Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

Using Attack Graphs to Analyze Social Engineering Threats

Academic Article
Publication Date:
2015
abstract:
The acquisition of information about computer systems by mostly non-technical means is called social engineering. Most critical systems are vulnerable to social threats, even when technical security is high. Social engineering is a technique that: (i) does not require any (advanced) technical tools, (ii) can be used by anyone, (iii) is cheap, (iv) almost impossible to eliminate completely. The integration of social engineering attackers with other attackers, such as software or network ones, is missing so far. Existing research focuses on classifying and analyzing social engineering attacks. The authors' contribution is to consider social engineering exploits together with technical vulnerabilities. The authors introduce a method for the integration of social engineering exploits into attack graphs and propose a simple quantitative analysis of the graphs that helps to develop a comprehensive defensive strategy.
Iris type:
01.01 Articolo in rivista
Keywords:
attack graph metrics risk Security
List of contributors:
Krautsevich, Leanid; Yautsiukhin, Artsiom
Authors of the University:
YAUTSIUKHIN ARTSIOM
Handle:
https://iris.cnr.it/handle/20.500.14243/307124
Published in:
INTERNATIONAL JOURNAL OF SECURE SOFTWARE ENGINEERING
Journal
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)