Social Engineering Intrusion: A Case Study


연구 분야: Strategies



학회: IAIT '20: Proceedings of the 11th International Conference on Advances in Information Technology


초록

Social engineering is a very old method to influence people in their daily actions. The same methods added with new techniques have been implemented to create effective penetration mechanisms against organizations. The goal in this study was to measure employees' security awareness and culture. This is a case study which uses several penetration methods to test an organization's vulnerability against social engineering techniques. The study started with cyber security research questions for all employees in the studied organization Reconnaissance and survey questions together provide use cases to the physical penetration testing phase. When comparing the results of the survey questions with the actual penetration test, a significant difference was found. Even employees understand how to behave in a penetration case; they act differently. This is a problem which can be resolved by increasing the awareness against security engineering attacks. The awareness can be increased by training, education and good security policy.


Author Profile
Miika Sillanpää

Institute of Information Technology JAMK University of Applied Sciences Finland

Finland
Author Profile
Jari Hautamäki

Institute of Information Technology JAMK University of Applied Sciences Finland

Finland

📄 논문 정보

발행 연도 2020년
인용수 1
출판 국가 Finland
사이트 ACM
좋아요 수 0

연관 논문 목록 (402건)