<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Implementation of Social Engineering Attack at Institution of Higher Education</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Central China Normal University</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Wuhan</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>China hzb@mail.ccnu.edu.cn</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Borys Grinchenko Kyiv University</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ukraine</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>v.buriachok</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>v.sokolov}@kubg.edu.ua</string-name>
        </contrib>
      </contrib-group>
      <abstract>
        <p>The paper shows an investigation utilizing assaults, for example, a phony passage and a phishing page. The past distributions on social building have been checked on, insights of separations are investigated and bearings and component of acknowledgment of assaults having components of social designing are examined. The information from the examination in three better places were gathered and investigated and the substance measurements were given. For examination, three classifications of advanced education organizations were picked: specialized, helpful and blended profiles. Since the exploration was led in instructive organizations during the week, most understudies in the test and graduate understudies partook in the test. For each instructive establishment, an enrollment structure layout was made that emulated the plan of the principle pages. Instances of equipment and programming execution of an average represent assault, information accumulation and investigation are given. So as to develop a test stand, generally accessible segments were picked to show that it is so natural to complete assaults of this sort without critical introductory expenses and uncommon aptitudes. The paper gives measurements on the quantity of associations, consent to utilize the location of the email and secret word, just as authorization to consequently move administration information to the program (cookies). The insights are prepared utilizing uniquely composed calculations. The proposed ways to deal with taking care of the issue of socio-specialized assaults can be utilized and executed for activity on any objects of data action.</p>
      </abstract>
      <kwd-group>
        <kwd>attack</kwd>
        <kwd>fishing</kwd>
        <kwd>social engineering</kwd>
        <kwd>wireless access point</kwd>
        <kwd>protection</kwd>
        <kwd>personal information</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Nowadays, all businesses are involved in the processes of storing and processing
information. This information may contain sensitive information, the disclosure of
which will cause significant damage to the reputation of the company, its working
capacity or financial position.</p>
      <p>Social engineering is not about computer technology, it’s about the user. Of interest
are all solvent persons, as well as users with valuable information, employees of
enterprises and public institutions. This method is used for financial transactions,
hacking, data theft, such as client databases, personal data, and other unauthorized
access to information. Social engineering helps competitors to scout, identify
weaknesses in an organization, entice employees.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Review of the Literature</title>
      <p>
        The issue of social engineering in domestic academia has emerged at a time of
dramatic increase in the availability of information resources, telecommunications
networks and user terminals. Principles of influence on a person through social
engineering are given in [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. General issues of data leakage are discussed in [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] and
[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], and directly social engineering—in [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] and [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. The problem of providing access
to business information is discussed in [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] and [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>Problem Statement</title>
      <p>
        Worldwide Information System Crash Statistics as of 2018, according to Verizon
Communications Inc. is presented in Fig. 1 [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. According to these statistics, social
engineering ranks third in the number of attacks.
There are many sources of threats to enterprise information and cyber security. The
staff of the enterprise is always involved in the process of storing and processing
information. Therefore, it is important to consider the anthropogenic factor as a real
existing vulnerability in the information security of the enterprise. According to
statistics, social engineering is the most significant threat to the anthropogenic factor.
There are many methods of counteracting social engineering. One such method is to
raise staff awareness of counteracting social engineering methods. Not all businesses
pay due attention to awareness. Therefore, it becomes necessary to create an effective
methodology for raising staff awareness of counteracting social engineering methods.
