Emerging Science Journal
Vol 8, No 2 (2024): April

Common Techniques, Success Attack Factors and Obstacles to Social Engineering: A Systematic Literature Review

António Lopes (ESCE IPS - Polytechnic Institute of Setúbal, Setúbal,)
Henrique S. Mamede (2) Institute for Systems and Computer Engineering, Technology and Science (INESC TEC), Porto, Portugal. 3) Department of Science and Technology, Universidade Aberta, Lisbon,)
Leonilde Reis (ESCE IPS - Polytechnic Institute of Setúbal, Setúbal,)
Arnaldo Santos (2) Institute for Systems and Computer Engineering, Technology and Science (INESC TEC), Porto, Portugal. 3) Department of Science and Technology, Universidade Aberta, Lisbon,)



Article Info

Publish Date
01 Apr 2024

Abstract

Knowledge of Social Engineering is crucial to prevent potential attacks related to organizational Information Security. The objective of this paper aims to identify the most common social engineering techniques, success attack factors, and obstacles, as well as the good practices and frameworks that could be adopted concerning their mitigation. As an analysis methodology, a Systematic Literature Review was carried out. The findings revealed that the discussion about SE attacks has increased and that the most imminent threat is phishing. Exploiting human vulnerabilities is a growing threat when the attack is not carried out directly through technical means. There continue to be more technical attacks than non-technical attacks. Encouraging organizational security prevention, like training, education, technical controls, process development, defense in detail, and the development of security policies, should be considered mitigating factors for the negative impact of SE attacks. Most SE frameworks/models are focused on attack techniques and methods, mostly on technical components, decorating human factor. As a novelty, we found the opportunity to develop a new framework that could improve coverage of the gaps found, supported on security international standards, that could help and support researchers in developing their work, understanding open research topics, and providing a clearer understanding of this type of threat. Doi: 10.28991/ESJ-2024-08-02-025 Full Text: PDF

Copyrights © 2024






Journal Info

Abbrev

ESJ

Publisher

Subject

Environmental Science

Description

Emerging Science Journal is not limited to a specific aspect of science and engineering but is instead devoted to a wide range of subfields in the engineering and sciences. While it encourages a broad spectrum of contribution in the engineering and sciences. Articles of interdisciplinary nature are ...