Skip to main content
QUICK REVIEW

[论文解读] A Survey on Human and Personality Vulnerability Assessment in Cyber-security: Challenges, Approaches, and Open Issues

Dimitra Papatsaroucha, Yannis Nikoloudakis|arXiv (Cornell University)|Jun 18, 2021
Information and Cyber Security参考文献 110被引用 9
一句话总结

本综述研究了网络安全中的人类与人格相关漏洞,分析了影响用户对社会工程攻击易感性的因素。提出了基于心理、社会和文化特征的用户易感性档案,指出现有评估框架中的不足之处,特别是对内部威胁的忽视,并呼吁采用整合人格与行为因素的持续、动态漏洞评估模型。

ABSTRACT

These days, cyber-criminals target humans rather than machines since they try to accomplish their malicious intentions by exploiting the weaknesses of end users. Thus, human vulnerabilities pose a serious threat to the security and integrity of computer systems and data. The human tendency to trust and help others, as well as personal, social, and cultural characteristics, are indicative of the level of susceptibility that one may exhibit towards certain attack types and deception strategies. This work aims to investigate the factors that affect human susceptibility by studying the existing literature related to this subject. The objective is also to explore and describe state of the art human vulnerability assessment models, current prevention, and mitigation approaches regarding user susceptibility, as well as educational and awareness raising training strategies. Following the review of the literature, several conclusions are reached. Among them, Human Vulnerability Assessment has been included in various frameworks aiming to assess the cyber security capacity of organizations, but it concerns a one time assessment rather than a continuous practice. Moreover, human maliciousness is still neglected from current Human Vulnerability Assessment frameworks; thus, insider threat actors evade identification, which may lead to an increased cyber security risk. Finally, this work proposes a user susceptibility profile according to the factors stemming from our research.

研究动机与目标

  • 分析影响人类对网络攻击(尤其是社会工程攻击)易感性的心理、社会和文化因素。
  • 评估现有网络安全框架中的人类漏洞评估模型,并识别其局限性。
  • 检查当前旨在降低用户相关安全风险的预防、缓解和培训策略。
  • 强调现有框架中缺乏对恶意内部人员行为的评估,这会削弱组织的安全性。
  • 提出一个基于人格与行为特征的综合用户易感性档案,以提升风险评估水平。

提出的方法

  • 对同行评审的关于网络安全中人为因素的研究进行了系统性文献回顾,重点关注人格、信任和欺骗易感性。
  • 对现有的人类漏洞评估模型进行分类,并评估其设计、范围以及在组织安全框架中的整合程度。
  • 分析针对用户行为改变的培训与意识计划及其在降低易感性方面的有效性。
  • 识别现有模型中的关键缺口,特别是缺乏持续评估以及对恶意内部人员行为的排除。
  • 提出一个整合人格特征(例如:可信度、开放性)、社会影响和文化背景的用户易感性档案。
  • 使用定性综合方法,推导出未来研究和动态、自适应漏洞评估框架开发的建议。

实验结果

研究问题

  • RQ1哪些心理、社会和文化因素导致个体对网络攻击的易感性?
  • RQ2当前的人类漏洞评估模型如何构建?其在实际部署中的局限性是什么?
  • RQ3为何现有漏洞评估框架通常忽视内部威胁行为?
  • RQ4当前的培训与意识计划在多大程度上有效降低了用户对社会工程攻击的易感性?
  • RQ5如何利用人格与行为因素设计一种动态、持续的用户易感性档案?

主要发现

  • 人类漏洞评估目前被视为一次性组织评估,而非持续、自适应的过程。
  • 现有框架在很大程度上忽略了恶意内部人员的作用,导致在检测故意用户威胁方面存在关键缺口。
  • 人格特质如信任、开放性和尽责性显著影响个体对社会工程攻击的易感性。
  • 文化与社会因素(包括合作规范和权威认知)在塑造欺骗情境下的用户行为方面起着关键作用。
  • 由于缺乏个性化和动态反馈,当前的培训与意识计划在长期效果上表现有限。
  • 提出基于人格、行为和情境的用户易感性档案,作为未来自适应风险评估系统的基础。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。