0% found this document useful (0 votes)
9 views34 pages

Social Engineering Attackes

The seminar report discusses social engineering attacks, highlighting their increasing threat to organizations and the importance of employee awareness training to mitigate risks. It emphasizes the need for a multi-layered defense approach that combines technological solutions with human factors, as exemplified by significant breaches like those of Yahoo and Sony. The report also outlines various attack methods, their psychological underpinnings, and the critical role of ongoing research and updated strategies in countering these evolving threats.

Uploaded by

vivekdetwal19
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views34 pages

Social Engineering Attackes

The seminar report discusses social engineering attacks, highlighting their increasing threat to organizations and the importance of employee awareness training to mitigate risks. It emphasizes the need for a multi-layered defense approach that combines technological solutions with human factors, as exemplified by significant breaches like those of Yahoo and Sony. The report also outlines various attack methods, their psychological underpinnings, and the critical role of ongoing research and updated strategies in countering these evolving threats.

Uploaded by

vivekdetwal19
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

A SEMINAR REPORT ON

Social Engineering Attacks

Submitted in partial fulfilment for the award of the degree of


Bachelor of Technology
In
Computer Science and Engineering
(Bikaner Technical University, Bikaner)

SESSION (2025 – 2026)

SUBMITTED TO : SUBMITTED BY:


DEPT. OF CSE Chitransh Bhatnagar
Cyber security
8th Semester
22EEACY016

DEPARTMENT OF COMPUTER SCIENCE AND


ENGINEERING ENGINEERING COLLEGE,
AJMER
ACKNOWLEDGEMENT

This is opportunity to express my heartfelt words for the people who were
part of this seminar in numerous ways, people who gave me unending
support right from beginning of the seminar.
I want to give sincere thanks to the principal Dr. Rekha Mehra for her
valuable support.
I extend my thanks to Dr. Jyoti Gajrani Head of the Department for his
constant support.
I express my deep sense of gratitude for continuous cooperation
encouragement towards my guide Dr. Deepak Gupta.

Chitransh Bhatnagar
22EEACY016
ABSTRACT

Social engineering attacks pose an escalating threat to organizations. This


thesis conducted a semi-comprehensive literature review using the
PRISMA method to address common attack methods, reducing
susceptibility among employees, and the need for awareness training.
Findings highlight severe consequences, exemplified by Yahoo and Sony
data breaches. Phishing and spear-phishing are prevalent attack methods,
exploiting the human element and bypassing high-tech security systems. To
mitigate risks, organizations should adopt a multi-layered approach,
combining technological solutions with employee awareness training. By
enhancing employees' ability to identify and respond to social engineering
attempts, susceptibility to attacks can be significantly reduced. Ongoing
research and updated defense strategies are crucial to countering evolving
attack vectors. The study emphasizes the collective responsibility in
cybersecurity, combining technical and non-technical measures effectively.
This thesis contributes to knowledge by providing insights into attack
methods, countermeasures, and the importance of employee awareness
training. The rigorous PRISMA method ensures a transparent approach,
offering valuable guidance for organizations aiming to enhance their
security posture against social engineering attacks.

Keywords: Social engineering, attack, employee awareness, framework, policy


CERTIFICATE

This is to certify that the Seminar Report entitled "Social Engineering Attacks"
has been submitted by "Chitransh Bhatnagar" in partial in fulfillment for the
requirement of the degree of [Link] in Computer Science & Engineering
(Cyber Security) for the academic Session 2025-2026.
He has undergone the requisite work as prescribed by Bikaner Technical
University, Bikaner (Rajasthan).

Mr. Anil Kumar Tailor Dr. Deepak Gupta Dr. S N Tazi


Dept of CSE Dept of CSE Dept of CSE
(Seminar Coordinator) (Seminar Supervisor) (HOD)

Place:
Date : 11/03/26
Table of Contents
1. Introduction .............................................................................................................. 1

1.1. The Impact of a Social Engineering Attack against an Organization ....................... 2

1.2. Manipulating the Human ....................................................................................... 2

1.3. Social Engineering as a Part of Hacking ................................................................. 2

1.4. The Cycle of a Social Engineering Attack .............................................................. 3

1.4.1. The Environment............................................................................................. 3

1.4.2. The Attacker ................................................................................................... 3

1.4.3. The Trick ........................................................................................................ 3

1.4.4. The Victim...................................................................................................... 4

1.5. Types of Attacks: Computer-based and Human-based ............................................ 4

1.5.1 Computer-Based............................................................................................... 4

1.5.2 Human-Based .................................................................................................. 5

1.6. Knowledge Gap ..................................................................................................... 8

2. Purpose .................................................................................................................... 9

2.1. Research Questions ............................................................................................... 9