      </p>
      <p>The purpose of the work is to prepare a sound methodology for raising the level of
awareness of staff in countering social engineering methods. The object of the study
is the process of managing staff awareness. The object of the study is to counteract
social engineering methods.</p>
      <p>The scientific novelty of the work is to develop a methodology for managing
personnel awareness in countering methods of social engineering. The practical value
lies in developing methodological guidance to raise staff awareness of counteracting
social engineering methods, as well as developing a questionnaire to analyze the level
of awareness.</p>
      <p>All the work done is done solely within the scope of the study to determine the
level of user awareness. All sensitive user information, such as passwords, is not
disclosed or stored in the public domain to protect them. The organizer of the research
reserves the right to store, process and publish all collected data, in accordance with
the terms of use of the service, each user who sent the data previously agreed to the
terms of use of the service.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Theoretical Basis</title>
      <p>– introduction of social innovations in the organization;
– social technology workshop;
– methods of conflict resolution.</p>
      <p>
        Basically, social engineering incidents related to staff actions occur because of low
levels of user awareness. Thus, by educating their staff on the basic rules in
information security, organizations can significantly reduce the risk of information
security breaches. No wonder, staff training is one of the main requirements of the
international standard for information security management ISO/IEC 27001 [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>Features of attacks using the human factor:
– do not require significant costs;
– do not require special knowledge;
– can last for a long period;
– difficult to track.</p>
      <p>A person is often much more vulnerable than the system. This is why social
engineering is aimed at obtaining information through a person, especially in cases
where it is impossible to access the system (for example, a computer with important
data is disconnected from the network).</p>
      <p>
        There are several techniques in social engineering that are used to accomplish these
tasks. All of them are based on the mistakes made by a person in behavior [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>Social engineering techniques include:
1. Phishing attacks are the most popular type of fraud in social engineering.
Phishing attack is the illegal acquisition of sensitive user data (login and password).
Often, phishing emails are written poorly and contain grammatical errors. In these
letters, the attackers point to a hyperlink to a copy of the site (for example, a mail
client) with a form where you need to enter your login, password and other personal
information. For example, phishing is used to collect user logins and passwords by
sending letters and messages prompting the victim to provide the necessary
information. You can protect yourself from abusers by ignoring letters from unknown
recipients.</p>
      <p>2. Pretexting is an attack conducted in advance prepared scenario. Such attacks are
aimed at developing a victim’s sense of trust in the attacker. Attacks are usually made
over the phone. This method often does not require the preparation and retrieval of
victim data. Pretexting is about extraditing oneself to another person to obtain the
desired data. You can get information about a person through open access sources,
mainly from social networking pages.</p>
      <p>3. The Trojan horse uses the qualities of a potential victim, such as curiosity and
greed. A social engineer sends an email with a free video or an antivirus update in an
attachment. The victim saves the attachments, which are actually Trojan programs.
This technique will remain effective as long as users continue to mindlessly store or
open any attachments.</p>
      <p>4. Quid pro quo. When using this type of attack, the attackers promise the victim a
benefit in return for the facts. For example, an attacker calls the company, introduces
a support staff, and is offered to install the “necessary” software. Once the consent to
the installation of the programs has been obtained, the offender shall have access to
the system and to all data stored in it.</p>
      <p>5. Feedback implies an unauthorized passage of an attacker along with a legitimate
user through a checkpoint. This method should not be used in companies where
employees need to use passes to enter the territory of the company.</p>
      <p>6. Shoulder surfing is one of the social engineering techniques. It is used in
transportation, cafes and other public places that allow the victim to monitor computer
devices and phones through the victim’s shoulder. There are situations in which the
user himself offers the fraudster the necessary information, being confident in the
decency of the person. In this case, they are talking about reverse social engineering.</p>
      <p>7. Threats when using instant messaging. Users quickly appreciated the
convenience of messaging in real time using the Skype, Viber, WhatsApp, Telegam,
and other networks. The accessibility and speed of this method of communication
makes it open to all kinds of attacks. For security, you should ignore messages from
unknown users, do not give them personal information, do not follow the links sent.</p>
      <p>
        It is obvious that social engineering can do enormous damage to any organization.
That is why every effort should be made to prevent human factor attacks [
        <xref ref-type="bibr" rid="ref12 ref13">12,13</xref>
        ].
