Suppr超能文献

从社会工程网络攻击视角看人类认知

Human Cognition Through the Lens of Social Engineering Cyberattacks.

作者信息

Montañez Rosana, Golob Edward, Xu Shouhuai

机构信息

Department of Computer Science, University of Texas at San Antonio, San Antonio, TX, United States.

Department of Psychology, University of Texas at San Antonio, San Antonio, TX, United States.

出版信息

Front Psychol. 2020 Sep 30;11:1755. doi: 10.3389/fpsyg.2020.01755. eCollection 2020.

Abstract

Social engineering cyberattacks are a major threat because they often prelude sophisticated and devastating cyberattacks. Social engineering cyberattacks are a kind of psychological attack that exploits weaknesses in human cognitive functions. Adequate defense against social engineering cyberattacks requires a deeper understanding of what aspects of human cognition are exploited by these cyberattacks, why humans are susceptible to these cyberattacks, and how we can minimize or at least mitigate their damage. These questions have received some amount of attention, but the state-of-the-art understanding is superficial and scattered in the literature. In this paper, we review human cognition through the lens of social engineering cyberattacks. Then, we propose an extended framework of human cognitive functions to accommodate social engineering cyberattacks. We cast existing studies on various aspects of social engineering cyberattacks into the extended framework, while drawing a number of insights that represent the current understanding and shed light on future research directions. The extended framework might inspire future research endeavor toward a new sub-field that can be called , which tailors or adapts principles of Cognitive Psychology to the cybersecurity domain while embracing new notions and concepts that are unique to the cybersecurity domain.

摘要

社会工程网络攻击是一个重大威胁,因为它们常常是复杂且具有破坏性的网络攻击的前奏。社会工程网络攻击是一种利用人类认知功能弱点的心理攻击。要对社会工程网络攻击进行充分防御,需要更深入地了解这些网络攻击利用了人类认知的哪些方面、人类为何易受这些网络攻击影响,以及我们如何能够将其损害降至最低或至少减轻。这些问题已受到一定程度的关注,但目前的理解较为肤浅且分散于文献之中。在本文中,我们从社会工程网络攻击的视角审视人类认知。然后,我们提出一个扩展的人类认知功能框架以适应社会工程网络攻击。我们将现有的关于社会工程网络攻击各方面的研究纳入该扩展框架,同时得出一些见解,这些见解代表了当前的理解并为未来的研究方向提供启示。这个扩展框架可能会激发未来朝着一个可称为 的新子领域开展研究工作,该领域将认知心理学原理调整或应用于网络安全领域,同时接纳网络安全领域特有的新观念和概念。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/9693/7554349/9531f6042b36/fpsyg-11-01755-g0001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验