DocumentCode
3708343
Title
An analysis of social engineering principles in effective phishing
Author
Ana Ferreira;Gabriele Lenzini
Author_Institution
CINTESIS-Center for Health Technology and Services Research, University of Porto
fYear
2015
fDate
7/1/2015 12:00:00 AM
Firstpage
9
Lastpage
16
Abstract
Phishing is a widespread practice and a lucrative business. It is invasive and hard to stop: a company needs to worry about all emails that all employees receive, while an attacker only needs to have a response from a key person, e.g., a finance or human resources´ responsible, to cause a lot of damages. Some research has looked into what elements make phishing so successful. Many of these elements recall strategies that have been studied as principles of persuasion, scams and social engineering. This paper identifies, from the literature, the elements which reflect the effectiveness of phishing, and manually quantifies them within a phishing email sample. Most elements recognised as more effective in phishing commonly use persuasion principles such as authority and distraction. This insight could lead to better automate the identification of phishing emails and devise more appropriate countermeasures against them.
Keywords
"Electronic mail","Psychology","Security","Internet","Social network services","Decision making"
Publisher
ieee
Conference_Titel
Socio-Technical Aspects in Security and Trust (STAST), 2015 Workshop on
Electronic_ISBN
2325-1697
Type
conf
DOI
10.1109/STAST.2015.10
Filename
7351971
Link To Document