[论文解读] Human Cognition through the Lens of Social Engineering Cyberattacks
本文提出了一种扩展的认知框架,系统分析社会工程网络攻击如何利用人类认知,引入一个数学模型以量化说服力,基于受害者因素(例如工作量、注意力、知识)和攻击者努力程度。其主要贡献在于奠定了网络信息安全认知心理学的基础,强调易感性由认知负荷和无意识处理驱动,而不仅仅是意识或性别因素。
Social engineering cyberattacks are a major threat because they often prelude sophisticated and devastating cyberattacks. Social engineering cyberattacks are a kind of psychological attack that exploits weaknesses in human cognitive functions. Adequate defense against social engineering cyberattacks requires a deeper understanding of what aspects of human cognition are exploited by these cyberattacks, why humans are susceptible to these cyberattacks, and how we can minimize or at least mitigate their damage. These questions have received some amount of attention but the state-of-the-art understanding is superficial and scattered in the literature. In this paper, we review human cognition through the lens of social engineering cyberattacks. Then, we propose an extended framework of human cognitive functions to accommodate social engineering cyberattacks. We cast existing studies on various aspects of social engineering cyberattacks into the extended framework, while drawing a number of insights that represent the current understanding and shed light on future research directions. The extended framework might inspire future research endeavors towards a new sub-field that can be called Cybersecurity Cognitive Psychology, which tailors or adapts principles of Cognitive Psychology to the cybersecurity domain while embracing new notions and concepts that are unique to the cybersecurity domain.
研究动机与目标
- 通过社会工程网络攻击的视角系统化人类认知,此类问题在心理学和网络信息安全研究中常被忽视。
- 解决人类为何易受社会工程攻击的理解空白,通过分析认知、情感和行为因素。
- 通过将认知心理学原则应用于网络信息安全情境,提出一个新的跨学科领域——网络信息安全认知心理学。
- 开发一个数学框架,基于受害者和攻击者因素,建模社会工程攻击中说服程度。
- 为未来研究提供指导,推动基于证据、心理上有效的社会工程防御策略。
提出的方法
- 将标准认知心理学框架扩展,纳入网络信息安全特定组件,如攻击者努力程度、欺骗线索和数字交互情境。
- 提出一个数学函数(公式1),表示受害者所体验的说服程度,作为短期认知、长期认知、长期记忆和攻击者努力程度的函数。
- 将现有关于网络钓鱼、精准网络钓鱼和社会媒体操纵研究的发现整合到扩展的认知框架中。
- 利用心理学文献中的见解,识别关键脆弱性因素,如认知工作量、压力、注意力警觉性以及领域知识缺乏。
- 强调无意识处理在有效训练中的作用,主张通过习惯养成而非有意识思考来提升防护能力。
- 建议针对人类受试者研究的伦理标准,特别是在网络钓鱼实验中,引用IRB合规性及既有的伦理准则。
实验结果
研究问题
- RQ1短期和长期认知因素如何影响受害者对社会工程网络攻击的易感性?
- RQ2攻击者努力程度在提升说服水平中扮演什么角色,其与受害者特征的相互作用机制如何?
- RQ3为何意识水平和一般技术知识无法持续降低对社会工程攻击的易感性?
- RQ4文化背景和性别如何影响易感性,这些因素在何种条件下变得显著?
- RQ5哪些训练策略最有效降低易感性,特别是当利用无意识认知处理时?
主要发现
- 高工作量、压力、注意力警觉性低、缺乏领域知识以及缺乏先前经验,会显著增加对社会工程网络攻击的易感性。
- 仅靠意识水平和性别无法降低易感性,表明心理防御措施必须比简单的教育或人口统计假设更为精细。
- 文化背景会影响易感性,表明社会工程攻击可能针对文化规范和价值观进行定制。
- 社会工程攻击的低频发生提高了其有效性,因为受害者不太可能发展出检测习惯。
- 有效的训练应利用高容量的无意识处理,以建立与有意识注意力并行运行的自动预警反应。
- 先前经验对降低易感性的影响取决于该经验是否具有代价(例如真实财务损失);非代价性经验无法显著降低未来易感性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。