The Experts below are selected from a list of 1731 Experts worldwide ranked by ideXlab platform

Roberto Perdisci - One of the best experts on this subject based on the ideXlab platform.

  • what you see is not what you get discovering and tracking Social Engineering Attack campaigns
    Internet Measurement Conference, 2019
    Co-Authors: Phani Vadrevu, Roberto Perdisci
    Abstract:

    Malicious ads often use Social Engineering (SE) tactics to coax users into downloading unwanted software, purchasing fake products or services, or giving up valuable personal information. These ads are often served by low-tier ad networks that may not have the technical means (or simply the will) to patrol the ad content they serve to curtail abuse. In this paper, we propose a system for large-scale automatic discovery and tracking of SE Attack Campaigns delivered via Malicious Advertisements (SEACMA). Our system aims to be generic, allowing us to study the SEACMA ad distribution problem without being biased towards specific categories of ad-publishing websites or SE Attacks. Starting with a seed of low-tier ad networks, we measure which of these networks are the most likely to distribute malicious ads and propose a mechanism to discover new ad networks that are also leveraged to support the distribution of SEACMA campaigns. The results of our study aim to be useful in a number of ways. For instance, we show that SEACMA ads use a number of tactics to successfully evade URL blacklists and ad blockers. By tracking SEACMA campaigns, our system provides a mechanism to more proactively detect and block such evasive ads. Therefore, our results provide valuable information that could be used to improve defense systems against Social Engineering Attacks and malicious ads in general.

  • Internet Measurement Conference - What You See is NOT What You Get: Discovering and Tracking Social Engineering Attack Campaigns
    Proceedings of the Internet Measurement Conference, 2019
    Co-Authors: Phani Vadrevu, Roberto Perdisci
    Abstract:

    Malicious ads often use Social Engineering (SE) tactics to coax users into downloading unwanted software, purchasing fake products or services, or giving up valuable personal information. These ads are often served by low-tier ad networks that may not have the technical means (or simply the will) to patrol the ad content they serve to curtail abuse. In this paper, we propose a system for large-scale automatic discovery and tracking of SE Attack Campaigns delivered via Malicious Advertisements (SEACMA). Our system aims to be generic, allowing us to study the SEACMA ad distribution problem without being biased towards specific categories of ad-publishing websites or SE Attacks. Starting with a seed of low-tier ad networks, we measure which of these networks are the most likely to distribute malicious ads and propose a mechanism to discover new ad networks that are also leveraged to support the distribution of SEACMA campaigns. The results of our study aim to be useful in a number of ways. For instance, we show that SEACMA ads use a number of tactics to successfully evade URL blacklists and ad blockers. By tracking SEACMA campaigns, our system provides a mechanism to more proactively detect and block such evasive ads. Therefore, our results provide valuable information that could be used to improve defense systems against Social Engineering Attacks and malicious ads in general.

Hein S. Venter - One of the best experts on this subject based on the ideXlab platform.

  • finite state machine for the Social Engineering Attack detection model seadm
    SAIEE Africa Research Journal, 2018
    Co-Authors: Francois Mouton, Louise Leenen, Alastair Nottingham, Hein S. Venter
    Abstract:

    Information security is a fast-growing discipline, and relies on continued improvement of security measures to protect sensitive information. Human operators are one of the weakest links in the security chain as they are highly susceptible to manipulation. A Social Engineering Attack targets this weakness by using various manipulation techniques to elicit individuals to perform sensitive requests. The field of Social Engineering is still in its infancy with respect to formal definitions, Attack frameworks, and examples of Attacks and detection models. In order to formally address Social Engineering in a broad context, this paper proposes the underlying abstract finite state machine of the Social Engineering Attack Detection Model (SEADM). The model has been shown to successfully thwart Social Engineering Attacks utilising either bidirectional communication, unidirectional communication or indirect communication. Proposing and exploring the underlying finite state machine of the model allows one to have a clearer overview of the mental processing performed within the model. While the current model provides a general procedural template for implementing detection mechanisms for Social Engineering Attacks, the finite state machine provides a more abstract and extensible model that highlights the inter-connections between task categories associated with different scenarios. The finite state machine is intended to help facilitate the incorporation of organisation specific extensions by grouping similar activities into distinct categories, subdivided into one or more states. The finite state machine is then verified by applying it to representative Social Engineering Attack scenarios from all three streams of possible communication. This verifies that all the capabilities of the SEADM are kept in tact, whilst being improved, by the proposed finite state machine.

  • Finite State Machine for the Social Engineering Attack Detection Model: SEADM
    SAIEE Africa Research Journal, 2018
    Co-Authors: Francois Mouton, Louise Leenen, Alastair Nottingham, Hein S. Venter
    Abstract:

    Based on: “Underlying Finite State Machine for the Social Engineering Attack Detection Model”, by F. Mouton, A. Nottingham, L. Leenen and H.S. Venter which appeared in the Proceedings of Information Security South African (ISSA) 2017, Johannesburg, 16 & 17 August 2017.

  • underlying finite state machine for the Social Engineering Attack detection model
    Information Security for South Africa, 2017
    Co-Authors: Francois Mouton, Louise Leenen, Alastair Nottingham, Hein S. Venter
    Abstract:

    Information security is a fast-growing discipline, and relies on continued improvement of security measures to protect sensitive information. In general, human operators are often highly susceptible to manipulation, and tend to be one of the weakest links in the security chain. A Social Engineering Attack targets this weakness by using various manipulation techniques to elicit individuals to perform sensitive requests. The field of Social Engineering is still in its infancy with respect to formal definitions, Attack frameworks, examples of Attacks and detection models. In order to formally address Social Engineering in a broad context, this paper proposes the underlying finite state machine of the Social Engineering Attack Detection Model (SEADM). The model has been proven to successfully thwart Social Engineering Attacks utilising either bidirectional communication, unidirectional communication or indirect communication. Proposing and exploring the underlying finite state machine of the model allows one to have a clearer overview of the mental processing performed within the model. While the current model provides a general procedural template for implementing detection mechanisms for Social Engineering Attacks, the finite state machine provides a more abstract and extensible model that highlights the interconnections between task categories associated with different scenarios. The finite state machine is intended to help facilitate the incorporation of organisation specific extensions by grouping similar activities into distinct categories, subdivided into one or more states. In addition, it facilitates additional analysis on state transitions that are difficult to extract from the original flowchart based model.

  • ISSA - Underlying finite state machine for the Social Engineering Attack detection model
    2017 Information Security for South Africa (ISSA), 2017
    Co-Authors: Francois Mouton, Louise Leenen, Alastair Nottingham, Hein S. Venter
    Abstract:

    Information security is a fast-growing discipline, and relies on continued improvement of security measures to protect sensitive information. In general, human operators are often highly susceptible to manipulation, and tend to be one of the weakest links in the security chain. A Social Engineering Attack targets this weakness by using various manipulation techniques to elicit individuals to perform sensitive requests. The field of Social Engineering is still in its infancy with respect to formal definitions, Attack frameworks, examples of Attacks and detection models. In order to formally address Social Engineering in a broad context, this paper proposes the underlying finite state machine of the Social Engineering Attack Detection Model (SEADM). The model has been proven to successfully thwart Social Engineering Attacks utilising either bidirectional communication, unidirectional communication or indirect communication. Proposing and exploring the underlying finite state machine of the model allows one to have a clearer overview of the mental processing performed within the model. While the current model provides a general procedural template for implementing detection mechanisms for Social Engineering Attacks, the finite state machine provides a more abstract and extensible model that highlights the interconnections between task categories associated with different scenarios. The finite state machine is intended to help facilitate the incorporation of organisation specific extensions by grouping similar activities into distinct categories, subdivided into one or more states. In addition, it facilitates additional analysis on state transitions that are difficult to extract from the original flowchart based model.

