems Science. Vol. 1 , No. 2 , 2016 , pp. 34 - 57 .