      </p>
      <p>Initially, the purpose of influencing a particular object is always formed. “Object”
refers to a victim targeted by an attacker.</p>
      <p>Then, information about the object is collected to identify the most suitable targets
of impact.</p>
      <p>Then comes the stage that psychologists call attraction. Attraction is the creation of
the necessary conditions for the attacker to influence the object.</p>
      <p>Forcing a social hacker to take action is usually achieved by performing the
previous steps, that is, once the attraction is reached, the victim creates the actions
that the attacker needs. However, in some cases this stage becomes independent, for
example, when the compulsion to act is accomplished by introducing into a trance,
psychological pressure, etc.</p>
      <p>All attacks by social hackers fit into one fairly simple scheme (Fig. 2).</p>
    </sec>
    <sec id="sec-5">
      <title>Method of Research</title>
      <p>Usually, for the convenience of people, most public Wi-Fi networks are left open,
making them a good place for a variety of attacks. This fact is the inspiration for this
study.</p>
      <p>So it was decided to create an open Wi-Fi network to collect data from the victims
as follows:
– ability to connect to a wireless network for anyone;
– pseudo-interface for registering a user on a network whose primary task will be
to collect the victim’s data, including the data it will provide us and the data we
receive from the victim’s browser, namely the User-Agent and Cookies for the
domain that the victim wanted to access. us to use its authentication on this domain;
– adjust the equipment so that it can operate in full offline mode;
– put the equipment in places of crowds of people;
– pick up the equipment in a week (high capacity batteries should be used to
achieve autonomy).</p>
      <p>The following hardware is included in the experiment:
– miniature single-board, energy-efficient computer based on ARM architecture
with the ability to connect devices via USB;
– USB-MicroUSB power cable;
– portable battery (power bank) with USB interface;
– 802.11n wireless network adapter with USB interface and external antenna;
– USB-USB extender for easy placement of elements;
– MicroSDHC Class 10 memory card.</p>
      <p>The following equipment was selected for the test bench: Raspberry Pi 3 Model B,
SanDisk MicroSDHC 16Gb Class 10, Trust PowerBank 10 000 mAh, Tp-Link
TLWN722N v3. In Fig. 3 shows a test bench in its assembled and on state.
To implement the fake hotspot and phishing interface, the following software toolkit
has been defined on it:
– hostapd is Wi-Fi hotspot service;
– dnsmasq is DHCP and DNS server;
– lighttpd is web server;
– PHP is web server programming language;
– HTML is CSS and JavaScript stack for browser representation;
– SQLite is database for storing data.</p>
      <p>As part of the experiment, three profiles of higher education institutions were
selected:
– technical (State University of Telecommunications, Kyiv);
– humanities (Borys Grinchenko Kyiv University, Kyiv);
– mixed (Lviv Polytechnic National University, Lviv).</p>
      <p>A separate phishing website was developed for each of them (Fig. 4 shows an
example of a page for (Borys Grinchenko Kyiv University).
The terms of service (privacy policy) have been developed for the validity of this
study. Agreeing to the privacy policy of the user before sending the data gives the
organizer a legitimate reason for storing, processing and publishing this data. The
access point did not have internet access, so the data was collected only the first time,
the data was stored only as statistics.
6</p>
    </sec>
    <sec id="sec-6">
      <title>Research Results</title>
      <p>While analyzing the results, there was a need to automate the information processing
and data linking process. In particular, the following program was written in C#/.NET
v. 4.5 to create mappings between MAC and IP addresses and actions on the web
server.</p>
      <p>The study provided technical data (operating system, browser version, mobile device
manufacturer, etc.), behavior data (reconnection) and user data (email, passwords,
cookies, request to the target site). Of all the data, the most valuable value for social
engineering research is the behavior and personal data that users have agreed to share.</p>
      <p>A good indicator of internet accessibility is the percentage of reconnections. From
the diagram in Fig. 5 shows that the number of attempts to reconnect does not depend
on the profile of the institution of higher education, but only on the availability of
alternative wireless networks.
