Measuring resistance to social engineering

  • Authors:
  • Hågen Hasle;Yngve Kristiansen;Ketil Kintel;Einar Snekkenes

  • Affiliations:
  • Gjøvik University College, Gjøvik, Norway;Gjøvik University College, Gjøvik, Norway;Gjøvik University College, Gjøvik, Norway;Gjøvik University College, Gjøvik, Norway

  • Venue:
  • ISPEC'05 Proceedings of the First international conference on Information Security Practice and Experience
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Social engineering (SE) is the name used for a bag of tricks used by adversaries to manipulate victims to make them say or do something they otherwise wouldn't have. Typically this includes making the victims disclose passwords, or give the adversary illegitimate access to buildings or privileged information. The book Art of Deception: Controlling the Human Element of Security by Kevin Mitnick gives several examples of potential attacks. Clearly, countermeasures are needed. Countermeasures may include special hardware, software, improved user interfaces, routines, procedures and staff training. However, in order to assess the effectiveness of these countermeasures, we need a SE resistance metric. This paper de.nes such a metric. We have also implemented software to obtain metric test data. A real life SE experiment involving 120 participants has been completed. The experiment suggests that SE may indeed represent an Achilles heel.