Triggering Empathy out of Malicious Intent: The Role of Empathy in Social Engineering Attacks

Verena Distler, Yasmeen Abdrabou, Felix Dietz, Florian Alt
{"title":"Triggering Empathy out of Malicious Intent: The Role of Empathy in Social Engineering Attacks","authors":"Verena Distler, Yasmeen Abdrabou, Felix Dietz, Florian Alt","doi":"10.1145/3588967.3588969","DOIUrl":null,"url":null,"abstract":"Social engineering is a popular attack vector among cyber criminals. During such attacks, impostors often attempt to trigger empathy to manipulate victims into taking dangerous actions, for example, sharing their credentials or clicking on malicious email attachments. The objective of this position paper is to initiate a conversation on the tension between positive and negative aspects of empathy in HCI as it pertains to security-relevant behaviors. To this end, we focus on the malicious ways in which empathy can be instrumentalized in social engineering. We describe examples of such empathy-related social engineering attacks, explore potential solutions (including the automated detection of empathy-triggering communication, or of empathetic communication on the part of a potential victim), and discuss technical, social as well as organizational interventions. We highlight research challenges and directions for future work.","PeriodicalId":199967,"journal":{"name":"Proceedings of the 2nd Empathy-Centric Design Workshop","volume":"39 23","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-04-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2nd Empathy-Centric Design Workshop","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3588967.3588969","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Social engineering is a popular attack vector among cyber criminals. During such attacks, impostors often attempt to trigger empathy to manipulate victims into taking dangerous actions, for example, sharing their credentials or clicking on malicious email attachments. The objective of this position paper is to initiate a conversation on the tension between positive and negative aspects of empathy in HCI as it pertains to security-relevant behaviors. To this end, we focus on the malicious ways in which empathy can be instrumentalized in social engineering. We describe examples of such empathy-related social engineering attacks, explore potential solutions (including the automated detection of empathy-triggering communication, or of empathetic communication on the part of a potential victim), and discuss technical, social as well as organizational interventions. We highlight research challenges and directions for future work.
从恶意意图触发共情:共情在社会工程攻击中的作用
社会工程是网络犯罪分子常用的攻击手段。在这类攻击中,冒名顶替者经常试图触发受害者的同理心,操纵受害者采取危险行动,例如,分享他们的凭证或点击恶意电子邮件附件。本立场文件的目的是就HCI中涉及安全相关行为的共情的积极方面和消极方面之间的紧张关系展开对话。为此,我们将关注移情在社会工程中被工具化的恶意方式。我们描述了这种与移情相关的社会工程攻击的例子,探索了潜在的解决方案(包括自动检测移情触发通信,或潜在受害者的移情通信),并讨论了技术,社会和组织干预措施。我们强调了未来工作的研究挑战和方向。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信