Przeskocz do nawigacji głównej Przeskocz do wyszukiwania Przeskocz do głównej treści

Development of the social engineering attack models

  • Oleksandr Bokhonko
  • , Sergii Lysenko
  • , Piotr Gaj
  • Khmelnytsky National University

Wyniki badań: Wkład do czasopismaArtykuł z konferencjirecenzja

Abstrakt

This study developed specialized models for detecting social engineering attacks, with a focus on spam emails, spear phishing, and trojan emails. Each model captures distinct features of these attacks using machine learning-based detection processes. Utilizing the BotGRABBER framework, which incorporates algorithms such as random forest, decision tree, K-nearest neighbor, and XGBoost, the models analyze characteristics like email metadata, user interaction patterns, attachment behaviors, and network anomalies to differentiate between malicious and legitimate communications. The targeted approach of each model enables tailored detection strategies that address specific social engineering tactics, whether they involve spam, personalized deceptive emails, or malware-infected attachments. For example, the trojan email model concentrates on identifying embedded malware within email attachments, utilizing sandbox environments for controlled testing and analysis. In contrast, the spear phishing model focuses on detecting personalized attack methods by analyzing sender details and links for suspicious patterns. The spam email model, on the other hand, prioritizes content filtering and tracking calls-to-action to distinguish between legitimate emails and mass-distributed spam. Empirical results demonstrate the models’ effectiveness, achieving approximately 99% detection accuracy with a 6% false positive rate. This strong performance highlights the potential of these models to contribute to proactive defense strategies against evolving social engineering threats. By leveraging targeted feature sets and adaptive machine learning algorithms, these models can be effectively deployed in real-world environments to safeguard networks and systems from a wide array of social engineering attacks.

Język oryginałuangielski
Strony (od–do)288-303
Liczba stron16
CzasopismoCEUR Workshop Proceedings
Tom3899
Status publikacjiOpublikowano - 2025
Wydarzenie1st International Workshop on Advanced Applied Information Technologies, AdvAIT 2024 - Khmelnytskyi, Ukraina
Czas trwania: 5 gru 2024 → …

Obszary tematyczne ASJC Scopus

  • Informatyka ogólna

Fingerprint

Zanurz się w tematy badawcze publikacji „Development of the social engineering attack models”. Razem tworzą niepowtarzalny odcisk palca.

Cytowanie