课题基金 / 基金详情

CyberCorps: Capacity Building In Social Engineering Penetration Testing

CyberCorps: Capacity Building In Social Engineering Penetration Testing
Cyber​​Corps:社会工程渗透测试的能力建设
批准号:
1723765
负责人:
Akbar Siami Namin
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-09-01 至 2023-08-31

项目摘要

项目成果

Akbar Siami Namin的其他基金

相似基金

相关文献

中文摘要
翻译
社会工程是使用欺骗方法操纵受害者透露个人信息的行为。社会工程攻击可以通过不同的方法发起,例如有针对性的网络钓鱼/诈骗电子邮件,欺诈性短信,或通过观察一个人的计算机活动,即,“肩膀冲浪。德克萨斯理工大学的这个项目将确定专业和道德黑客发动欺骗性社会工程攻击所需的社会技能。该项目建议:开展实验,以了解社会工程攻击过程中起作用的因素;开发教育材料,将从这些实验中吸取的教训纳入其中;并为学生和教育工作者提供相互练习社会工程攻击战术的机会。通过这些方法,该项目将增加具有网络安全能力的专业人员的数量,使他们能够对系统安全进行更好和更有效的测试。通过该项目,将进行人为因素实验,以了解三种主要社会工程攻击方法的影响因素:i)能够成功发起网络钓鱼攻击的电子邮件的特征,ii)攻击者通过电话欺骗受害者以泄露受害者个人信息时的行为和方式,以及iii)攻击者以获取敏感信息为目的接近受害者时的行为和方式。此外,项目人员将为社会工程学课程编制一套教学单元。这些模块将a)反映人为因素实验的结果,B)包括渗透测试攻击工具包,使学生能够获得此类攻击的实践经验,以及c)包括课程计划,以帮助网络安全专业人员学习社会工程内容并成为更好的渗透测试人员。为了建立社会工程的能力,该项目将为来自全国各地的学生和教育工作者提供专业发展研讨会,展示这项研究的成果。这些讲习班将为学生和教育工作者提供一个机会,使他们能够获得社会工程技能的实践经验,以便他们能够更好地了解这些方法的性质和功效,并更好地解决这些问题。
英文摘要
Social engineering is the act of using methods of deception to manipulate victims into revealing personal information. Social engineering attacks can be launched through different methods, such as targeted phishing/scam emails, fraudulent text messages, or by observation of a person's computer activity over their shoulder, i.e., "shoulder surfing." The project from Texas Tech University will identify the social skillsets that professional and ethical hackers need for launching deceptive social engineering attacks. This project proposes to: carry-out experiments to understand factors at play during social engineering attacks; develop of educational materials that incorporate lessons learned from these experiments; and offer opportunities for students and educators to practice social engineering attack-tactics with one another. Through these approaches, the project will increase the number of cybersecurity-capable professionals and enable them to conduct better and more effective tests of security of systems. Through the project, human-factor experiments will be conducted to understand the factors at play on three major social engineering attack methods: i) the characteristics of emails that enable launching successful phishing attacks, ii) the behavior and manner of attackers when deceiving victims through phone calls with the purpose of divulging the victims' personal information, and iii) the behavior and manner of attackers when physically approaching victims with the goal of obtaining sensitive information. In addition, project personnel will develop a set of instructional modules for a course on Social Engineering. Those modules will a) reflect the results of the human-factor experiments, b) include penetration testing attack toolkits that allow students to gain hands-on experience with such attacks, and c) include lesson plans to help cybersecurity professionals learn social engineering content and become better penetration testers. To build a capacity in social engineering, the project will offer professional development workshops for students and educators from across the nation where the results of this research will be showcased. These workshops will provide an opportunity for students and educators to gain hands-on experience with social engineering skills so that they may better understand the nature and efficacy of these approaches, and be better equipped to address them.
期刊论文(23)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1007/s42452-020-2584-8
发表时间: 2020-04
期刊: SN Applied Sciences
影响因子: 2.6
作者: [Neda Tavakoli;Sima Siami‐Namini;Mahdi Adl Khanghah;Fahimeh Mirza Soltani;Akbar Siami Namin]
通讯作者: Neda Tavakoli;Sima Siami‐Namini;Mahdi Adl Khanghah;Fahimeh Mirza Soltani;Akbar Siami Namin
Email Embeddings for Phishing Detection
用于网络钓鱼检测的电子邮件嵌入
DOI: 10.1109/bigdata50022.2020.9377821
发表时间: 2020
期刊: 2020 IEEE International Conference on Big Data (Big Data
影响因子: --
作者: [Gutierrez, Luis Felipe, Abri, Faranak, Armstrong, Miriam, Namin, Akbar Siami, Jones, Keith S.]
通讯作者: Jones, Keith S.
DOI: 10.1109/bigdata50022.2020.9377828
发表时间: 2020-12
期刊: 2020 IEEE International Conference on Big Data (Big Data)
影响因子: --
作者: [Luis Felipe Gutiérrez;Sima Siami‐Namini;Neda Tavakoli;A. Namin]
通讯作者: Luis Felipe Gutiérrez;Sima Siami‐Namini;Neda Tavakoli;A. Namin
Cloud: A Platform to Launch Stealth Attacks
云:发起隐形攻击的平台
DOI: 10.1109/compsac48688.2020.00-33
发表时间: 2020
期刊: and Applications Conference (COMPSAC
影响因子: --
作者: [Chatterjee, Moitrayee, Datta, Prerit, Abri, Faranak, Siami Namin, Akbar, Jones, Keith S.]
通讯作者: Jones, Keith S.
共 16 条
    Collaborative Research: SaTC: CORE: Small: Analytical Models for Conversational Social Engineering Attacks
    • 批准号:
      2319802
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $40.0万
    • 财政年份:
      2023
    • 负责人:
      Akbar Siami Namin
    • 依托单位:
    I-Corps: A Platform to Automatically Measure Users Susceptibility to Social Engineering Attacks
    • 批准号:
      2227704
    • 项目类别:
      Standard Grant
    • 资助金额:
      $5.0万
    • 财政年份:
      2022
    • 负责人:
      Akbar Siami Namin
    • 依托单位:
    SaTC: EDU: Improving Student Learning and Engagement in Digital Forensics through Collaborative Investigation of Cyber Security Incidents and Simulated Capture-the-Flag Exercises
    • 批准号:
      1821560
    • 项目类别:
      Standard Grant
    • 资助金额:
      $30.0万
    • 财政年份:
      2018
    • 负责人:
      Akbar Siami Namin
    • 依托单位:
    SBE: Medium: User-Centric Design of a Sonification System for Automatically Alarming Security Threats and Impact
    • 批准号:
      1564293
    • 项目类别:
      Standard Grant
    • 资助金额:
      $88.92万
    • 财政年份:
      2016
    • 负责人:
      Akbar Siami Namin
    • 依托单位:
    海外基金