• DocumentCode
    3708343
  • Title

    An analysis of social engineering principles in effective phishing

  • Author

    Ana Ferreira;Gabriele Lenzini

  • Author_Institution
    CINTESIS-Center for Health Technology and Services Research, University of Porto
  • fYear
    2015
  • fDate
    7/1/2015 12:00:00 AM
  • Firstpage
    9
  • Lastpage
    16
  • Abstract
    Phishing is a widespread practice and a lucrative business. It is invasive and hard to stop: a company needs to worry about all emails that all employees receive, while an attacker only needs to have a response from a key person, e.g., a finance or human resources´ responsible, to cause a lot of damages. Some research has looked into what elements make phishing so successful. Many of these elements recall strategies that have been studied as principles of persuasion, scams and social engineering. This paper identifies, from the literature, the elements which reflect the effectiveness of phishing, and manually quantifies them within a phishing email sample. Most elements recognised as more effective in phishing commonly use persuasion principles such as authority and distraction. This insight could lead to better automate the identification of phishing emails and devise more appropriate countermeasures against them.
  • Keywords
    "Electronic mail","Psychology","Security","Internet","Social network services","Decision making"
  • Publisher
    ieee
  • Conference_Titel
    Socio-Technical Aspects in Security and Trust (STAST), 2015 Workshop on
  • Electronic_ISBN
    2325-1697
  • Type

    conf

  • DOI
    10.1109/STAST.2015.10
  • Filename
    7351971