SoK: Why Have Defenses against Social Engineering Attacks Achieved Limited Success?

03/15/2022
by   Theodore Longtchi, et al.
0

Social engineering attacks are a major cyber threat because they often serve as a first step for an attacker to break into an otherwise well-defended network, steal victims' credentials, and cause financial losses. The problem has received due amount of attention with many publications proposing defenses against them. Despite this, the situation has not improved. In this SoK paper, we aim to understand and explain this phenomenon by looking into the root cause of the problem. To this end, we examine the literature on attacks and defenses through a unique lens we propose – psychological factors (PFs) and techniques (PTs). We find that there is a big discrepancy between attacks and defenses: Attacks have deliberately exploited PFs by leveraging PTs, but defenses rarely take either of these into consideration, preferring technical solutions. This explains why existing defenses have achieved limited success. This prompts us to propose a roadmap for a more systematic approach towards designing effective defenses against social engineering attacks.

READ FULL TEXT
research
03/09/2022

Social Engineering Attacks and Defenses in the Physical World vs. Cyberspace: A Contrast Study

Social engineering attacks are phenomena that are equally applicable to ...
research
02/25/2021

Characterizing the Landscape of COVID-19 Themed Cyberattacks and Defenses

COVID-19 (Coronavirus) hit the global society and economy with a big sur...
research
04/10/2022

Measuring the False Sense of Security

Recently, several papers have demonstrated how widespread gradient maski...
research
02/01/2018

Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples

We identify obfuscated gradients as a phenomenon that leads to a false s...
research
11/02/2018

Stronger Data Poisoning Attacks Break Data Sanitization Defenses

Machine learning models trained on data from the outside world can be co...
research
12/20/2022

SoK: Analysis of Root Causes and Defense Strategies for Attacks on Microarchitectural Optimizations

Microarchitectural optimizations are expected to play a crucial role in ...
research
03/15/2022

This is not the padding you are looking for! On the ineffectiveness of QUIC PADDING against website fingerprinting

Website fingerprinting (WF) is a well-know threat to users' web privacy....

Please sign up or login with your details

Forgot password? Click here to reset