Abdulateef M. Yaser Al-Bustani, Abdulatif Almutairi, Abdullah AlRashed, A. W. Muzaffar
{"title":"基于人格心理学的社会工程——基于人格模式绕过用户提高安全意识","authors":"Abdulateef M. Yaser Al-Bustani, Abdulatif Almutairi, Abdullah AlRashed, A. W. Muzaffar","doi":"10.1109/ITIKD56332.2023.10100048","DOIUrl":null,"url":null,"abstract":"In this research, we applied personality psychology within Social Engineering to raise security awareness and identify the awareness level of the Dominance, Influence, Steadiness, and Conscientiousness (DiSC) Personality Model of William Moulton Marston, 1928. By convincing people to click a scam but safe URL through an email message (URL Phishing) phrased to be convincing based on every person's personality pattern, we were able to effectively conduct this pilot study. This URL forwards the user (or victim) to a safe landing page with a security warning, and countermeasures suggested by the U.S. Department of Homeland Security to apply to avoid falling victim to similar attacks, thus raising security awareness. The first goal of this work was to build and analyze a data set of 86 applicants' that contained their name, age, gender, email, and personality pattern. This information was collected through the RBYG TEST by Abdulateef Al-Bustani, 2020, a short personality test of 3 precisely made questions. Accordingly, based on each applicant's behavioral pattern, several social engineering attack scenarios were applied in two stages, Attack 1 & Attack 2, and vulnerability scores were recorded to identify the awareness level of all behavioral patterns in the DiSC Personality Model. We concluded that the most secure personality pattern with the highest awareness level is “Y” / “Influence”, then “B” / “Conscientious”, then “G” / “Stability”, and the weakest is “R”/ “Dominance”. The results of this study can be used as a guide for organizations to raise security awareness, especially for people with the lowest awareness level.","PeriodicalId":283631,"journal":{"name":"2023 International Conference on IT Innovation and Knowledge Discovery (ITIKD)","volume":"182 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-03-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Social Engineering via Personality Psychology - Bypassing Users Based on Their Personality Pattern To Raise Security Awareness\",\"authors\":\"Abdulateef M. Yaser Al-Bustani, Abdulatif Almutairi, Abdullah AlRashed, A. W. Muzaffar\",\"doi\":\"10.1109/ITIKD56332.2023.10100048\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In this research, we applied personality psychology within Social Engineering to raise security awareness and identify the awareness level of the Dominance, Influence, Steadiness, and Conscientiousness (DiSC) Personality Model of William Moulton Marston, 1928. By convincing people to click a scam but safe URL through an email message (URL Phishing) phrased to be convincing based on every person's personality pattern, we were able to effectively conduct this pilot study. This URL forwards the user (or victim) to a safe landing page with a security warning, and countermeasures suggested by the U.S. Department of Homeland Security to apply to avoid falling victim to similar attacks, thus raising security awareness. The first goal of this work was to build and analyze a data set of 86 applicants' that contained their name, age, gender, email, and personality pattern. This information was collected through the RBYG TEST by Abdulateef Al-Bustani, 2020, a short personality test of 3 precisely made questions. Accordingly, based on each applicant's behavioral pattern, several social engineering attack scenarios were applied in two stages, Attack 1 & Attack 2, and vulnerability scores were recorded to identify the awareness level of all behavioral patterns in the DiSC Personality Model. We concluded that the most secure personality pattern with the highest awareness level is “Y” / “Influence”, then “B” / “Conscientious”, then “G” / “Stability”, and the weakest is “R”/ “Dominance”. The results of this study can be used as a guide for organizations to raise security awareness, especially for people with the lowest awareness level.\",\"PeriodicalId\":283631,\"journal\":{\"name\":\"2023 International Conference on IT Innovation and Knowledge Discovery (ITIKD)\",\"volume\":\"182 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-03-08\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2023 International Conference on IT Innovation and Knowledge Discovery (ITIKD)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ITIKD56332.2023.10100048\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 International Conference on IT Innovation and Knowledge Discovery (ITIKD)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ITIKD56332.2023.10100048","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Social Engineering via Personality Psychology - Bypassing Users Based on Their Personality Pattern To Raise Security Awareness
In this research, we applied personality psychology within Social Engineering to raise security awareness and identify the awareness level of the Dominance, Influence, Steadiness, and Conscientiousness (DiSC) Personality Model of William Moulton Marston, 1928. By convincing people to click a scam but safe URL through an email message (URL Phishing) phrased to be convincing based on every person's personality pattern, we were able to effectively conduct this pilot study. This URL forwards the user (or victim) to a safe landing page with a security warning, and countermeasures suggested by the U.S. Department of Homeland Security to apply to avoid falling victim to similar attacks, thus raising security awareness. The first goal of this work was to build and analyze a data set of 86 applicants' that contained their name, age, gender, email, and personality pattern. This information was collected through the RBYG TEST by Abdulateef Al-Bustani, 2020, a short personality test of 3 precisely made questions. Accordingly, based on each applicant's behavioral pattern, several social engineering attack scenarios were applied in two stages, Attack 1 & Attack 2, and vulnerability scores were recorded to identify the awareness level of all behavioral patterns in the DiSC Personality Model. We concluded that the most secure personality pattern with the highest awareness level is “Y” / “Influence”, then “B” / “Conscientious”, then “G” / “Stability”, and the weakest is “R”/ “Dominance”. The results of this study can be used as a guide for organizations to raise security awareness, especially for people with the lowest awareness level.