Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Friday, 8 November 2019

More Dangerous Than Malware?

a post by Bob Rankin for his Ask Bob Rankin blog

Most experts writing about computer and Internet security focus on threats found 'out there' in the online sphere, or in the form of malicious hackers with malevolent intentions. The danger is that they will get to you or your computer, and steal or do damage. Most security measures focus on preventing such intrusions. But the greatest threat is not 'out there.' It's much closer than you think. Read on for the answer...

The Biggest Threat?

The Biggest Online Threat?

It's YOU, in fact.

You are human (no matter what your kids or ex-wife says), and have a human mind (or enough of one to get by). Nothing is more capable of causing, or is more likely to cause you trouble. Yet the mind is seldom the subject of information security articles. This is one of those rare reads.

“It ain't what you don’t know that gets you into trouble,” wrote Mark Twain. “it’s what you know for sure that just ain’t so.” Almost every activity that a human performs, including most of what is supposed to be “knowledge work,” is done unconsciously; motions are gone through with blind faith that they will produce the same results they did last time. No attention is paid to what is right in front of you, in your hands.

That is why people click on links in emails that generally look like they’re from their bank; follow the instructions on what generally looks like their banks’ Web sites; and have their accounts emptied by bandits in some third-world country. Had you been paying attention, you would have noticed that your bank’s emails address you by name, not as “Dear Customer…” You would have remembered that your bank has told you, at the time you opened your account and many times since, that it will never ask you for your account password via email, and that you should always use a bookmark or type in the bank's web address. But busy people do not always pay attention.

Continue reading There’s not much more to the the blog post itself but there are lots of links to further information about regular malware, phishing etc.



Thursday, 24 October 2019

Solutions for counteracting human deception in social engineering attacks

an article by Curtis C. Campbell (University of Phoenix, Tempe, Arizona, USA) published in Information Technology & People Volume 32 Issue 5 (2019)

Abstract

Purpose
The purpose of this paper is to investigate the top three cybersecurity issues in organizations related to social engineering and aggregate solutions for counteracting human deception in social engineering attacks.

Design/methodology/approach
A total of 20 experts within Information System Security Association participated in a three-round Delphi study for aggregating and condensing expert opinions. Three rounds moved participants toward consensus for solutions to counteract social engineering attacks in organizations.

Findings
Three significant issues: compromised data; ineffective practices; and lack of ongoing education produced three target areas for implementing best practices in countering social engineering attacks. The findings offer counteractions by including education, policies, processes and continuous training in security practices.

Research limitations/implications
Study limitations include lack of prior data on effective social engineering defense. Research implications stem from the psychology of human deception and trust with the ability to detect deception.

Practical implications
Practical implications relate to human judgment in complying with effective security policies and programs and consistent education and training. Future research may include exploring financial, operational and educational costs of implementing social engineering solutions.

Social implications
Social implications apply across all knowledge workers who benefit from technology and are trusted to protect organizational assets and intellectual property.

Originality/value
This study contributes to the field of cybersecurity with a focus on trust and human deception to investigate solutions to counter social engineering attacks. This paper adds to under-represented cybersecurity research regarding effective implementation for social engineering defense.




Monday, 11 December 2017

Which phish get caught? An exploratory study of individuals′ susceptibility to phishing

an article by Gregory D. Moody (University of Nevada-Las Vegas, USA), Dennis F. Galletta (University of Pittsburgh, USA) and Brian Kimball Dunn (Utah State University, Logan, USA) published in European Journal of Information Systems Volume 26 Issue 6 (November 2017)

Abstract

Phishing, or the practice of sending deceptive electronic communications to acquire private information from victims, results in significant financial losses to individuals and businesses.

The first goal of this study is to identify situational and personality factors that explain why certain individuals are susceptible to such attacks. The second goal is to test those empirically, along with previously identified factors, to explain the likelihood that an individual will fall victim to a phishing attack.

We employed the Delphi method to identify seven personality factors that may influence this susceptibility (trust, distrust, curiosity, entertainment drive, boredom proneness, lack of focus, and risk propensity). Our regression model included these as well as variables examined in previous studies.

We find that emails sent from a known source significantly increase user susceptibility to phishing, as does a user’s curiosity, risk propensity, general Internet usage, and Internet anxiety.

In post hoc tests, we also find that trust and distrust can be significant predictors of susceptibility and that this significance is dependent on the characteristics of the message.


Sunday, 28 October 2007

A framework of anti-phishing measures aimed at protecting the online consumer's identity

This is an "interest rather than work" article that I found in The Electronic Library (Volume: 25 Issue: 5 Page: 517 - 533) by Rika Butler (University of Stellenbosch, Republic of South Africa)
Abstract:
Purpose
The purpose of this paper is to aim to educate the Internet consumer, who may be a potential phishing victim, and to suggest a framework of anti-phishing measures, following the staggering increase in the number of recent phishing attacks. Phishing describes a method of online identity theft, in which phishers typically pose as legitimate organisations when sending deceptive e-mail messages to internet users. When they respond to such e-mails, victims are lured to malicious web sites, where they are duped into disclosing their personal details. In this way, phishers are able to commit identity theft, with possibly devastating consequences for the victim.
Design/methodology/approach
After a literature review of the available sources, the phishing threat is investigated by analysing the modus operandi of phishers and the basic components of a typical phishing scheme. A possible solution for the phishing problem is examined.
Findings
Phishers continually target the weakest link in the security chain, namely consumers, in their attacks. Educating the online consumer about phishing, as well as the implementation and proper application of anti-phishing measures, are critical steps in protecting the identities of online consumers against e-mail phishing attacks.
Originality/value
This article proposes measures that Internet consumers can take to ward off phishing attacks, as well as remedial actions that they can take after falling victim to such an attack. By implementing these measures online, consumers can minimise the risk of becoming victims of successful phishing attacks, as well as remedy the negative effects of any past disclosure of

Article Type: Literature review
DOI: 10.1108/02640470710829514
Publisher: Emerald Group Publishing Limited