Bonanza Offer FLAT 20% off & $20 sign up bonus Order Now
CS683
SA
Saudi Electronic University
The social engineering attack could be determined to be the kind of the manipulation done to people for ensuring that the confidential information is being gained easily. The kinds of information that are being gained by the criminals could easily vary from the people to people but when the individuals are being targeted, the individuals would easily gain the access in the system through the manipulation of the individual by making them something to be authentic when it is not authentic. The organisation that is being selected for the experiment of the social engineering attack is the Jadwa investment, which is the Saudi organisation functioning in the financial sector. This report intends to execute the social engineering experiment on the Jadwa investment and then attempt to steal the sensitive information from the organisation through the manipulation of individuals.
The experiment that is being conducted on the organisation is the phishing attack. It has been considered that the employees of the organisation would be targeted for being the victim of the attack and they would be sent with the email comprising of malicious software that would be able to gain access in the database where the data is being stored of the organisation. It could be analysed that the organisational employees would be sent the email and it would be made mandatory to open the files. When the file would be opened by the individual, then the embedded malicious program would travel to the system of the individual and it would be able to provide the details of the sensitive information that is being stored in the system. The individual would be requested to install the program that would be attached in the email that is being sent and when the installation would be successfully completed by the individual, the access in the system would be gained.
Phishing could be considered to be the kind of the social engineering attack that is frequently being used for stealing the user data, involving the login credentials as well as the credit card numbers (Benavides et al., 2020). It mainly occurs when the attacker, masquerading as the trusted entity, dupes the victim into the opening the email, text message or even any email message. This recipient is particularly then tricked into the clicking the malicious link that could lead to the installation of the malware, freezing of this system as the part of the ransomware attack or even the revealing of the sensitive information that is being stored in the workstations. Particularly, the kind of phishing that would be used for ensuring that the sensitive information is being gained is the method of spear phishing. The spear phishing could be considered as the phishing method where the malicious user (Zabihimayvan & Doran, 2019) would be targeting any particular person or even the enterprise as opposed to the random users of the application. It could be considered to be the increasingly in-depth version of the phishing that needs the special understanding regarding the organisation, involving the power structure (Hota, Shrivas & Hota, 2018). The sequence of steps that would be followed for ensuring that the spear phishing method is being successfully executed are:
The weakness of the system that is being exploited in this situation is the lack of the proper security protocols and the security measure of not opening any email from the unknown senders and no matter what, the programs would not be installed in the workstation of the organisation without the proper approval from the higher management (Gajera et al., 2019). The installation of the programs would only be done by the IT department of the organisation after the proper analysis of the software that is needed. No attachment including the links would be opened and then travelled to the location where the page is taking the employees (Nguyen, Rosoff & John, 2017).
The recommendations that are being provided to the Jadwa Investment organisation for ensuring that the organisation does not face the situation of the phishing attack are:
Proper information to be provide regarding phishing attacks: The employees of the organisation would be required to be provided with the proper information about the phishing attacks what damage it could do in the organisation. The methods by which the phishing attacks could be prevented should be properly taught to the organisational employees and it would be ensured that the proper security protocols and security measures are implemented in the organisation (Munivel & Kannammal, 2019).
Installing the anti-phishing toolbar: The browsers that are being used in the organisation would be upgraded by installing the anti-phishing toolbar. The toolbar would help in ensuring that the quick checks are being executed on various sites that are being visited and then it would be compare with the list of the various known sites of phishing.
Implementation of firewalls: The firewalls would be implemented in the organisational network for ensuring that the malicious programs are not being installed in the network of the organisation that could pose major threat to the data that is being stored in the server of the organisation. The firewall would help in providing the organisational employees with the methods and practices that even if the malicious programs are being installed in the system by mistake, it would protect the organisational system properly.
Use of the antivirus software: There are various kinds of reasons of using the antivirus software. The special signatures that have been included with the antivirus software guards against the popularly known workarounds of the technology as well as the loopholes. It has to be monitored that the system that is being used should be regularly updated and maintained at the proper level. The firewall setting and the anti-spyware must be properly used for preventing the phishing attacks and the users must regularly update all the programs constantly (Pienta, Thatcher & Johnston, 2018).
Therefore, the conclusion could be determined from the above discussion that presently due to the lack of the proper security measures and the security protocols in the Jadwa Investment organisation, the malicious users could easily manipulate the organisational employees into providing the sensitive information. The phishing method of social engineering attack is being used for determining the steps that are being used for gaining the access in the system and gain control over the data that is being stored in the organisational server.
Benavides, E., Fuertes, W., Sanchez, S., & Sanchez, M. (2020). Classification of phishing attack solutions by employing deep learning techniques: A systematic literature review. Developments and advances in defense and security, 51-64.
Hota, H. S., Shrivas, A. K., & Hota, R. (2018). An ensemble model for detecting phishing attack with proposed remove-replace feature selection technique. Procedia computer science, 132, 900-907.
Jain, A. K., & Gupta, B. B. (2021). A survey of phishing attack techniques, defence mechanisms and open research challenges. Enterprise Information Systems, 1-39.
Chen, X., Liu, X., Zhang, L., & Tang, C. (2019). Optimal defense strategy selection for spear-phishing attack based on a multistage signaling game. IEEE Access, 7, 19907-19921.
Nguyen, K. D., Rosoff, H., & John, R. S. (2017). Valuing information security from a phishing attack. Journal of Cybersecurity, 3(3), 159-171.
Munivel, E., & Kannammal, A. (2019). New authentication scheme to secure against the phishing attack in the mobile cloud computing. Security and Communication Networks, 2019.
Buber, E., Diri, B., & Sahingoz, O. K. (2017, December). NLP based phishing attack detection from URLs. In International Conference on Intelligent Systems Design and Applications (pp. 608-618). Springer, Cham.
Pienta, D., Thatcher, J. B., & Johnston, A. C. (2018, December). A taxonomy of phishing: Attack types spanning economic, temporal, breadth, and target boundaries. In Proceedings of the 13th Pre-ICIS Workshop on Information Security and Privacy, San Francisco, CA, USA (Vol. 1).
Zabihimayvan, M., & Doran, D. (2019, June). Fuzzy rough set feature selection to enhance phishing attack detection. In 2019 IEEE International Conference on Fuzzy Systems (FUZZ-IEEE) (pp. 1-6). IEEE.
Gajera, K., Jangid, M., Mehta, P., & Mittal, J. (2019, June). A novel approach to detect phishing attack using artificial neural networks combined with pharming detection. In 2019 3rd International conference on Electronics, Communication and Aerospace Technology (ICECA) (pp. 196-200). IEEE.
Do you think, “I wish a professional could write my assignment for me?” whenever deadlines come knocking on your door? Then we’ve got the best news for you! At Myassignmenthelp.co.uk, you can avail yourself of the best finance assignment help in the UK. But that’s not all! You can also explore top-notch accounting assignment help without worrying about burning a hole in your pocket.
Our affordable services have become the top choice for students looking for reliable coursework help at a moment's notice. Moreover, our experts are always available to answer your queries. So, feel free to send us your questions, and you're guaranteed high-quality homework help services 24/7.
Upload your Assignment and improve Your Grade
Boost Grades