Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Using Attack Graphs to Analyze Social Engineering Threats

Articolo
Data di Pubblicazione:
2015
Abstract:
The acquisition of information about computer systems by mostly non-technical means is called social engineering. Most critical systems are vulnerable to social threats, even when technical security is high. Social engineering is a technique that: (i) does not require any (advanced) technical tools, (ii) can be used by anyone, (iii) is cheap, (iv) almost impossible to eliminate completely. The integration of social engineering attackers with other attackers, such as software or network ones, is missing so far. Existing research focuses on classifying and analyzing social engineering attacks. The authors' contribution is to consider social engineering exploits together with technical vulnerabilities. The authors introduce a method for the integration of social engineering exploits into attack graphs and propose a simple quantitative analysis of the graphs that helps to develop a comprehensive defensive strategy.
Tipologia CRIS:
01.01 Articolo in rivista
Keywords:
attack graph metrics risk Security
Elenco autori:
Krautsevich, Leanid; Yautsiukhin, Artsiom
Autori di Ateneo:
YAUTSIUKHIN ARTSIOM
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/307124
Pubblicato in:
INTERNATIONAL JOURNAL OF SECURE SOFTWARE ENGINEERING
Journal
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)