3. Method ................................................................................................................... 10

3.1. Literature Review ................................................................................................ 10

3.1.1. Identification ................................................................................................. 11

3.1.2. Screening ...................................................................................................... 11

3.1.3. Eligibility ...................................................................................................... 11

3.1.4. Inclusion ....................................................................................................... 11

3.2. Ethical Considerations ......................................................................................... 12

4. Results.................................................................................................................... 13

5. Discussion .............................................................................................................. 16

5.1. Contributions to the Field..................................................................................... 17

5.2. Effects of Increased Employee Awareness ........................................................... 17


5.3. Limitations .......................................................................................................... 18
5.4. Validity and Reliability ........................................................................................ 18

5.5. Recommendations for Future Research ................................................................ 19

6. Conclusion ............................................................................................................. 20

References...................................................................................................................... 21
List of Tables
Table 1. Key Concept. …………………………………………………………..…
Table 2. Human-based attack techniques ............................................................. 6
Table 3. Search strategy for literature review ..................................................... 10
Table 4. Overview of results from literature study ............................................. 13
Table 5. Comparison between sources that propose a framework ........................ 15
List of Figures
Figure 1. Flowchart for article selection strategy for literature review ................. 12
Key Concepts
Table 1. Key concepts.

Term Description
Baiting is a trick where the attacker leaves
physical or digital bait in a common area, to lure
a victim into picking it up out of curiosity. The
Baiting bait contains malicious software or virus to
compromise the victim’s device (Chetioui et al.,
2022).

Where someone uses emails to impersonate a


higher authority to deceive employees into
Business Email Compromise (BEC) transferring funds to their accounts (Mansfield-
Devine, 2016).

Secretly intercept and surveil others

Eavesdropping conversations without their knowledge or


consent (NIST, n.d).

Malware is a malicious software code that can be


downloaded onto a computer system, replicate

Malware itself, and create backdoors for hackers to access


personal information (Chantler & Broadhurst,
2008).

OSINT involves collecting information from

Open-source Intelligence (OSINT) publicly available sources to find relevant data


(Sharma et al., 2021).

A type of attack that involves pretending to be


trustworthy through electronic communications
Phishing to gain access to sensitive information
(Krombholz et al., 2015).

The use of false claims to gain access to sensitive

Pretexting information by building a false sense of trust


(Chetioui et al., 2022).
Exchange of a favor for sensitive information, for

Quid Pro Quo example an impostor posing as an IT consultant


(Chetioui et al., 2022).

Ransomware is malicious software that encrypts

Ransomware data and demands payment for access (Verizon,


2022).

A type of attack where the attacker manipulates


the victim into making contact, instead of
Reverse attacks initiating the contact themselves (Algarni et al.,
2013).

When an individual looks over an unaware

Shoulder surfing person to observe their activity or obtain


sensitive information (Algarni et al., 2013).

A targeted type of phishing that involves


gathering information on specific individuals or

Spear-Phishing companies to customize the attack and increase


the chances of obtaining sensitive information
(Krombholz et al., 2015).

Gain unauthorized access to secure facilities by

Tailgating following an authorized person closely (Chetioui


et al., 2022).

With the use of a phone call, the attacker can lure


the victim into providing sensitive information or
Vishing persuade the victim to download malicious
software (Chetioui et al., 2022).
1. Introduction
Data breaches have become an increasingly pressing issue in today's digital
landscape, and human error is a significant contributor to the problem. According
to a recent report from Verizon (2022) 82 % of all breaches involve the human
element, with social engineering being the primary method of attack. The report
reveals that phishing is the leading social engineering attack type, followed by
pretexting. It also highlights the importance of having a strong security awareness
program and of identifying and acting on the 2.9 % of employees who click on
phishing emails.

Moreover, IBM Security (2023) reports that 41 % of social engineering incidents


were caused by phishing, with spear-phishing attachments as the leading attack
vector at 62 %. The Verizon (2022) report emphasizes the significance of social
engineering awareness programs, as the human element continues to be a key
driver of 82 % of breaches, with phishing being one of the four main entry points
into an organization, affecting millions of email accounts.

In 2017, a data breach dating back to 2014 exposed all three billion Yahoo user
accounts. The attackers gained access through a spear-phishing attack,
compromising employee logins and infiltrating Yahoo's network. This breach
resulted in unauthorized access to sensitive information such as names, email
addresses, phone numbers, birthdates, encrypted passwords, and
encrypted/unencrypted security questions (Williams, 2017).

The Yahoo data breach highlights the need for robust protection against social
engineering attacks, which exploits human vulnerabilities through psychological
manipulation and deception (Aldawood & Skinner, 2019). It showed the severe
consequences of insufficient vigilance, compromising the sensitive data of
millions of users. This serves as an introduction to our bachelor thesis on The
Human Element of Cybersecurity: A Literature Review of Social Engineering
Attacks and Countermeasures, emphasizing the importance of social engineering
awareness programs and strong security measures.

