ResearchSpace

Social engineering attacks: an augmentation of the socio-technical systems framework

Show simple item record

dc.contributor.author Shozi, Nobubele A
dc.contributor.author Modise, M
dc.date.accessioned 2016-11-29T11:57:18Z
dc.date.available 2016-11-29T11:57:18Z
dc.date.issued 2015-03
dc.identifier.citation Shozi, A. and Modise, M. 2015. Social engineering attacks: an augmentation of the socio-technical systems framework. In: International Conference on Cyber Warfare and Security 2015, Kruger National Park, South Africa March 2015 en_US
dc.identifier.uri http://search.proquest.com/openview/dad1bd4d21a8d5ca8b92b9643fdfa9e4/1?pq-origsite=gscholar&cbl=396500
dc.identifier.uri http://hdl.handle.net/10204/8873
dc.description International Conference on Cyber Warfare and Security 2015, Kruger National Park, South Africa March 2015 en_US
dc.description.abstract Social engineering attacks pose huge security threats to companies today. These attacks have succeeded mainly because they come from weaknesses that combine the social engineering practices that exploit the human vulnerabilities, with technical skills to bypass the defences of information systems. This paper is founded on the premise that social engineering attacks result from interdependent yet interrelating factors that combine to give an attacker the ability to compromise an individual or organisation’s information. We analyse social engineering attacks as a Socio-technical System because it recognises the interaction between people and technology in a work environment. In the case of social engineering attacks, the social subsystem would encompass the people (both victim and attacker), the environmental subsystem would be the environment in which the social engineering attack occurs and the technical subsystem would be the technology used to perform the social engineering attack. The Socio-technical subsystems are further mapped against an existing framework known as the Socio-technical systems framework. This paper applies the currently existing Sociotechnical systems framework along with the Socio-technical subsystems mappings to analyse a social engineering attack case study to help identify the underlying factors that made the attack successful. The case study is a popular attack known as ‘The Francophone attack’, which is an attack that was carried out on a French bank. Through the analysis of the case study, the researchers found that in order to analyse a social engineering attack using the framework, it is pivotal to augment the framework by adding an Information node in the environmental subsystem as one of the aims of any social engineering attacks is to trick you into handing over passwords or other sensitive financial and personal information. The outcome of this research is twofold – firstly, it aims to provide an in-depth perspective into the factors that can allow a social engineering attack to be successful and secondly, to augment the socio-technical systems framework to suit analysis of social engineering attacks when identifying socio-technical system factors. en_US
dc.language.iso en en_US
dc.publisher Academic Conferences International Limited en_US
dc.relation.ispartofseries Workflow;16642
dc.subject Social engineering attack en_US
dc.subject Socio-technical systems framework en_US
dc.subject Work environment en_US
dc.subject Francophone attack en_US
dc.title Social engineering attacks: an augmentation of the socio-technical systems framework en_US
dc.type Conference Presentation en_US
dc.identifier.apacitation Shozi, N. A., & Modise, M. (2015). Social engineering attacks: an augmentation of the socio-technical systems framework. Academic Conferences International Limited. http://hdl.handle.net/10204/8873 en_ZA
dc.identifier.chicagocitation Shozi, Nobubele A, and M Modise. "Social engineering attacks: an augmentation of the socio-technical systems framework." (2015): http://hdl.handle.net/10204/8873 en_ZA
dc.identifier.vancouvercitation Shozi NA, Modise M, Social engineering attacks: an augmentation of the socio-technical systems framework; Academic Conferences International Limited; 2015. http://hdl.handle.net/10204/8873 . en_ZA
dc.identifier.ris TY - Conference Presentation AU - Shozi, Nobubele A AU - Modise, M AB - Social engineering attacks pose huge security threats to companies today. These attacks have succeeded mainly because they come from weaknesses that combine the social engineering practices that exploit the human vulnerabilities, with technical skills to bypass the defences of information systems. This paper is founded on the premise that social engineering attacks result from interdependent yet interrelating factors that combine to give an attacker the ability to compromise an individual or organisation’s information. We analyse social engineering attacks as a Socio-technical System because it recognises the interaction between people and technology in a work environment. In the case of social engineering attacks, the social subsystem would encompass the people (both victim and attacker), the environmental subsystem would be the environment in which the social engineering attack occurs and the technical subsystem would be the technology used to perform the social engineering attack. The Socio-technical subsystems are further mapped against an existing framework known as the Socio-technical systems framework. This paper applies the currently existing Sociotechnical systems framework along with the Socio-technical subsystems mappings to analyse a social engineering attack case study to help identify the underlying factors that made the attack successful. The case study is a popular attack known as ‘The Francophone attack’, which is an attack that was carried out on a French bank. Through the analysis of the case study, the researchers found that in order to analyse a social engineering attack using the framework, it is pivotal to augment the framework by adding an Information node in the environmental subsystem as one of the aims of any social engineering attacks is to trick you into handing over passwords or other sensitive financial and personal information. The outcome of this research is twofold – firstly, it aims to provide an in-depth perspective into the factors that can allow a social engineering attack to be successful and secondly, to augment the socio-technical systems framework to suit analysis of social engineering attacks when identifying socio-technical system factors. DA - 2015-03 DB - ResearchSpace DP - CSIR KW - Social engineering attack KW - Socio-technical systems framework KW - Work environment KW - Francophone attack LK - https://researchspace.csir.co.za PY - 2015 T1 - Social engineering attacks: an augmentation of the socio-technical systems framework TI - Social engineering attacks: an augmentation of the socio-technical systems framework UR - http://hdl.handle.net/10204/8873 ER - en_ZA


Files in this item

This item appears in the following Collection(s)

Show simple item record