USER AWARENESS MEASUREMENT THROUGH SOCIAL ENGINEERING
USER AWARENESS MEASUREMENT THROUGH SOCIAL ENGINEERING
Tolga MATARACIOGLU1 and Sevgi OZKAN2 1TUBITAK
National Research Institute of Electronics and Cryptology (UEKAE), Department of Information Systems Security, 06700, Ankara, TURKEY 2Middle East Technical University, Informatics Institute, Department of Information Systems, 06531, Ankara, TURKEY
ABSTRACT
TUBITAK National Research Institute of Electronics and Cryptology (UEKAE) Department of Information Systems Security makes social engineering attacks to Turkish public agencies within the frame of “Information Security Tests” [19]. This paper will make an analysis of the social engineering tests that have been carried out in several Turkish public agencies. The tests include phone calling to sample employees by the social engineer and trying to seize employees’ sensitive information by exploiting their good faith. The aim of this research is to figure that the employees in Turkish public agencies have a lack of information security awareness and they compromise the information security principles which should be necessarily applied for any public agencies. Social engineering, both with its low cost and ability to take advantage of low technology, has taken its place in the information security literature as a very effective form of attack [8].
KEYWORDS
User Behavior, Social Engineering, Information Security Awareness, Public Agency, Information Security Test
https://airccse.org/journal/mvsc/papers/1210ijmvsc02.pdf
Comments
Post a Comment