1
1.1. The Impact of a Social Engineering Attack against an
Organization

The article "The Sony hacker indictment: 5 lessons for IT security" by Strom
(2018) describes how the FBI identified the North Korean hackers responsible for
the 2014 Sony Pictures hack. The attackers used a combination of spear-phishing
emails, malware, and other targeted elements to penetrate Sony's network. The
malware had thousands of hard-coded host names that suggested the hackers had
conducted extensive reconnaissance before the attack. The consequences of the
attack were significant, with Sony losing millions of dollars in revenue and facing
legal and regulatory challenges, while thousands of employees' personal
information was stolen. The North Korean hackers also targeted other
organizations, including banks and US corporations, using similar tactics. The
FBI's analysis of the malware used in the Sony hack and other attacks also
revealed links to the WannaCry ransomware attacks (Strom, 2018).

1.2. Manipulating the Human

Despite the use of high-security defense systems, such as firewalls and secure file
transfers, the human element is still the cause of vulnerabilities for attacks (Ghafir
et al., 2016). Social engineering is a type of hacking attack that involves
manipulating the weakest link in an information system, which is often human
behavior, to gain unauthorized access to data or to profit financially. Social
engineering attacks can compromise the confidentiality, integrity, and availability
of data, either directly or indirectly. Examples of human behavior that social
engineering attacks exploit include authority, reciprocation, moral duty, and
overloading (Mann, 2008; Mohammed & Apeh, 2016).

1.3. Social Engineering as a Part of Hacking

According to Shlyakhtunov (2021), the three most common types of hackers are
white, gray, and black hats. White hat hackers, also known as ethical hackers,
work for the good guys and use their skills to find vulnerabilities and improve
security. They are often employed by large software corporations, the military, and
other organizations to test their security systems and find weaknesses. They may

2
earn significant sums of money from "bug bounties" for finding and reporting
vulnerabilities.

Gray hat hackers operate in a legal gray area, exposing vulnerabilities in systems
without permission from their owners. They may request a fee for not disclosing
the vulnerability and may publicly disclose it if the organization does not fix the
problem quickly enough (Shlyakhtunov, 2021).

Black hat hackers are the most malicious type of hacker. They use their skills to
gain unauthorized access to systems, steal data, and cause damage. They may do
this for financial gain, political or ideological reasons, or simply for the thrill of it.
Their activities are illegal and can cause significant harm to individuals and
organizations alike (Shlyakhtunov, 2021).

1.4. The Cycle of a Social Engineering Attack

According to Algarni et al. (2013), a social engineering attack cycle consists of


four parts: the environment, the attacker, the trick, and the victim.

1.4.1. The Environment


Social networking sites (SNSs) are frequently used to gather personal or
organizational information about potential victims, which is then used to initiate a
social engineering attack (Algarni et al., 2013). This can be done through two
methods: firstly, by gathering information about the victim to identify their
vulnerabilities, and secondly, by using SNSs to reach the victims and collect
further information (Algarni et al., 2013; Luo et al., 2009).

1.4.2. The Attacker


To succeed in a social engineering attack, the attacker must have the ability to
understand the victim, develop a possible plan, and execute it at the right time.
Obtaining information about the victim's cognitive map, personal characteristics,
and motivations is important to execute a successful attack (Algarni et al., 2013).

1.4.3. The Trick


The success of the trick depends on the appropriateness of the technique used,
which can include phishing, persuasion, bribery, or reverse attacks. The technique

3
is part of the plan, which includes the necessary steps, resources, and timeline to
execute the attack successfully. The choice of plan and technique are crucial in
determining the success of the attack, as it relies heavily on the ability to exploit
the target's trust and reveal sensitive information (Algarni et al., 2013; Ghafir et
al., 2016).

1.4.4. The Victim


The susceptibility of social networking site users to social engineering attacks is
directly influenced by several factors that affect the victim. These factors include
socio-psychological factors such as emotions and thoughts, demographic variables
that encompass personal information, and motivations and drives that determine
one's actions. The success of the attacker's plan heavily relies on these factors,
given that the victim is the primary target who directly interacts with the trick
(Algarni et al., 2013).

1.5. Types of Attacks: Computer-based and Human-based

Ghafir et al. (2016) describes that social engineering techniques can be divided
into two main categories: attacks that rely on physical locations (computer-based
attacks) and attacks that use psychological manipulation (human-based attacks).

