User Behavior Analysis in Determining the Vulnerable Category of Vishing and Smishing
Prasadi Kumarasinghe, Dushan Dissanayake, Prarthana Gamage, Gamage Upeksha Ganegoda · 2023
Despite the fact that phishing is frequently addressed, voice phishing and SMS phishing which is also known as vishing and smishing are least addressed social engineering attacks. Through vishing and smishing, the attackers try to divulge sensitive information over the phone. As some of the common types of vishing and smishing attacks, bank related attacks, insurance related attacks, charity related attacks, social media related attacks can be pointed out. Most of the time these attacks are conducted targeting specific domains that the user is highly vulnerable to. Such as mobile device users have the higher tendency to be susceptible to a scam attack in the domain where they are frequently engaged in. Hence by observing the behavior of the user to a scam attempt, analyzing the user behavior, the vulnerability of the user to a specific scam attack category can be determined. User's behavior in a scam attempt is further influenced by their own characteristics such as socio demographic attributes, behavior related attributes and perceptual related attributes. So the impact of those user characteristics which their behavior in a scam attempt is influenced by plays a significant importance in determining their susceptibility to a scam attempt. Security Education Training and Awareness(SETA) is a program which is commonly available within organizations as preventive mechanisms. The same concept is applied in this proposed solution by creating a knowledge base of SETA recommendations for each category of attack that the user is highly vulnerable to. So this application determines the category of attack that the user is highly susceptible to and increases awareness and proficiency of the user to ensure prevention.