  • Social Engineering Attack examples, templates and scenarios
    Computers and Security, 2016
    Co-Authors: Francois Mouton, Louise Leenen, Hein S. Venter
    Abstract:

    The field of information security is a fast-growing discipline. Even though the effectiveness of security measures to protect sensitive information is increasing, people remain susceptible to manipulation and thus the human element remains a weak link. A Social Engineering Attack targets this weakness by using various manipulation techniques to elicit sensitive information. The field of Social Engineering is still in its early stages with regard to formal definitions, Attack frameworks and templates of Attacks. This paper proposes detailed Social Engineering Attack templates that are derived from real-world Social Engineering examples. Current documented examples of Social Engineering Attacks do not include all the Attack steps and phases. The proposed Social Engineering Attack templates attempt to alleviate the problem of limited documented literature on Social Engineering Attacks by mapping the real-world examples to the Social Engineering Attack framework. Mapping several similar real-world examples to the Social Engineering Attack framework allows one to establish a detailed flow of the Attack whilst abstracting subjects and objects. This mapping is then utilised to propose the generalised Social Engineering Attack templates that are representative of real-world examples, whilst still being general enough to encompass several different real-world examples. The proposed Social Engineering Attack templates cover all three types of communication, namely bidirectional communication, unidirectional communication and indirect communication. In order to perform comparative studies of different Social Engineering models, processes and frameworks, it is necessary to have a formalised set of Social Engineering Attack scenarios that are fully detailed in every phase and step of the process. The Social Engineering Attack templates are converted to Social Engineering Attack scenarios by populating the template with both subjects and objects from real-world examples whilst still maintaining the detailed flow of the Attack as provided in the template. Furthermore, this paper illustrates how the Social Engineering Attack scenarios are applied to verify a Social Engineering Attack detection model. These templates and scenarios can be used by other researchers to either expand on, use for comparative measures, create additional examples or evaluate models for completeness. Additionally, the proposed Social Engineering Attack templates can also be used to develop Social Engineering awareness material.

Francois Mouton - One of the best experts on this subject based on the ideXlab platform.

  • seader Social Engineering Attack detection in online environments using machine learning
    Journal of Information and Telecommunication, 2020
    Co-Authors: Merton Lansley, Francois Mouton, Stelios Kapetanakis, Nikolaos Polatidis
    Abstract:

    Social Engineering Attacks are one of the most well-known and easiest to apply Attacks in the cybersecurity domain. Research has shown that the majority of Attacks against computer systems was base...

  • finite state machine for the Social Engineering Attack detection model seadm
    SAIEE Africa Research Journal, 2018
    Co-Authors: Francois Mouton, Louise Leenen, Alastair Nottingham, Hein S. Venter
    Abstract:

    Information security is a fast-growing discipline, and relies on continued improvement of security measures to protect sensitive information. Human operators are one of the weakest links in the security chain as they are highly susceptible to manipulation. A Social Engineering Attack targets this weakness by using various manipulation techniques to elicit individuals to perform sensitive requests. The field of Social Engineering is still in its infancy with respect to formal definitions, Attack frameworks, and examples of Attacks and detection models. In order to formally address Social Engineering in a broad context, this paper proposes the underlying abstract finite state machine of the Social Engineering Attack Detection Model (SEADM). The model has been shown to successfully thwart Social Engineering Attacks utilising either bidirectional communication, unidirectional communication or indirect communication. Proposing and exploring the underlying finite state machine of the model allows one to have a clearer overview of the mental processing performed within the model. While the current model provides a general procedural template for implementing detection mechanisms for Social Engineering Attacks, the finite state machine provides a more abstract and extensible model that highlights the inter-connections between task categories associated with different scenarios. The finite state machine is intended to help facilitate the incorporation of organisation specific extensions by grouping similar activities into distinct categories, subdivided into one or more states. The finite state machine is then verified by applying it to representative Social Engineering Attack scenarios from all three streams of possible communication. This verifies that all the capabilities of the SEADM are kept in tact, whilst being improved, by the proposed finite state machine.

  • Finite State Machine for the Social Engineering Attack Detection Model: SEADM
    SAIEE Africa Research Journal, 2018
    Co-Authors: Francois Mouton, Louise Leenen, Alastair Nottingham, Hein S. Venter
    Abstract:

    Based on: “Underlying Finite State Machine for the Social Engineering Attack Detection Model”, by F. Mouton, A. Nottingham, L. Leenen and H.S. Venter which appeared in the Proceedings of Information Security South African (ISSA) 2017, Johannesburg, 16 & 17 August 2017.