1.5.1 Computer-Based

Computer-based attacks uses technology to trick a victim into providing the


attacker with critical information needed to execute malicious activities (Ghafir et
al., 2016). Mann (2008) supplies an example in the book “Hacking the Human”
where an attack could be a phishing email that appears to be from a legitimate
source, prompting the victim to click on a link and enter their sensitive
information. This sensitive information could then be sent back to the attacker.
Three common attacking strategies include physically gaining access to the
workplace, social engineering attacks over the telephone, or online attacks through
various channels such as email or social media (Ghafir et al., 2016).

[Link] Through the workplace


To gain unauthorized access to an organization's premises and network, attackers
often perform various social engineering methods targeting the workplace. These

4
methods include impersonation, tailgating, and masquerading. Once the attacker
gains access, they can exploit any weak security measures in place to obtain
sensitive information, passwords, or even access to the network (Ghafir et al.,
2016; Mann, 2008).

[Link] Telephone
Attackers commonly use social engineering through phones to gain access to
sensitive information from an organization by targeting its help desk or customer
care helplines. They pretend to be calling from within the organization, allowing
them to remain anonymous while obtaining valuable information (Ghafir et al.,
2016).

[Link] Online
Online attacks are carried out using a range of platforms, including social media,
instant messaging, and email. The attacker may trick the target into installing
malware, send personal information through phishing or obtain information
through web searches. Attackers may also use social engineering techniques in
social networks, such as reverse social engineering attacks that abuse features
provided by the platform to launch automated attacks. The attacker can attract
large numbers of legitimate users without actively sending any friend requests,
making these attacks a feasible threat in real life (Ghafir et al., 2016; Irani et al.,
2011).

1.5.2 Human-Based

Human-based attacks use manipulative tactics like authority, flattery, intimidation,


and name-dropping to influence targets and gain access to sensitive information or
secure systems. The attacker engages in one-on-one communication with the target
and conducts preliminary research on the targeted organization before initiating an
attack, using techniques like eavesdropping and shoulder surfing. The attacker
uses manipulation methods, such as exploiting psychological vulnerabilities, as
described below in table 2, to execute a successful attack (Ghafir et al., 2016).

5
Table 2. Human-based attack techniques.

Attack Description
This technique involves a social engineer
portraying themselves as an authority
figure to elicit compliance from the
target. The fear of punishment, if they
Authority undermine the authority figure's
legitimacy, can make the target more
vulnerable to this technique (Chantler &
Broadhurst, 2008; Ghafir et al., 2016).

Attackers exploit employees' desire to be


seen as trustworthy and committed by
instructing them to execute a certain task

Commitment and Consistency and requiring the target to share their


credentials, resulting in the employee
sharing their system credentials (Ghafir
et al., 2016).

This social engineering method involves


building a relationship with a target by
sharing information, appearing similar, or
discussing a common enemy. This

Deceptive Relationship establishes trust and increases the


likelihood of the target sharing sensitive
information. The goal is to exploit the
target and obtain valuable (Chantler &
Broadhurst, 2008).

This technique is a persuasion technique


where the target is convinced that they
will not be solely responsible for their
Diffusion of Responsibility and Moral Duty actions, making it easier for them to
comply. This can be achieved through
various means, such as emphasizing the
potential benefits and consequences of

6
their actions or invoking a sense of moral
duty (Chantler & Broadhurst, 2008).

People's tendency to follow through on


commitments, even if they suspect they
may not be legitimate, can be used in
social engineering attacks. These attacks

Integrity and Consistency exploit psychological vulnerabilities and


can cause discomfort or anxiety while
being difficult to detect due to human
error in reasoning and decision-making
duty (Chantler & Broadhurst, 2008).

An attacker sets up a rapport with the


target by sharing similar interests or

Liking and Similarity claiming to have similar roots, making it


easier to acquire sensitive information
from the target (Ghafir et al., 2016).

Attackers request information or tasks


from employees who have little or no
interest in the information or task request,
such as the receptionist or cleaning crew,
Low Involvement and use their ignorance and an
overwhelming sense of assertion of
authority to obtain vital organizational
information (Ghafir et al., 2016).

Attackers take advantage of people's


natural tendency to help by

Natural Inclination to Help impersonating someone needing


assistance and gaining access to a target
building or system (Ghafir et al., 2016).

Attackers bombard with a large amount


of information within a brief period,
Overloading
including mistaken premises interlaced
with convincing truisms and hurried

7
persuasive axioms, triggers a
psychological response that causes them
to become mentally passive and absorb
information without evaluating it, leading
to compliance. This is achieved through a
time element and can be referred to as
overloading (Chantler & Broadhurst,
2008).

An attacker creates a situation that


prompts the target to seek assistance from
the attacker, who resolves the situation,
Reciprocation and in return, the victim offers the
attacker requested information (Chantler
& Broadhurst, 2008; Ghafir et al., 2016).

