Mitigating Social Engineering Attacks Through Cost-Effective Security Awareness Training Policy

Yang Qin, Xiaofan Yang, Lu‐Xing Yang, Kaifan Huang · IEEE Transactions on Network Science and Engineering · 2025

Human beings are often considered the weakest link in cybersecurity. Social engineering attacks exploit this vulnerability, posing significant threats to the digital assets of organizations. A highly effective strategy to protect users from falling into traps set by attackers is to implement comprehensive security awareness training focused on social engineering. In this context, the organization needs to find a cost-effective policy of allocating the security awareness training cost. We refer to the problem of finding such a policy as the security awareness training (SAT) problem. This paper addresses the SAT problem. First, an opinion dynamics-based security awareness evolution model is introduced. On this basis, the SAT problem is reduced to an optimal control model (the SAT model). Second, by deriving the optimality system for the SAT problem, an algorithm of solving the SAT model is proposed. Next, the feasibility of the proposed algorithm is validated through numerical experiments. Additionally, further exploration of the SAT algorithm are conducted. Finally, for greater versatility, the problem is formulated as a discrete-time problem (the discrete SAT problem), and the discrete SAT algorithm is proposed to solve it. This work takes the first step toward the prevention of social engineering attack through optimal control approach.

Read the paper · More papers on PaperTik