Blunting the Phisher’s Spear: A risk-based approach for defining user training and awarding administrative privileges

نویسنده

  • Arun Vishwanath
چکیده

People today are the weakest links in cybersecurity. Solving the “people problem” of cyber security requires us to understand why people fall victim to spear phishing. Unfortunately, the only proactive solution against spear phishing is to train and educate people. But, judging from the number of continued breaches, training appears to be limited in its effectiveness. Today’s leading cybersecurity training programs focus on hooking people in repeated simulated spear phishing attacks and then showing them the nuances in the emails they missed. This “gotcha game” presumes that users merely lack knowledge, and if they are told often enough and repeatedly shown what they lack, they would become better at spear phishing detection. We propose a radical change to this “one-size-fits all” approach. Recent human factors research—the Suspicion, Cognition, Automaticity Model (SCAM)—identifies two independent sets of factors that lead to individual phishing victimization: users’ cognitive processing schemas premised on their perceptions about the safety of online behaviors, and their habits and patterns borne out of repeated, ritualistic behaviors influenced by work culture and the types of devices people use to connect and communicate. Using the SCAM, we propose the development of an employee Cyber Risk Index (CRI). Similar to how financial credit scores work, the CRI will provide security analysts the ability to pinpoint the weak-links in organizations and identify who is likely to fall victim, who needs training, how much training, and also what the training should focus on. The CRI will also allow security analysts to identify which users get administrative access, replacing the current mostly binary, role-based apportioning method, where individuals are given access based on their organizational role and responsibilities, with a system that is based on individuals’ quantified cyber risk propensity. The CRI based approach we present will lead to individualized, cognitive-behavioral training and an evidence-based approach to awarding users’ admin privileges. These are paradigm-changing solutions that will altogether improve individual cyber resilience and blunt the effectiveness of spear phishing.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Comparison of Indicators for Determining the Thresholds of Banks' Financial Crisis in EWS Based on Business Cycles

 The purpose of this paper is to design a prediction system for thresholds of the bankruptcy of banks based on the business cycle and examine the effects of different approaches in defining the bankruptcy threshold in predicting bankruptcy time of Iranian banks using the Kaplan-Meier and Cox Proportional-Hazards Models. So, the data of listed banks in Tehran Stock Exchange were used from 1385-1...

متن کامل

Human Error Assessment in City Gate Stations of Isfahan Natural Gas Company Using the System for Predictive Error Analysis and Reduction Framework

Introduction: Human factor analysis has been identified as the most common cause of accidents in natural gas transportation and distribution facilities. The occurrence of accidents at these systems, especially gas reduction stations located in residential and industrial areas, has had catastrophic consequences. Therefore, this study aimed at analyzing critical tasks and human error assessment u...

متن کامل

Determining Components of Medical Instructional Design based on Virtual Reality by Research Synthesis

Introduction: The purpose of the present study was to determine the components of medical education design based on virtual reality by research synthesis method. Methods: In the present study a synthesis method was used. In order to study the research background and to collect appropriate data among the databases of Science Direct, Springer, Scopus, ProQuest and Eric (ERIC) search. With the ke...

متن کامل

CEO Risk-Taking Incentives based on Environmental Sustainability

In this study, I try to examine the effect of environmental sustainability on CEO risk taking. Prior research, however, has struggled to establish this relation empirically; moreover, some evidence points to the possibility that the CEO risk appetite is lower for firms with sustainable environment. The opportunistic approach of managers leads to decisions about personal interests and imposing c...

متن کامل

Developing a Risk Management Model for Banking Software Development Projects Based on Fuzzy Inference System

Risk management is one of the most influential parts of project management that has a major impact on the success or failure of projects. Due to the increasing use of information technology (IT) systems in all fields and the high failure rate of IT projects in software development and production, it is essential to effectively manage these projects is essential. Therefore, this study is aimed t...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016