It is a technique to manipulate an
individual's decision-making abilities,
often in the context of phishing attacks.
This technique involves triggering strong

Strong Affect emotions such as fear or excitement to


compromise an individual's logical
reasoning and increase the likelihood of
falling for a scam (Chantler &
Broadhurst, 2008).

1.6. Knowledge Gap

The increasing reliance on technology in organizational settings has exposed a


knowledge gap in social engineering prevention strategies within organizational
contexts. To address this gap, there is a need for research aimed at identifying
effective countermeasures specifically tailored to organizations. Therefore, this
study investigates prevalent social engineering attacks, evaluates the importance of
human factors in prevention strategies, and provides insights on the best practices
for protecting organizational assets.

8
2. Purpose
The purpose of this thesis is to investigate the current state of research on social
engineering methods, along with how they are being used and how they can be
prevented. The paper should then be able to be used as a basis for organizations
designing their social engineering prevention framework or policies.

2.1. Research Questions

The following research questions have been formulated to achieve the purpose of
this thesis, which is to investigate:

 What are the most effective ways of reducing susceptibility to social


engineering attacks among employees?
 Is there a need for employee awareness training when it comes to the
prevention of social engineering attacks?

9
3. Method
3.1. Literature Review

To answer our research questions, we conducted a literature review. Data


collection for our literature review was conducted through using two databases that
were considered relevant to our research question: ScienceDirect and IEEE
Xplore.

To develop our search strategy, we began with brainstorming search terms related
to our research question. Then test searches were conducted to get an overview of
the research situation and to verify if the search terms were relevant to our
research question. By refining our search strategy, we found relevant keywords
that aligned with our research question, including social engineering, employee
awareness, attacks, and policy. This formed the basis for deciding whether we
could obtain relevant results based on our search terms.

To obtain relevant results that align with our research questions and purpose, we
minimized irrelevant hits by using the keywords we had identified. By combining
these keywords using the "and" operator, we were able to conduct a more targeted
search. This was to obtain a more focused and informative set of results that were
most suitable for our research question. Since different databases have different
search methods, the search string was different between databases. The search
strategy is presented in Table 3.

Table 3. Search strategy for literature review.

Database Search string Date

("All Metadata":social engineering) AND ("All

IEEE Xplore Metadata":employee awareness) AND ("All 2023-04-24


Metadata":attacks) AND ("All Metadata":policy)

"social engineering" AND "employee awareness" AND


2023-04-24
ScienceDirect "attacks" AND "policy"

10
To achieve a more reliable and semi-comprehensive analysis, the Preferred
Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) method
was used. PRISMA is a four-part process consisting of identification, screening,
eligibility, and inclusion. The PRISMA-flowchart is described in figure 1.

3.1.1. Identification

We summarized the number of search results from the two databases we used,
which each have their own unique collection of publications. Since we did not find
any duplicates across the databases, we did not need to remove any at this stage.

3.1.2. Screening

This means reading titles and abstracts. To ensure relevance to our literature
review, we conducted a thorough screening of article titles and abstracts based on
our chosen keywords. Specifically, we checked each article to decide if it had
relevant material related to keywords.

3.1.3. Eligibility

Here, the search results were filtered to show only results that had open access and
full texts that we have access to via Dalarna University's various subscriptions to
different databases. We included articles that supplied information on preventing
employees from being deceived by various types of social engineering attacks and
creating policies to prevent them. We excluded articles where the context was not
organizational or employee oriented.

3.1.4. Inclusion

After applying these inclusion and exclusion criteria, we were left with a total of 9
articles that contained valuable information related to our research topic. These
articles were considered eligible and were included in our systematic review.

11
Figure 1. Flowchart for article selection strategy for literature review.

3.2. Ethical Considerations

Since a literature study does not involve any physical or psychological impact on
the research participants, it is considered ethically unproblematic.

12
4. Results
This study resulted in 13 included articles and two tables. Table 4 is an overview
of the included studies and their results according to seven categories. Each
category is clearly defined at the bottom of the table.

Table 4. Overview of results from literature study.


Source PF ETP RA CC RWP OS BS

Aldawood and Skinner (2019) Yes

Alghenaim et al. (2021) Yes Yes

Alshaikh (2020) Yes Yes

Annarelli et al. (2020) Yes Yes

Hayes and Cappa (2018) Yes Yes

Lee (2021) Yes

Mansfield-Devine (2016) Yes Yes

Nwankpa and Datta (2023) Yes Yes

Rocha Flores and Ekstedt (2016) Yes Yes

PF, Proposed framework or model for social engineering prevention; ETP, Proposed employee
training programs or initiatives related to social engineering; RA, Methods/tools used for assessing
the risk of social engineering attacks; CC, Building a cybersecurity culture to prevent social
engineering attacks; RWP, Adapting policies and procedures related to remote work and their
impact on social engineering; OS, Using OSINT for conducting risk assessments related to social
engineering; BS, BEC scams and their impact on organizations.

