상세 보기
사회공학 공격에 대한 기업조직의 위험 수준 평가 방안
- 박영후;
- 신동천
초록
Recently security related attacks occur in very diverse ways, aiming at people who operate the system rather than the system itself by exploiting vulnerabilities of the system. However, to the our best knowledge, there has been very few works to analyze and strategically to deal with the risks of social engineering attacks targeting people. In this paper, in order to access risks of social engineering attacks we analyze those attacks in terms of attack routes, attack means, attack steps, attack tools, attack goals. Then, with the purpose of accessing the organizational risks we consider the characteristics and environments of the organizations because the impacts of attacks on the organizations obviously depend on the characteristics and environments of the organizations. In addition, we analyze general attack risk assessment methods such as CVSS, CWSS, and OWASP Risk Rating Methodolog. Finally, we propose the risk access scheme of social engineering attacks for the organizations. The proposed scheme allows each organization to take its own proper actions to address social engineering attacks according to the changes of its environments.
키워드
- 제목
- 사회공학 공격에 대한 기업조직의 위험 수준 평가 방안
- 제목 (타언어)
- A Risk Assessment Scheme of Social Engineering Attacks for Enterprise Organizations
- 저자
- 박영후; 신동천
- 발행일
- 2019-03
- 저널명
- 융합보안 논문지
- 권
- 19
- 호
- 1
- 페이지
- 103 ~ 110