SBE: Small: Technological Con-Artistry: An Analysis of Social Engineering
SBE: Small: Technological Con-Artistry: An Analysis of Social Engineering
批准号:
1616804
负责人:
Kevin Steinmetz
金额:
$35.04万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2020-08-31
中文摘要
当今世界对网络空间安全最严重的威胁之一是“社会工程”--通过这个过程,可以接触到有关信息系统安全的关键信息的人被欺骗或操纵,将这些信息交给未经授权的人,从而允许他们访问原本安全的系统。到目前为止,关于社会工程的系统研究还很少。这项研究将通过调查谁是社会工程师,他们为什么从事社会工程,他们用来构思和实施社会工程项目的过程,以及他们如何看待信息隐私和安全以及为自己的行为辩护来填补这一空白。此外,为了了解受社会工程影响的组织如何应对其构成的威胁,本研究还调查了负责组织计算机系统和潜在敏感信息安全的IT专业人员对社会工程的看法。通过更深入和更准确地了解社会工程--这一现象目前笼罩在神话和许多人的误解中--这项研究将有助于犯罪学和其他领域的重要进展,这些领域的既得利益是了解信息安全的人的层面,并为信息安全战略的发展提供信息。本研究采用横断面非实验研究设计,采用定性和定量相结合的研究方法。定性部分包括对社会工程师、安全审计员和IT专业人士的半结构化访谈。开放式面试问题将被用来引出这些数据。此外,这些访谈将被用来收集量化数据,以衡量社会工程师的人口统计、计算机使用和其他社会特征。作为面试过程的一部分,面试官将提出一系列结构化的调查问题。为了选择样本,采用了一种非概率、有目的的“滚雪球”抽样设计,这种设计非常适合于研究“隐藏”人群,如社会工程师。为了分析定性数据,使用了扎根的理论技术,这涉及到将数据转换为概念,然后将概念总结为更广泛的分析类别,导致数据中的模式分离。定量数据将通过一系列单变量、双变量和多变量技术进行分析。
英文摘要
One of the most serious threats in the world today to the security of cyberspace is "social engineering" - the process by which people with access to critical information regarding information systems security are tricked or manipulated into surrendering such information to unauthorized persons, thereby allowing them access to otherwise secure systems. To date, little systematic research has been conducted on social engineering. This research will fill this void by examining who social engineers are, why they engage in social engineering, the processes they use to conceive of and implement social engineering projects, and how they view information privacy and security and justify their behavior. Further, to understand how organizations affected by social engineering cope with the threat it poses, this research also examines the perspectives on social engineering of IT professionals who oversee organizational computer systems and the security of potentially sensitive information. Through gaining a deeper and more accurate understanding of social engineering - a phenomenon currently shrouded in myth and misconception for many - this research will contribute to important advances in criminology and other fields with a vested interest in learning about the human dimensions of information security and inform the development of information security strategies. This study uses a cross-sectional, non-experimental research design that employs both qualitative and quantitative data. The qualitative component involves semi-structured interviews of social engineers "in the wild," security auditors, and IT professionals. Open-ended interview questions will be used to elicit this data. In addition, these interviews will be used to gather quantitative data to measure demographic, computer use, and other social characteristics of social engineers. A set of structured survey questions will be administered by the interviewer as part of the interview process. To select a sample of subjects, a nonprobability, purposive, "snowball" sampling design is used, which is well-suited for studying "hidden" populations such as social engineers. To analyze the qualitative data, grounded theory techniques are used which involve the transformation of data into concepts, which are then summarized into broader analytic categories, leading to the isolation of patterns in the data. Quantitative data will be analyzed through an assortment of univariate, bivariate, and multivariate techniques.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1007/s10612-019-09461-9
发表时间:
2020
期刊:
Critical Criminology
影响因子:
1.8
作者:
[Steinmetz, Kevin F., Pimentel, Alexandra, Goe, W. Richard]
通讯作者:
Goe, W. Richard
The Identification of a Model Victim for Social Engineering: A Qualitative Analysis
社会工程模型受害者的识别:定性分析
DOI:
10.1080/15564886.2020.1818658
发表时间:
2021
期刊:
Victims & Offenders
影响因子:
2.2
作者:
[Steinmetz, Kevin F.]
通讯作者:
Steinmetz, Kevin F.
Collaborative Research: Origins and population history of marine and terrestrial hunter-gatherer groups
-
批准号:2019581
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2020
-
负责人:Kevin Steinmetz
-
依托单位:
SaTC: CORE: Small: Collaborative: Understanding Law-Enforcement Cyber Investigations
-
批准号:1916284
-
项目类别:Standard Grant
-
资助金额:$38.31万
-
财政年份:2019
-
负责人:Kevin Steinmetz
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: