Development of Risk Assessment Indices for Social Engineering Attacks

Dong Cheon Shin, Young Hoo Park
2017 Journal of Security Engineering  
Due to the development of system performance and security technology, the first target of recent security attacks tends to be the people who operate the system, rather than the system itself. Therefore, one of the most crucial vulnerabilities is the people, which reflects the need for the human-centric security. To the best our knowledge, however, there is no previous works for such social engineering attacks through the analysis of risk assessment. In this paper, first we analyze the
more » ... es of social engineering attacks and methodologies for common vulnerability assessment such as CVSS, CWSS, OWSAP Risk Rating Methodology. Then, based on the analysis, we develop risk assesment indexes for social engineering attacks.
doi:10.14257/jse.2017.04.01 fatcat:vet6k4ur25e7jgqb4pvpm2mfji