Training Future Cybersecurity Professionals in Spear Phishing using SiEVE

Jared James Meyers, Derek L. Hansen, Justin Scott Giboney, Dale C. Rowe · 2018

Most enterprise network attacks are the result of spear phishing, a highly personalized form of social engineering attack that is increasingly common. It is imperative that future cybersecurity professionals understand how to protect against such attacks, as well as how to effectively and efficiently perform such attacks during penetration testing. To help such education efforts, this paper introduces a process for creating spear phishing attacks called the Social Engineering Vulnerability Evaluation, or SiEVE for short. The step-by-step process relies solely on open source data and includes the steps of (1) identifying targets, (2) profiling targets, and (3) crafting spear phishing messages. SiEVE was evaluated as part of an experiment that compared performance of two groups of students in a 3rd year University Cybersecurity class: those with SiEVE (n=27) and those without SiEVE. (n=24). Findings show that those using the SiEVE process (a) did not identify more targets, though SiEVE students had significantly lower variance, (b) did identify more information about targets, and (c) did lead to more effective spear phishing attacks. The study illustrates the value of providing simple guidelines on improving performance of social engineering activities.

Read the paper · More papers on PaperTik