Lee (2021), Alghenaim et al. (2021), and Annarelli et al. (2020) all proposed
formal frameworks for preventing social engineering attacks. While they all had
unique approaches, there were several similarities between them. Lee (2021)
emphasized the importance of educating employees about social engineering
techniques, utilizing secure access control mechanisms, and implementing two-
factor authentication where possible. Similarly, Alghenaim et al. (2021) found that
employee awareness and training were crucial in detecting and reporting social

13
engineering attacks, and recommended implementing security awareness programs
as part of an organization’s security strategy.

Annarelli et al. (2020) had more of a holistic approach, focusing on four key
components: organizational culture, employee training, incident management, and
awareness-raising activities. Additionally, Aldawood and Skinner (2019),
Alshaikh (2020), Alghenaim et al. (2021), and Mansfield-Devine (2016) all
highlighted the need for conducting employee awareness training.

Aldawood and Skinner (2020) suggest that education and training programs should
aim to raise awareness among employees about the different types of social
engineering attacks, along with the tactics used by attackers, as well as the
consequences that follow when an attacker is successful in their attack. Other
studies, such as the one by Ling Li, Li Xu, and Wu He (2020), suggest that
simulated phishing exercises can be an effective way to train employees to
recognize and respond to phishing attacks. These involve sending fake phishing
emails to employees and analyzing their responses to identify areas where they
may need additional training. Aldawood and Skinner (2020) suggest a similar
approach, effectively simulating social engineering attack scenarios and having
employees practice responding to the attacks in a safe and controlled environment.

In the study by Alshaikh (2020), the concept of gamification was identified as a


tool for increasing employee awareness. They proposed interactive and engaging
training material, to increase attention among the employees being educated. The
importance of developing a cybersecurity culture within the organization and using
leadership to foster a security culture was also heavily emphasized. In Alghenaim
et al. (2021), an employee awareness model that includes stages such as
awareness, education, training, and evaluation was implemented and tested in the
Saudi public sector, with results showing a significant increase in employee
knowledge and awareness of social engineering attacks.

Table 5 provides an overview and comparison of the results from the sources that
proposed frameworks. All the sources agree on the importance of employee
awareness and training in preventing social engineering attacks.

14
Table 5. Comparison between sources that propose a formal framework or model.

Source Result

Found that employees with high levels of awareness and training were

Alghenaim et more likely to detect and report social engineering attacks. Highlights

al. (2021) the importance of employee awareness programs to help prevent those
attacks.

Importance of employee awareness training, implementing strict


Alshaikh security policies, and using incident response plans was highlighted.
(2020)

Suggests a holistic approach to social engineering defense, which


Annarelli et al. includes incorporating organizational culture, employee training,
(2020) incident management, and awareness-raising initiatives.

Employees need to be informed about social engineering techniques

Lee (2021) and ways to prevent them. Use access control mechanisms and two-
factor authentication.

Recommends using employee awareness programs and policies to


Mansfield- prevent social engineering. It was found that naivety and lack of
Devine (2016) awareness by employees were the main reasons for successful attacks.

Highlights the importance of employee awareness programs along


Nwankpa and with strict security policies and procedures to help prevent social
Datta (2023) engineering.

15
5. Discussion
The aim of this bachelor thesis was to provide a foundation for organizations that
design frameworks or policies to prevent social engineering, by examining the
current state of research on social engineering practices and their prevention. To
identify relevant articles, a search string based on the keywords was created, and a
literature review was conducted using the databases ScienceDirect and IEEE
Xplore, resulting in 13 articles.

The study sought to identify common social engineering attack methods, effective
ways to reduce employee susceptibility, and the need for awareness training. Table
4 gives an overview of the 13 articles, while table 5 compares the results from the
articles that formally present a framework and highlights the importance of
employee awareness in preventing social engineering attacks.

The report from Verizon (2022) that was mentioned in the introduction highlights
that 82 % of all breaches involve the human element, with social engineering
being the primary method. The report identifies phishing as the most used social
engineering attack, followed by pretexting. It suggests several effective ways to
reduce employee susceptibility, including employee awareness and training,
building a cybersecurity culture, using risk assessment methods or tools, adapting
policies for remote work, and using OSINT for risk assessments. Simulated
phishing exercises, gamification, and incident management were also identified as
effective training tools. The study highlights the need for employee awareness
training in the prevention of social engineering attacks. Various training methods
were proposed including simulated phishing exercises and interactive and
engaging training materials. Lastly, all sources that suggested a framework to
prevent social engineering attacks agreed on the significance of employee
awareness and education.

