The Threat of Social Engineering and the Safety of Companies
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F70883521%3A28140%2F21%3A63541578" target="_blank" >RIV/70883521:28140/21:63541578 - isvavai.cz</a>
Result on the web
<a href="https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9668755" target="_blank" >https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9668755</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/CSCC53858.2021.00030" target="_blank" >10.1109/CSCC53858.2021.00030</a>
Alternative languages
Result language
angličtina
Original language name
The Threat of Social Engineering and the Safety of Companies
Original language description
Social engineering is a method of attack aimed at the state, organization, or individual. It focuses on the weakest point in the use of information and communication technologies, specifically the human factor. The article deals with the issue of social engineering with a focus on the attack and the possibilities of defense against it in a commercial and manufacturing company. Several questionnaire studies were conducted, which found that only a small number of staff had been trained in the past against similar attacks. Companies still underestimate their protection, investing in new technologies, but already investing less in training employees who use them. At the same time, social engineering largely focuses on them. The article, therefore, identifies social engineering, its ways of carrying out the attack. Furthermore, the article briefly summarizes its threats as well as its history, along with an overview of the first attacks. For greater orientation in practice, the individual types of attackers, the progress of their attacks, and the relevant technical aspects are described here. An analysis of the current state of safety in the existing manufacturing and trading company was performed, namely, the specific directives that are currently in force. These were compared with current needs and appropriate measures were proposed. Based on this analysis, recommendations for improving the state of security against social engineering attacks in all companies, in general, are described at the end of the article. The most frequently used methods in practice are listed according to the survey, followed by the establishment of safety recommendations. Individual technologies are constantly evolving, newer applications are being launched on the market, and at the same time, more advanced methods for data protection need to be developed.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
—
Continuities
S - Specificky vyzkum na vysokych skolach
Others
Publication year
2021
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings - 25th International Conference on Circuits, Systems, Communications and Computers, CSCC 2021
ISBN
978-166542749-4
ISSN
—
e-ISSN
—
Number of pages
8
Pages from-to
126-133
Publisher name
IEEE Computer Society
Place of publication
Los Alamitors
Event location
Chania
Event date
Jul 19, 2021
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—