Skip to main navigation Skip to search Skip to main content

Development of the social engineering attack models

  • Oleksandr Bokhonko
  • , Sergii Lysenko
  • , Piotr Gaj
  • Khmelnytsky National University

Research output: Contribution to journalConference articlepeer-review

Abstract

This study developed specialized models for detecting social engineering attacks, with a focus on spam emails, spear phishing, and trojan emails. Each model captures distinct features of these attacks using machine learning-based detection processes. Utilizing the BotGRABBER framework, which incorporates algorithms such as random forest, decision tree, K-nearest neighbor, and XGBoost, the models analyze characteristics like email metadata, user interaction patterns, attachment behaviors, and network anomalies to differentiate between malicious and legitimate communications. The targeted approach of each model enables tailored detection strategies that address specific social engineering tactics, whether they involve spam, personalized deceptive emails, or malware-infected attachments. For example, the trojan email model concentrates on identifying embedded malware within email attachments, utilizing sandbox environments for controlled testing and analysis. In contrast, the spear phishing model focuses on detecting personalized attack methods by analyzing sender details and links for suspicious patterns. The spam email model, on the other hand, prioritizes content filtering and tracking calls-to-action to distinguish between legitimate emails and mass-distributed spam. Empirical results demonstrate the models’ effectiveness, achieving approximately 99% detection accuracy with a 6% false positive rate. This strong performance highlights the potential of these models to contribute to proactive defense strategies against evolving social engineering threats. By leveraging targeted feature sets and adaptive machine learning algorithms, these models can be effectively deployed in real-world environments to safeguard networks and systems from a wide array of social engineering attacks.

Original languageEnglish
Pages (from-to)288-303
Number of pages16
JournalCEUR Workshop Proceedings
Volume3899
Publication statusPublished - 2025
Event1st International Workshop on Advanced Applied Information Technologies, AdvAIT 2024 - Khmelnytskyi, Ukraine
Duration: 5 Dec 2024 → …

Keywords

  • cyberattacks
  • cybersecurity
  • detection
  • models
  • network host
  • social engineering attack

ASJC Scopus subject areas

  • General Computer Science

Fingerprint

Dive into the research topics of 'Development of the social engineering attack models'. Together they form a unique fingerprint.

Cite this