The statistics on the ease with which users share their email address and even their
passwords are shown in Fig. 6. The trend shows an increase in the percentage of
personal data provided by students in the humanities profile, but still the trust in
unknown open networks is quite high among the students of technical higher
education institutions. The high percentage of password entry is due to the input of
non-existent passwords.
The issue is the openness of cookies, because to get more functionality from web
resources, most users allow this data to be exchanged without a single request for data
transfer. From Fig. 7 shows that the number of users sharing a cookie depends only
partially on the profile of the institution of higher education. Therefore, the issue of
cookie openness should be considered as a general danger of data exchange, and not
just as an aspect of social engineering.</p>
    </sec>
    <sec id="sec-7">
      <title>Acknowledgments</title>
      <p>This scientific work was partially supported by RAMECS and self-determined
research funds of CCNU from the colleges’ primary research and operation of MOE
(CCNU19TS022).
8</p>
    </sec>
    <sec id="sec-8">
      <title>Conclusions and Further Research</title>
      <p>During the work there were problems in the configuration of the lighttpd software. By
default, this web server does not use logging of all hits, unlike Apache httpd.
Therefore, statistics such as device manufacturers from devices that provided Web
server data are not available at the State Telecommunication University. This fact was
taken into account and the number of information collection points was increased to
three.</p>
      <p>During the work, a number of problems were solved related to logging, automation
of data analysis and processing, configuring IPv4 network addressing, intercepting all
user requests, and more. Issues resolved regarding reconciliation between data
collected by different software.</p>
      <p>The main task of the work is to investigate the awareness of users regarding social
attacks, it was solved and sufficient statistics were obtained during the study. Because
the test bench is built on widely available components and open source software, this
kind of attack can easily be replicated by anyone with a technical background in
computer engineering and information security.</p>
      <p>Experiments show that users’ awareness of even the technical specialties is
insufficient, so special attention should be paid to developing techniques for raising
user awareness and reducing the number of potential attacks on information objects.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Nemtseva</surname>
            ,
            <given-names>O. O.:</given-names>
          </string-name>
          <article-title>The notion of informational and psychological influence</article-title>
          .
          <source>Soc. Commun.: Theory Pract</source>
          .
          <volume>1</volume>
          :
          <fpage>55</fpage>
          -
          <lpage>66</lpage>
          (
          <year>2015</year>
          ) [Ukrainian].
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Emelyanov</surname>
            ,
            <given-names>S. L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nosov</surname>
            ,
            <given-names>V. V.</given-names>
          </string-name>
          :
          <article-title>Ways and channels of information leakage from a typical object of informatization</article-title>
          .
          <source>Law Saf</source>
          .
          <volume>1</volume>
          :
          <fpage>273</fpage>
          -
          <lpage>279</lpage>
          (
          <year>2009</year>
          ) [Ukrainian].
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Filippova</surname>
          </string-name>
          , L. Y.:
          <article-title>Information paradigm of social communication (review of scientific approaches and concepts)</article-title>
          .
          <source>Bull. Kharkiv State Acad. Cult</source>
          .
          <volume>39</volume>
          :
          <fpage>79</fpage>
          -
          <lpage>86</lpage>
          (
          <year>2013</year>
          ) [Ukrainian].
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Dashko</surname>
            ,
            <given-names>D. A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Meshkov</surname>
            ,
            <given-names>V. I.</given-names>
          </string-name>
          :
          <article-title>Social engineering from the point of view of information security</article-title>
          . In: V Ukrainian Conference “ITBtaZ,” pp.
          <fpage>1</fpage>
          -
          <lpage>2</lpage>
          . DVNZ “NGU,
          <string-name>
            <surname>”</surname>
            <given-names>LLC</given-names>
          </string-name>
          “Salvia,”
          <string-name>
            <surname>Kyiv</surname>
          </string-name>
          (
          <year>2013</year>
          ) [Russian].
