Social engineering and its countermeasures

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

6 Scopus citations

Abstract

This chapter introduces and defines social engineering, a recognized threat to the security of information systems. It also introduces a taxonomy for classifying social engineering attacks along four dimensions: who or what the targets are, what media are used, how the attacks fit in an attack cycle, and the techniques used to execute the attacks. Additionally, the chapter discusses current social engineering countermeasures and how to map attack types to these countermeasures. Finally, the chapter ends with a discussion of future trends and technologies for defending against social engineering attacks. Use of the taxonomy should help security professionals and researchers understand social engineering attacks, and implementation of the discussed current and future countermeasures should help professionals reduce the risks associated with social engineering attacks.

Original languageEnglish
Title of host publicationHandbook of Research on Social and Organizational Liabilities in Information Security
Pages228-242
Number of pages15
DOIs
StatePublished - 2008

EGS Disciplines

  • Operations and Supply Chain Management

Fingerprint

Dive into the research topics of 'Social engineering and its countermeasures'. Together they form a unique fingerprint.

Cite this