Social engineering in cybersecurity: The evolution of a concept

Social engineering in cybersecurity: The evolution of a concept
复制标题

DOI:
10.1016/j.cose.2017.10.008
复制
发表时间:
2018-03-01
影响因子:
5.6
通讯作者:
Hatfield, Joseph M.
Hatfield, Joseph M.
中科院分区:
计算机科学3区
文献类型:
--
作者:
Hatfield, Joseph M.

文献摘要

被引文献

相似文献

本文介绍了网络安全中社会工程概念的历史,并认为虽然该术语最初出现在政治研究中,后来才在网络安全领域得到使用,但这些都是相同基本思想的应用:认知不对称、技术统治主导地位和目的论替代。该论文进一步认为,该术语在这两个领域的用法在概念和语义上仍然是相互关联的。此外,对这种相互关系的无知继续阻碍我们识别和拒绝网络空间中的社会工程攻击的能力。该论文的概念历史始于十九世纪经济学家约翰·格雷和索尔斯坦·凡勃伦的著作。对学术文章的分析表明,这一概念在整个二十世纪早期到中期在社会科学内外广泛传播。然后,本文利用学术出版物和回忆录,包括对当时活跃的黑客社区参与者的采访,追溯了 20 世纪 60 年代至 1980 年代这一概念向网络安全的转变。最后,它通过分析 1990 年至 2017 年有关网络安全的学术文章中的 134 个术语定义,揭示了一系列当代内涵的概念。由 Elsevier Ltd 出版。
This paper offers a history of the concept of social engineering in cybersecurity and argues that while the term began its life in the study of politics, and only later gained usage within the domain of cybersecurity, these are applications of the same fundamental ideas: epistemic asymmetry, technocratic dominance, and teleological replacement. The paper further argues that the term's usages in both areas remain conceptually and semantically interrelated. Moreover, ignorance of this interrelation continues to handicap our ability to identify and rebuff social engineering attacks in cyberspace. The paper's conceptual history begins in the nineteenth-century in the writings of the economists John Gray and Thorstein Veblen. An analysis of scholarly articles shows the concept's proliferation throughout the early to mid twentieth century within the social sciences and beyond. The paper then traces the concept's migration into cybersecurity through the 1960s-1980s utilizing both scholarly publications and memoir accounts - including interviews with then-active participants in the hacker community. Finally, it reveals a conceptual array of contemporary connotations through an analysis of 134 definitions of the term found in academic articles written about cybersecurity from 1990 to 2017. Published by Elsevier Ltd.