<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Creativity Techniques for Social Engineering Threat Elicitation: A Controlled Experiment</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Kristian Beckers</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Veronika Fries</string-name>
          <email>veronika.fries@in.tum.de</email>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Eduard C. Groen</string-name>
          <email>eduard.groen@iese.fraunhofer.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sebastian Pape</string-name>
          <email>sebastian.pape@m-chair.de</email>
          <email>sebastian.pape@social-engineering.academy</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Fraunhofer IESE</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Goethe University Frankfurt</institution>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Social Engineering Academy</institution>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Technical University of Munich</institution>
        </aff>
      </contrib-group>
      <abstract>
        <p>We propose a controlled experiment to assess how well creativity techniques can support social engineering threat assessment. Social engineering threats form the basis for the elicitation of security requirements, a type of quality requirement, which state what threat should be prevented or mitigated. The proposed experiment compares a serious game and the Morphological Forced Connections technique with regard to their productivity, as well as completeness and precision.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Social engineering is the illicit acquisition of information about computer
systems by primarily non-technical means. Although the technical security of most
critical systems is usually being regarded, such systems remain highly vulnerable
to attacks from social engineers that exploit humans to obtain information (e.g.,
phishing) [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ]. To develop systems that are more resilient to threats from social
engineering, the security requirements should speci cally address such threats.
      </p>
      <p>
        Moreover, performing a threat assessment of social engineering is hard,
because an attacker (a) does not need any (advanced) technical skills, and (b) can
conduct an attack without advanced equipment. Hence, anyone can in ict
significant damage through social engineering5. We have developed a serious game for
social engineering [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ] (see Fig. 1), which is suitable for educating non-security
experts about the threats of social engineering, as well as for eliciting security
requirements to prevent and mitigate social engineering threats. The empirical
elicitation and assessment of security requirements concerning social engineering
is di cult, as it is not the system's security measures themselves that are causing
the security threat, but unpredictability of humans with system knowledge. For
example, humans can give away passwords. In the business context, these
techniques additionally rely on the participation of common employees, who posses
the required practical and domain knowledge.
      </p>
    </sec>
    <sec id="sec-2">
      <title>Copyright 2017 for this paper by its authors. Copying permitted for private and academic purposes.</title>
      <p>Kristian Beckers, Veronika Fries, Eduard C. Groen, and Sebastian Pape</p>
    </sec>
    <sec id="sec-3">
      <title>This makes foreseeing possible social</title>
      <p>engineering threats the main challenge.</p>
      <p>The elicitation of requirements to this
end draws on the stakeholders'
ability to make new associations, and
therefore requires creativity techniques
for the combination of existing (work)
practices and potential threats.</p>
      <p>
        In order to validate the suitability and e ectiveness of our game (cf. [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ])
for eliciting security requirements concerning social engineering, we propose to
conduct an experiment of 90 minutes in which we compare its yield for social
engineering threat elicitation with that of the Morphological Forced Connections
technique [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. This established creativity technique was chosen because of its
suitability to transform a combination of preexisting (work) aspects into new
conceptual combinations (i.e., a threat) through inference.
      </p>
      <p>The context of our experiment is the CreaRE workshop. Social engineering
threats for a prede ned scenario are elicited from the participants in either of
two conditions. Our hypothesis concerns the productivity and precision of both
approaches. We hypothesise that the serious game is more productive and precise
than the creativity technique. We de ne true positives (TP) as correctly
identi ed threats (i.e., correct result that experts have previously found or or that
they verify during the experiment). False positives (FP) are threats reported by
participants but not veri ed by expert review. We measure productivity in the
number of TP discovered during a limited time frame and precision as the
percentage of TP of the overall discovered threats. The independent variable is the
technique used for the social engineering threat assessment, with two levels:
"social engineering game" and "Morphological Forced Connections technique". The
dependent variables are the total number of threats elicited with each method,
the number of threats that are identi ed to be correct, and the time required to
identify these threats. The correctness is validated by security experts reviewing
the elicited threats and an assessment of the participants during the experiment.</p>
      <p>The results of our experiment should provide an indication of how suitable
the two creativity techniques are for performing social engineering threat
elicitation. We need additional research to address the fundamental threat of social
engineering to security.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Beckers</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pape</surname>
            <given-names>S.</given-names>
          </string-name>
          <article-title>A Serious Game for Eliciting Social Engineering Security Requirements</article-title>
          ,
          <source>Proceedings of RE, IEEE Computer Society</source>
          , pp.
          <fpage>16</fpage>
          -
          <lpage>25</lpage>
          ,
          <year>2016</year>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Beckers</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pape</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fries</surname>
            <given-names>V.</given-names>
          </string-name>
          <string-name>
            <surname>HATCH: Hack And Trick Capricious Humans - A Serious Game on Social</surname>
            <given-names>Engineering</given-names>
          </string-name>
          ,
          <source>Proceedings of BHCI, ACM</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>3</lpage>
          ,
          <fpage>2016</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Mitnick</surname>
            ,
            <given-names>K.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Simon</surname>
            ,
            <given-names>W.L.</given-names>
          </string-name>
          :
          <article-title>The Art of Deception</article-title>
          . Wiley (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Hadnagy</surname>
          </string-name>
          . C.:
          <string-name>
            <surname>Social</surname>
          </string-name>
          Engineering - The Art of Human Hacking. Wiley (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Boden. M.</surname>
          </string-name>
          <article-title>A.: The Creative Mind: Myths</article-title>
          &amp;
          <string-name>
            <surname>Mechanisms</surname>
          </string-name>
          (2nd Ed),
          <source>Routledge</source>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>