论文标题
通过社会工程网络攻击的人类认知
Human Cognition through the Lens of Social Engineering Cyberattacks
论文作者
论文摘要
社会工程网络攻击是一个主要威胁,因为它们经常序曲复杂而毁灭性的网络攻击。社会工程网络攻击是一种心理攻击,可利用人类认知功能的弱点。针对社会工程网络攻击的充分防御需要更深入地了解这些网络攻击的人类认知方面的哪些方面,为什么人类对这些网络攻击敏感,以及我们如何最大程度地减少或至少减轻他们的损害。这些问题引起了一些关注,但最先进的理解是肤浅的,在文献中分散了。在本文中,我们通过社会工程网络攻击的视角回顾了人类认知。然后,我们提出了人类认知功能的扩展框架,以适应社会工程网络攻击。我们将有关社会工程网络攻击的各个方面的现有研究进行了扩展框架,同时绘制了许多见解,这些见解代表了当前的理解并阐明了未来的研究方向。扩展的框架可能会激发未来的研究努力,可以称为网络安全认知心理学,该领域可以量身定制或适应认知心理学的原理对网络安全领域,同时拥抱网络安全域独有的新概念和概念。
Social engineering cyberattacks are a major threat because they often prelude sophisticated and devastating cyberattacks. Social engineering cyberattacks are a kind of psychological attack that exploits weaknesses in human cognitive functions. Adequate defense against social engineering cyberattacks requires a deeper understanding of what aspects of human cognition are exploited by these cyberattacks, why humans are susceptible to these cyberattacks, and how we can minimize or at least mitigate their damage. These questions have received some amount of attention but the state-of-the-art understanding is superficial and scattered in the literature. In this paper, we review human cognition through the lens of social engineering cyberattacks. Then, we propose an extended framework of human cognitive functions to accommodate social engineering cyberattacks. We cast existing studies on various aspects of social engineering cyberattacks into the extended framework, while drawing a number of insights that represent the current understanding and shed light on future research directions. The extended framework might inspire future research endeavors towards a new sub-field that can be called Cybersecurity Cognitive Psychology, which tailors or adapts principles of Cognitive Psychology to the cybersecurity domain while embracing new notions and concepts that are unique to the cybersecurity domain.