2014
DOI: 10.1007/978-3-662-44208-1_22
|View full text |Cite
|
Sign up to set email alerts
|

Towards an Ontological Model Defining the Social Engineering Domain

Abstract: The human is often the weak link in the attainment of Information Security due to their susceptibility to deception and manipulation. Social Engineering refers to the exploitation of humans in order to gain unauthorised access to sensitive information. Although Social Engineering is an important branch of Information Security, the discipline is not well defined; a number of different definitions appear in the literature. Several concepts in the domain of Social Engineering are defined in this paper. This paper… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
39
0
1

Year Published

2014
2014
2023
2023

Publication Types

Select...
5
3

Relationship

3
5

Authors

Journals

citations
Cited by 44 publications
(40 citation statements)
references
References 15 publications
0
39
0
1
Order By: Relevance
“…There are many models and taxonomies for social engineering attacks [1,13,16,17,18,19,20]. The most commonly known model is Kevin Mitnick's social engineering attack cycle as described in his book, The art of deception: controlling the human element of security [8].…”
Section: Defining Social Engineering Attacksmentioning
confidence: 99%
See 2 more Smart Citations
“…There are many models and taxonomies for social engineering attacks [1,13,16,17,18,19,20]. The most commonly known model is Kevin Mitnick's social engineering attack cycle as described in his book, The art of deception: controlling the human element of security [8].…”
Section: Defining Social Engineering Attacksmentioning
confidence: 99%
“…There are various definitions of social engineering and also a number of different models of social engineering attack [1,2,3,4,5,6,7,8,9,10,11]. The authors considered a number of definitions of social engineering and social engineering attack taxonomies in a previous paper, Towards an Ontological Model Defining the Social Engineering Domain [1], and formulated a definition for both social engineering and social engineering attack. In addition, the authors proposed an ontological model for a social engineering attack.…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…These traps operate in the Application layer. Due to the difficulty of detecting social engineering attacks, to determine that one of these attack mechanisms was used has a low confidence [27,28,29].…”
Section: Attack Mechanism Determinationmentioning
confidence: 99%
“…Social engineering -in the context of this paper -refers to the science of using social interaction as a means to persuade an individual or an organisation to comply with a specific request from an attacker where either the social interaction, the persuasion or the request involves a computer-related entity [1]. As clearly stated by various authors, the human element is the 'glitch' or vulnerable element in security systems [2,3,4].…”
Section: Introductionmentioning
confidence: 99%