|
|
|
Analysis and Defensive Tools for Social Engineering Attacks on Computer SystemLena Laribee, David Barnes, Neil Rowe and Craig MartellThe 7th IEEE Information Assurance Workshop (IAWorkshop 2006)West Point, New York, USA, June 21-23, 2006
AbstractSince security is centered on trust in protection and authenticity, the weakest link in the security chain is between the keyboard and monitor. This is due to the natural human willingness to accept someone at his or her word. Attacking computer systems through social interactions with people is called social engineering. Attackers know how much easier it is to trick insiders instead of targeting the complex technological protections of systems. We discuss methods we have developed for modeling social-engineering attacks. We then apply them to the specific problem of defending against phishing.
|
|