  • underlying finite state machine for the Social Engineering Attack detection model
    Information Security for South Africa, 2017
    Co-Authors: Francois Mouton, Louise Leenen, Alastair Nottingham, Hein S. Venter
    Abstract:

    Information security is a fast-growing discipline, and relies on continued improvement of security measures to protect sensitive information. In general, human operators are often highly susceptible to manipulation, and tend to be one of the weakest links in the security chain. A Social Engineering Attack targets this weakness by using various manipulation techniques to elicit individuals to perform sensitive requests. The field of Social Engineering is still in its infancy with respect to formal definitions, Attack frameworks, examples of Attacks and detection models. In order to formally address Social Engineering in a broad context, this paper proposes the underlying finite state machine of the Social Engineering Attack Detection Model (SEADM). The model has been proven to successfully thwart Social Engineering Attacks utilising either bidirectional communication, unidirectional communication or indirect communication. Proposing and exploring the underlying finite state machine of the model allows one to have a clearer overview of the mental processing performed within the model. While the current model provides a general procedural template for implementing detection mechanisms for Social Engineering Attacks, the finite state machine provides a more abstract and extensible model that highlights the interconnections between task categories associated with different scenarios. The finite state machine is intended to help facilitate the incorporation of organisation specific extensions by grouping similar activities into distinct categories, subdivided into one or more states. In addition, it facilitates additional analysis on state transitions that are difficult to extract from the original flowchart based model.

  • ISSA - Underlying finite state machine for the Social Engineering Attack detection model
    2017 Information Security for South Africa (ISSA), 2017
    Co-Authors: Francois Mouton, Louise Leenen, Alastair Nottingham, Hein S. Venter
    Abstract:

    Information security is a fast-growing discipline, and relies on continued improvement of security measures to protect sensitive information. In general, human operators are often highly susceptible to manipulation, and tend to be one of the weakest links in the security chain. A Social Engineering Attack targets this weakness by using various manipulation techniques to elicit individuals to perform sensitive requests. The field of Social Engineering is still in its infancy with respect to formal definitions, Attack frameworks, examples of Attacks and detection models. In order to formally address Social Engineering in a broad context, this paper proposes the underlying finite state machine of the Social Engineering Attack Detection Model (SEADM). The model has been proven to successfully thwart Social Engineering Attacks utilising either bidirectional communication, unidirectional communication or indirect communication. Proposing and exploring the underlying finite state machine of the model allows one to have a clearer overview of the mental processing performed within the model. While the current model provides a general procedural template for implementing detection mechanisms for Social Engineering Attacks, the finite state machine provides a more abstract and extensible model that highlights the interconnections between task categories associated with different scenarios. The finite state machine is intended to help facilitate the incorporation of organisation specific extensions by grouping similar activities into distinct categories, subdivided into one or more states. In addition, it facilitates additional analysis on state transitions that are difficult to extract from the original flowchart based model.

Phani Vadrevu - One of the best experts on this subject based on the ideXlab platform.

  • what you see is not what you get discovering and tracking Social Engineering Attack campaigns
    Internet Measurement Conference, 2019
    Co-Authors: Phani Vadrevu, Roberto Perdisci
    Abstract:

    Malicious ads often use Social Engineering (SE) tactics to coax users into downloading unwanted software, purchasing fake products or services, or giving up valuable personal information. These ads are often served by low-tier ad networks that may not have the technical means (or simply the will) to patrol the ad content they serve to curtail abuse. In this paper, we propose a system for large-scale automatic discovery and tracking of SE Attack Campaigns delivered via Malicious Advertisements (SEACMA). Our system aims to be generic, allowing us to study the SEACMA ad distribution problem without being biased towards specific categories of ad-publishing websites or SE Attacks. Starting with a seed of low-tier ad networks, we measure which of these networks are the most likely to distribute malicious ads and propose a mechanism to discover new ad networks that are also leveraged to support the distribution of SEACMA campaigns. The results of our study aim to be useful in a number of ways. For instance, we show that SEACMA ads use a number of tactics to successfully evade URL blacklists and ad blockers. By tracking SEACMA campaigns, our system provides a mechanism to more proactively detect and block such evasive ads. Therefore, our results provide valuable information that could be used to improve defense systems against Social Engineering Attacks and malicious ads in general.

