Social Engineering Attacks and Mitigation Strategies
Nihad Ahmad Hassan, Rami Hijazi · Cybersecurity · 2025
This chapter focuses on social engineering (SE) attacks and corresponding defense mechanisms. It defines SE as a non-technical threat exploiting psychological manipulation to extract sensitive information from victims. The chapter breaks down the attack process into four phases: Information gathering, trust establishment, manipulation, and exit. It categorizes various attack vectors and examines techniques including phishing, spear phishing, whaling, business email compromise, vishing, and smishing, while offering preventative measures against these threats.