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Daddyuk</surname>
            ,
            <given-names>A. V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petryk</surname>
            ,
            <given-names>V. M.</given-names>
          </string-name>
          :
          <article-title>Counteraction to Automated Means of Using Social Engineering</article-title>
          . In:
          <article-title>IX All-Ukrainian Scientific and Practical Conference “Actual Problems of Information Security Management of the State</article-title>
          ,” pp.
          <fpage>346</fpage>
          -
          <lpage>347</lpage>
          . NASBU,
          <string-name>
            <surname>Kyiv</surname>
          </string-name>
          (
          <year>2018</year>
          ). [Ukrainian].
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Navrotsky</surname>
            ,
            <given-names>Y. Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Patsey</surname>
            ,
            <given-names>N. V.</given-names>
          </string-name>
          :
          <article-title>Implementation of caching policies in informationoriented networks</article-title>
          .
          <source>In: Proceedings of BSTU</source>
          , vol.
          <volume>3</volume>
          (
          <issue>1</issue>
          ), pp.
          <fpage>99</fpage>
          -
          <lpage>103</lpage>
          , Minsk (
          <year>2018</year>
          ) [Russian].
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Fan</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lwakatare</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rong</surname>
          </string-name>
          , R.:
          <article-title>Social engineering: I-E based model of human weakness for attack and defense investigations</article-title>
          .
          <source>Int. J. Comput. Netw. Inf. Secur</source>
          .
          <volume>9</volume>
          (
          <issue>1</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>11</lpage>
          (
          <year>2017</year>
          ). DOI:
          <volume>10</volume>
          .5815/ijcnis.
          <year>2017</year>
          .
          <volume>01</volume>
          .01
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Verizon</surname>
            <given-names>Communications</given-names>
          </string-name>
          :
          <article-title>Data breach investigations report</article-title>
          .
          <source>11th edn.</source>
          ,
          <volume>68</volume>
          p. (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9. InfoWatch:
          <article-title>Modern threats emanating from information systems</article-title>
          . 12 p. (
          <year>2017</year>
          ) [Russian].
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>International</surname>
            <given-names>ISO</given-names>
          </string-name>
          /IEC standard 27001:
          <year>2013</year>
          .
          <article-title>Information technology</article-title>
          .
          <source>Methods of protection. Information security management systems. Requirements</source>
          .
          <volume>34</volume>
          p. (
          <year>2013</year>
          ) [Russian].
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Shatkovsky</surname>
            ,
            <given-names>M. O.:</given-names>
          </string-name>
          <article-title>The influence of social engineering on the information security of organizations</article-title>
          . NTUU “KPI”,
          <string-name>
            <surname>Kyiv</surname>
          </string-name>
          (
          <year>2015</year>
          ) [Ukrainian].
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Anisimova</surname>
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vasylenko</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fedushko</surname>
            <given-names>S</given-names>
          </string-name>
          .
          <article-title>Social Networks as a Tool for a Higher Education Institution Image Creation</article-title>
          .
          <source>CEUR Workshop Proceedings. - 2019</source>
          . Vol 2392: COAPSN-2019. P.
          <volume>54</volume>
          -
          <fpage>65</fpage>
          . http://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>2392</volume>
          /paper5.pdf
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Sokolov</surname>
          </string-name>
          , V. Y.,
          <string-name>
            <surname>Korzhenko</surname>
            ,
            <given-names>O. Y.</given-names>
          </string-name>
          :
          <article-title>Analysis of recent attacks based on social engineering techniques</article-title>
          .
          <source>In All-Ukrainian Scientific and Practical Conference of Higher Education Applicants</source>
          and Young Scientists “Computer Engineering and Cyber Security: Achievements and Innovations,” pp.
          <fpage>361</fpage>
          -
          <lpage>363</lpage>
          . CNTU,
          <string-name>
            <surname>Kropyvnytskyi</surname>
          </string-name>
          (
          <year>2018</year>
          ). DOI:
          <volume>10</volume>
          .5281/zenodo.2575459.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>