Overall, this study provides valuable insights into social engineering methods and
their prevention, which can be used by organizations to design effective prevention
frameworks and policies.

16
5.1. Contributions to the Field

Our study contributes to the field of cybersecurity by providing a semi-


comprehensive review of the literature on preventing social engineering attacks in
an organizational context. By identifying the most effective methods for
preventing social engineering attacks, we provide useful insights for organizations
and researchers working in the field of cybersecurity.

5.2. Effects of Increased Employee Awareness

According to the findings in the IBM Security (2023) X-Force Threat Intelligence
Index report of 2023, there was a significant decrease in spear-phishing links as
the infection vector targeting European organizations. In the report from the
previous year, with data from 2021, spear-phishing links accounted for a
substantial 42 % of the infection vectors, whereas in the year after, that number
dropped to 14 %. It is believed that this is a result from several different factors,
including improved user awareness, stronger email security defenses, and other
effective defense mechanisms capable of catching malware post-installation.

The report suggests that organizations are becoming increasingly aware and
knowledgeable about the risks associated with social engineering attacks and
indicates that they are doing more than before to educate their employees on
attacks and ways to prevent them from occurring. Subsequently, this may lead to
employees being more cautious when interacting with emails and attachments of
suspicious characters, reducing their susceptibility to becoming a victim in the first
place.

Additionally, the report indicates that organizations may have increased their email
security defenses that can detect and block phishing attempts more effectively.
Furthermore, it seems that improvements have been made when it comes to post-
malware detection and response. All these security advancements seem to indicate
that a holistic solution with multiple layers should be used to prevent social
engineering attacks most effectively in the organizational context.

17
5.3. Limitations

The literature review conducted in this bachelor thesis has several limitations.
Initially, the study relied on data that was collected from two databases, which
might not cover all available research regarding the subject. The limited sample
size may affect the extensiveness of the result.

The search strategy that was formed for this literature review was based on
brainstorming relevant search terms and through conducting test-searches. Despite
our efforts to enhance the search strategy there is a possibility that some relevant
articles could have been missed or excluded due to our chosen search term or
criteria.

Worth noting is that during our review a similar article published 2022 was
discovered. Although their topic had resemblance to our subject it was not
included in this review, because they used keywords that did not match our search
criteria.

Articles that did not have open access or were not available through Dalarna
University were filtered out from the review, to ensure that only relevant articles
with full text appeared in the results. It is possible that relevant articles were
excluded, as they did not match the search criteria.

Lastly, there is a possibility that new relevant literature has been published that we
have not been able to include in the review.

5.4. Validity and Reliability

To ensure the reliability and validity of our research in this bachelor thesis, we
emphasized a strict and systematic review method for evaluation, specifically
PRISMA. By conducting this approach, we efficiently minimized the inclusion of
irrelevant findings, which enhanced the overall quality of our study.

18
5.5. Recommendations for Future Research

The findings of this study provide valuable insights that can be leveraged to dive
deeper into the subject in various ways. One area of focus for future research could
involve implementing certain social engineering prevention frameworks in specific
industries, such as in the banking sector or real estate sector. The studies could be
of longitudinal form, to track the retention of knowledge and changes in employee
behavior over a long period of time. This will enable a better understanding of
whether the measures proposed in the frameworks continue to deliver good results
in the long term. For this to work, the implemented frameworks would consistently
need to be updated and maintained, to be adapted to the most recent and current
social engineering threats.

19
6. Conclusion
This thesis has emphasized the escalating threat of social engineering attacks in
organizational settings. The Yahoo and Sony data breaches serve as epitomes for
the financial losses, legal challenges, stolen personal information, and many other
serious consequences that can result from one of these attacks.

The presence of various types of hackers highlights the complex landscape in


which social engineering attacks occur, and the social engineering attack cycle
undertones the need for organizations to implement sufficient and comprehensive
security measures. This thesis stresses the importance of a multi-layered approach
to counter these attacks, using both technological solutions such as firewalls and
non-technological solutions such as proper employee awareness training.

Continued research in the area is essential as attacks continue to evolve, becoming


more and more advanced as time goes on. Staying up to date with the most recent
attack vectors and updating defense strategies is key to protecting an
organization’s assets.

In conclusion, this thesis highlights the collective responsibility in cybersecurity.


By combining the technical with the non-technical, and continuously improving,
we can effectively combat the threat of social engineering attacks.

