Human Cognition through the Lens of Social Engineering Cyberattacks

Rosana Montanez Rodriguez,Edward Golob,Shouhuai Xu
DOI: https://doi.org/10.48550/arXiv.2007.04932
2020-07-10
Abstract:Social engineering cyberattacks are a major threat because they often prelude sophisticated and devastating cyberattacks. Social engineering cyberattacks are a kind of psychological attack that exploits weaknesses in human cognitive functions. Adequate defense against social engineering cyberattacks requires a deeper understanding of what aspects of human cognition are exploited by these cyberattacks, why humans are susceptible to these cyberattacks, and how we can minimize or at least mitigate their damage. These questions have received some amount of attention but the state-of-the-art understanding is superficial and scattered in the literature. In this paper, we review human cognition through the lens of social engineering cyberattacks. Then, we propose an extended framework of human cognitive functions to accommodate social engineering cyberattacks. We cast existing studies on various aspects of social engineering cyberattacks into the extended framework, while drawing a number of insights that represent the current understanding and shed light on future research directions. The extended framework might inspire future research endeavors towards a new sub-field that can be called Cybersecurity Cognitive Psychology, which tailors or adapts principles of Cognitive Psychology to the cybersecurity domain while embracing new notions and concepts that are unique to the cybersecurity domain.
Cryptography and Security
What problem does this paper attempt to address?
This paper attempts to systematically understand human cognition from the perspective of social - engineering cyber - attacks. Specifically, it aims to explore the following aspects: 1. **Which aspects of human cognition are exploited by social - engineering cyber - attacks?** The paper proposes an extended human - cognition framework to adapt to the characteristics of social - engineering cyber - attacks, so as to gain a deeper understanding of how these attacks exploit human cognitive weaknesses. 2. **Why are humans vulnerable to social - engineering cyber - attacks?** The author analyzes human vulnerability in situations such as high workload, high stress, low attention alertness, and lack of domain knowledge or experience. These factors make individuals more likely to be targets of attacks. 3. **How can the damage of these attacks be minimized or at least mitigated?** The paper proposes a method of designing defensive measures through psychologically valid assumptions and emphasizes the importance of unconscious processing ability and how to establish a warning system that operates in parallel with the user's conscious attention. 4. **Future research directions**: The paper also points out some directions for future research, especially in quantifying the influence of model parameters (such as the short - term cognitive factors, long - term cognitive factors, long - term memory of victims and attacker efforts) on the degree of persuasion of human targets. Through the exploration of these issues, the paper hopes to provide a new perspective for future research, namely "cyber - security cognitive psychology", a field that applies the principles of cognitive psychology to the field of cyber - security while introducing new concepts and ideas specific to cyber - security.