  • Internet Measurement Conference - What You See is NOT What You Get: Discovering and Tracking Social Engineering Attack Campaigns
    Proceedings of the Internet Measurement Conference, 2019
    Co-Authors: Phani Vadrevu, Roberto Perdisci
    Abstract:

    Malicious ads often use Social Engineering (SE) tactics to coax users into downloading unwanted software, purchasing fake products or services, or giving up valuable personal information. These ads are often served by low-tier ad networks that may not have the technical means (or simply the will) to patrol the ad content they serve to curtail abuse. In this paper, we propose a system for large-scale automatic discovery and tracking of SE Attack Campaigns delivered via Malicious Advertisements (SEACMA). Our system aims to be generic, allowing us to study the SEACMA ad distribution problem without being biased towards specific categories of ad-publishing websites or SE Attacks. Starting with a seed of low-tier ad networks, we measure which of these networks are the most likely to distribute malicious ads and propose a mechanism to discover new ad networks that are also leveraged to support the distribution of SEACMA campaigns. The results of our study aim to be useful in a number of ways. For instance, we show that SEACMA ads use a number of tactics to successfully evade URL blacklists and ad blockers. By tracking SEACMA campaigns, our system provides a mechanism to more proactively detect and block such evasive ads. Therefore, our results provide valuable information that could be used to improve defense systems against Social Engineering Attacks and malicious ads in general.

Alexander L. Tulupyev - One of the best experts on this subject based on the ideXlab platform.

  • Employees’ Social Graph Analysis: A Model of Detection the Most Criticality Trajectories of the Social Engineering Attack’s Spread
    Advances in Intelligent Systems and Computing, 2020
    Co-Authors: Anastasiia O. Khlobystova, Maxim V. Abramov, Alexander L. Tulupyev
    Abstract:

    In this research we present the hybrid model of finding the most critical distribution trajectories of multipath Social Engineering Attacks, passing through which by the malefactor on a global basis has the topmost degree of probability and will bring the greatest loss to the company. The solution of search problem concerning the most critical trajectories rests upon the assumption that the estimated probabilities of the direct Social Engineering Attack on user, degree evaluation of documents’ criticality, the estimated probabilities of Social Engineering Attack’s distribution from user to user are premised on linguistic indistinct variables are already calculated. The described model finds its application at creation when constructing the estimates of information systems users’ safety against Social Engineering Attacks and promotes well-timed informing of decision-makers on the vulnerabilities which being available in system.

  • Soft Estimates for Social Engineering Attack Propagation Probabilities Depending on Interaction Rates Among Instagram Users
    Intelligent Distributed Computing XIII, 2020
    Co-Authors: Anastasiia O. Khlobystova, Mikhajlovich Valerij Abramov, Alexander L. Tulupyev
    Abstract:

    The purpose of this article is to propose an approach to denoting the parameters of the model for assessing the probability of success of a multi-pass Social Engineering Attack of an Attacker on a user. These parameters characterize the evaluation of the probability of propagation of Social Engineering Attacks from user to user in one type of interaction. These estimates are related to the intensity of user interaction, information about which is extracted from data obtained from Social Media. The article proposes an approach to the conversion of information about the episodes of interaction between users in the Social Media Instagram in assessing the probability of the spread of Social Engineering Attack, based on the Khovanov method. The obtained results help produce Social network analysis and serve as a basis for the subsequent analysis of possible trajectories of the spread of multi-pass Social Engineering Attacks, allowing the simulation of Social Engineering Attacks and automated calculation of estimates of the success of the Attack on different trajectories. The novelty of the research is to the application quantification method to Social links in the context of Social Engineering Attacks.

