为STEM学生和从业者提供的社会工程意识和培训研讨会

Aunshul Rege, T. Nguyen, Rachel Bleiman
{"title":"为STEM学生和从业者提供的社会工程意识和培训研讨会","authors":"Aunshul Rege, T. Nguyen, Rachel Bleiman","doi":"10.1109/ISEC49744.2020.9280596","DOIUrl":null,"url":null,"abstract":"The human element is often regarded as the weakest link in cybersecurity, yet awareness and training efforts focus primarily on the technical aspects of cybersecurity and downplay the relevance of the human factor. One way to exploit this human vulnerability is through social engineering, in which cybercriminals utilize persuasion and manipulation of human behavior and psychology to convince individuals to reveal information, provide access or perform an action. This paper offers a case study on efforts to design and develop a social engineering awareness and training program that was implemented at the 2019 National Science Foundation Cybersecurity Summit using the National Institute of Standards and Technology framework for program development. This program was developed to enhance the ability for individuals in the future and current workforce to protect their organization against vulnerabilities to social engineering attacks, through corresponding awareness and training. The authors share the different stages that are involved in producing a successful program: designing the program, developing the awareness and training material, and implementing the program. In addition, this paper details the challenges and lessons the authors experienced and learned, which can be used as a guide for other practitioners to develop social engineering awareness and training programs.","PeriodicalId":355861,"journal":{"name":"2020 IEEE Integrated STEM Education Conference (ISEC)","volume":"30 12","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A social engineering awareness and training workshop for STEM students and practitioners\",\"authors\":\"Aunshul Rege, T. Nguyen, Rachel Bleiman\",\"doi\":\"10.1109/ISEC49744.2020.9280596\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The human element is often regarded as the weakest link in cybersecurity, yet awareness and training efforts focus primarily on the technical aspects of cybersecurity and downplay the relevance of the human factor. One way to exploit this human vulnerability is through social engineering, in which cybercriminals utilize persuasion and manipulation of human behavior and psychology to convince individuals to reveal information, provide access or perform an action. This paper offers a case study on efforts to design and develop a social engineering awareness and training program that was implemented at the 2019 National Science Foundation Cybersecurity Summit using the National Institute of Standards and Technology framework for program development. This program was developed to enhance the ability for individuals in the future and current workforce to protect their organization against vulnerabilities to social engineering attacks, through corresponding awareness and training. The authors share the different stages that are involved in producing a successful program: designing the program, developing the awareness and training material, and implementing the program. In addition, this paper details the challenges and lessons the authors experienced and learned, which can be used as a guide for other practitioners to develop social engineering awareness and training programs.\",\"PeriodicalId\":355861,\"journal\":{\"name\":\"2020 IEEE Integrated STEM Education Conference (ISEC)\",\"volume\":\"30 12\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-08-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 IEEE Integrated STEM Education Conference (ISEC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ISEC49744.2020.9280596\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE Integrated STEM Education Conference (ISEC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISEC49744.2020.9280596","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

人的因素通常被认为是网络安全中最薄弱的环节,然而意识和培训工作主要集中在网络安全的技术方面,而低估了人的因素的相关性。利用这一人类弱点的一种方法是通过社会工程,网络罪犯利用说服和操纵人类行为和心理来说服个人透露信息、提供访问权限或执行某项行动。本文提供了一个案例研究,介绍了在2019年国家科学基金会网络安全峰会上使用国家标准与技术研究所框架进行计划开发的社会工程意识和培训计划的设计和开发工作。该计划旨在通过相应的意识和培训,提高个人和当前劳动力的能力,以保护他们的组织免受社会工程攻击的脆弱性。作者分享了制定一个成功的计划所涉及的不同阶段:设计计划,开发意识和培训材料,以及实施计划。此外,本文还详细介绍了作者所经历和学习到的挑战和教训,可以作为其他实践者发展社会工程意识和培训计划的指南。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A social engineering awareness and training workshop for STEM students and practitioners
The human element is often regarded as the weakest link in cybersecurity, yet awareness and training efforts focus primarily on the technical aspects of cybersecurity and downplay the relevance of the human factor. One way to exploit this human vulnerability is through social engineering, in which cybercriminals utilize persuasion and manipulation of human behavior and psychology to convince individuals to reveal information, provide access or perform an action. This paper offers a case study on efforts to design and develop a social engineering awareness and training program that was implemented at the 2019 National Science Foundation Cybersecurity Summit using the National Institute of Standards and Technology framework for program development. This program was developed to enhance the ability for individuals in the future and current workforce to protect their organization against vulnerabilities to social engineering attacks, through corresponding awareness and training. The authors share the different stages that are involved in producing a successful program: designing the program, developing the awareness and training material, and implementing the program. In addition, this paper details the challenges and lessons the authors experienced and learned, which can be used as a guide for other practitioners to develop social engineering awareness and training programs.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信