Skip to main content

Social Engineering: Bridging the Gap Between Psychology and Cybersecurity

Page 1

International Research Journal of Engineering and Technology (IRJET)

e-ISSN: 2395-0056

Volume: 12 Issue: 01 | Jan 2025

p-ISSN: 2395-0072

www.irjet.net

Social Engineering: Bridging the Gap Between Psychology and Cybersecurity Vishwashree Karhadkar1, Reshma Kale1, Chandrakanth Talakokkula1, Salal Ali Khan1 1Master’s Students at St. Francis Xavier University

---------------------------------------------------------------------***---------------------------------------------------------------------

Abstract - Social engineering is a type of deceptive

assaults, hardware or software solutions will not be able to prevent these kinds of attacks. Cybercriminals opted for these attacks when they couldn't break into a system with no technical weaknesses[1].

human behaviour technique used in computer and network security which modifies user mindsets intending to cause harm to users or organizational assets. It consists of various phases applied in this type of attack explaining various types of active and passive attacks which come under social engineering like Phishing, Smishing, and Whaling etc. This type of attack can only be mitigated through proper training and awareness of the users. The following paper discusses from the basics of what is Social Engineering its type and ways of attacks, with that it also give us an idea about the defence mechanism, prevention methods and challenges available which can be implemented to prevent attacks happening under social engineering. This paper also explains the approaches that the corporate world can implement for the employees to have an idea of what and how social engineering attacks look like so they can be prevented.

Major corporations and media outlets have experienced targeted cyber attacks on their information systems, showcasing the vulnerability of even well-established entities. Google faced a significant breach in 2009, RSA's security token system was compromised in 2011, and Facebook encountered a breach in 2013, along with the New York Times. Instances of PayPal customers receiving phishing emails and inadvertently providing attackers with sensitive information, including credit card numbers, further highlight the severity of these cyber threats. Such recent incidents involving valuable assets are commonly identified as Advanced Persistent Threats[3]. Even though social engineering attacks may follow different processes, they all follow a similar pattern. The described approach involves four distinct stages: 1) acquiring information about the target, 2) establishing a connection with the target, 3) employing gathered information to execute the attack, and 4) ensuring the absence of any detectable traces. Figure 1 illustrates the four phases of a social engineering attack[1].

Key Words: Social engineering, Human Behaviour, Physio-logical behaviour, Manipulation, Harm, Assets, Ethical perspective, Defence mechanism.

1. INTRODUCTION Social engineering attacks are growing more frequent these days, making cyber security less effective. Social engineering is the practice of using trust-building techniques to manipulate people and organizations to get them to divulge private information like Social Security numbers and financial details[1]. Social engineering assaults occur frequently when victims click on emails that contain malicious links, receive banking SMS requests for credentials that aren't really from the bank, or receive physical impersonation attempts from people in positions of power[2]. Even with the effectiveness of firewalls, antivirus programs, intrusion detection systems, and cryptographic techniques, the danger to cybersecurity remains substantial. Humans trust other humans rather than trusting computers or technologies, this makes humans the most vulnerable link to cybersecurity.

Figure-1: Phases of Social Engineering Attack[1]

1.1 Phases of Social Engineering 1.1.1. Acquiring information about the target

Taking this as an advantage, cyber criminals manipulate human minds making them reveal their personal information which compromises cybersecurity. Until people are trained to avoid falling for social engineering

© 2025, IRJET

|

Impact Factor value: 8.315

An attacker can use various methods to gather information about their targets. Once they have this information, they can use it to build a connection with the target or someone important for the success of the attack.

|

ISO 9001:2008 Certified Journal

|

Page 308


Turn static files into dynamic content formats.

Create a flipbook