  • employees Social graph analysis a model of detection the most criticality trajectories of the Social Engineering Attack s spread
    International Conference on Intelligent Information Technologies for Industry, 2019
    Co-Authors: Anastasiia O. Khlobystova, Maxim V. Abramov, Alexander L. Tulupyev
    Abstract:

    In this research we present the hybrid model of finding the most critical distribution trajectories of multipath Social Engineering Attacks, passing through which by the malefactor on a global basis has the topmost degree of probability and will bring the greatest loss to the company. The solution of search problem concerning the most critical trajectories rests upon the assumption that the estimated probabilities of the direct Social Engineering Attack on user, degree evaluation of documents’ criticality, the estimated probabilities of Social Engineering Attack’s distribution from user to user are premised on linguistic indistinct variables are already calculated. The described model finds its application at creation when constructing the estimates of information systems users’ safety against Social Engineering Attacks and promotes well-timed informing of decision-makers on the vulnerabilities which being available in system.

  • IDC - Soft Estimates for Social Engineering Attack Propagation Probabilities Depending on Interaction Rates Among Instagram Users
    Intelligent Distributed Computing XIII, 2019
    Co-Authors: Anastasiia O. Khlobystova, Maxim V. Abramov, Alexander L. Tulupyev
    Abstract:

    The purpose of this article is to propose an approach to denoting the parameters of the model for assessing the probability of success of a multi-pass Social Engineering Attack of an Attacker on a user. These parameters characterize the evaluation of the probability of propagation of Social Engineering Attacks from user to user in one type of interaction. These estimates are related to the intensity of user interaction, information about which is extracted from data obtained from Social Media. The article proposes an approach to the conversion of information about the episodes of interaction between users in the Social Media Instagram in assessing the probability of the spread of Social Engineering Attack, based on the Khovanov method. The obtained results help produce Social network analysis and serve as a basis for the subsequent analysis of possible trajectories of the spread of multi-pass Social Engineering Attacks, allowing the simulation of Social Engineering Attacks and automated calculation of estimates of the success of the Attack on different trajectories. The novelty of the research is to the application quantification method to Social links in the context of Social Engineering Attacks.

  • Search for the shortest trajectory of a Social engeneering Attack between a pair of users in a graph with transition probabilities
    Information and Control Systems, 2018
    Co-Authors: Anastasiia O. Khlobystova, Mikhajlovich Valerij Abramov, Alexander L. Tulupyev, Andrey A. Zolotin
    Abstract:

    Introduction: Social Engineering Attacks can be divided into two types: direct (one-way) and multi-pass ones, passing through a chain of users. Normally, there are several propagation paths for a multi-pass Social Engineering Attack between two users. Estimates of the probabilities of an Attack to spread along different trajectories will differ. Purpose: Identification of the most critical (most probable) trajectory for a multi-pass Social Engineering Attack between two users. Methods: Methods of searching, matching and algorithm analysis are used to identify the most critical trajectory of Attack propagation. They apply the information about the intensity of the interaction between employees in companies based on data extracted from Social networks. These algorithms are reduced, using a number of transformations of the original data, to the algorithms of finding the shortest path in a graph. The estimates of a multi-path Social Engineering Attack success probability are calculated with the methods of constructing an estimate of a complex event probability. Results: We have proposed an approach to identifying the most critical trajectories, whose estimate of the Attack success probability is the highest. In the simplest case, the problem can be reduced to finding a path in the graph with the maximum product of the weights of all the edges involved. The resource intensity of the algorithm when searching for the most critical trajectory on a complete graph with a large number of vertices can be reduced with a specially developed technique. A brief overview of the methods and algorithms providing automated search for the most critical propagation path of a Social Engineering Attack showed that in a general case it can be reduced, with some transformations, to the problem of finding the most critical trajectory using the configuration of Dijkstra and Bellman — Ford algorithms. The chosen algorithm was adapted for the specified context, and an approach was proposed to thin out the graph when searching for the most critical trajectory. The presented methods and algorithms are implemented in software code. Numerical experiments were performed to verify the calculation results. Practical relevance: The developed software based on the method and algorithm proposed in this article complements the functionality of the previous versions of software prototypes for analyzing the protection of information system users against Social Engineering Attacks. It allows you to take into account a wider range of factors affecting the assessment of Social Engineering Attack success probability.