20
References
Aldawood, H., & Skinner, G. (2019). Reviewing Cyber Security Social
Engineering Training and Awareness Programs-Pitfalls and Ongoing Issues.
Future Internet, 11(3), Article 73. [Link]

Algarni, A., Xu, Y., Taizan, C., & Yu-Chu, T. (2013). Social engineering in social
networking sites: Affect-based model. In 8th International Conference for Internet
Technology and Secured Transactions (ICITST-2013), December 9-12, 2013 (pp.
508-515). IEEE. [Link]

Alghenaim, M. F., Bakar, N. A. A., Yusoff, R. C. M., Hassan, N. H., &


Sallehudin, H. (2021). Employee Awareness Model to Enhance Awareness of
Social Engineering Threats in the Saudi Public Sector. In 2021 International
Congress of Advanced Technology and Engineering (ICOTEN) (pp. 1-6). 4-5 July
2021. [Link]

Alshaikh, M. (2020). Developing cybersecurity culture to influence employee


behavior: A practice perspective. Computers & Security, 98, 102003.
[Link]

Annarelli, A., Nonino, F., & Palombi, G. (2020). Understanding the management
of cyber resilient systems. Computers & Industrial Engineering, 149, 106829.
[Link]

Chantler, N., & Broadhurst, R. (2008). Social engineering and crime prevention in
cyberspace. Proceedings of the Korean Institute of Criminology, 65-92.
[Link]

Chetioui, K., Bah, B., Alami, A. O., & Bahnasse, A. (2022). Overview of Social
Engineering Attacks on Social Networks. Procedia Computer Science, 198, 656-
661. [Link]

21
Ghafir, I., Prenosil, V., Alhejailan, A., & Hammoudeh, M. (2016). Social
engineering attack strategies and defense approaches. In 4th IEEE International
Conference on Future Internet of Things and Cloud (FiCloud), August 22-24,
2016, Vienna, Austria (pp. 147-151). IEEE.
[Link]

Hayes, D. R., & Cappa, F. (2018). Open-source intelligence for risk assessment.
Business Horizons, 61(5), 689-697. [Link]

Irani, D., Balduzzi, M., Balzarotti, D., Kirda, E., & Pu, C. (2011). Reverse social
engineering attacks in online social networks. In Detection of Intrusions and
Malware, and Vulnerability Assessment (pp. 55-74). Springer, Berlin, Heidelberg.
[Link]

Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social
engineering attacks. Journal of Information Security and Applications, 22, 113-
122. [Link]

Lee, I. (2021). Cybersecurity: Risk management framework and investment cost


analysis. Business Horizons, 64(5), 659-671.
[Link]

Luo, W., Liu, J., Liu, J., & Fan, C. (2009). An analysis of security in social
networks. In 2009 Eighth IEEE International Conference on Dependable,
Autonomic and Secure Computing (pp. 648-651). IEEE.
[Link]

Mann, M. I. (2008). Hacking the human: social engineering techniques and


security countermeasures. Gower Publishing, Ltd.

Mansfield-Devine, S. (2016). The imitation game: how business email compromise


scams are robbing organisations. Computer Fraud & Security, 2016(11), 5-10.
[Link]

22
Mohammed, S., & Apeh, E. (2016). A model for social engineering awareness
program for schools. In 2016 10th International Conference on Software,
Knowledge, Information Management & Applications (SKIMA) (pp. 392-397).
IEEE. [Link]

NIST. (n.d). Eavesdropper. Retrieved May 13, 2023, from


[Link]

Nwankpa, J. K., & Datta, P. M. (2023). Remote Vigilance: The Roles of Cyber
Awareness and Cybersecurity Policies Among Remote Workers. Computers &
Security, 103266. [Link]

Rocha Flores, W., & Ekstedt, M. (2016). Shaping intention to resist social
engineering through transformational leadership, information security culture and
awareness. Computers & Security, 59, 26-44.
[Link]

IBM Security. (2023). X-Force Threat Intelligence Index 2023. Annual Report.
Retrieved from [Link]

Sharma, A., Breeden II, J., & Fruhlinger, J. (2021, June 28). 15 top open-source
intelligence tools. CSO. Retrieved May 13, 2023, from
[Link]
[Link]

Shlyakhtunov, M. A. (2021). White-Grey-Black Hat Hackers Role in World and


Russian Domestic and Foreign Cyber Strategies. International Journal of
Advanced Computer Science and Applications, 12(8).
[Link]

Strom, D. (2018, September 25). The Sony hacker indictment: 5 lessons for IT
security. CSO. Retrieved April 11, 2023, from
[Link]
[Link]

23
Verizon. (2022). 2022 Data Breach Investigations Report (DBIR) (T124). Verizon.
[Link]
[Link]

Williams, M. (2017, October 4). Inside the Russian hack of Yahoo: How they did
it. CSO. Retrieved April 21, 2017, from
[Link]
[Link]

24

You might also like