A Conceptual Model of Social Engineering



Journal of Information System Security
Volume 7, Number 2 (2011)
Pages 313
ISSN 1551-0123
Marcus Nohlberg — University of Skövde, Sweden
Benkt Wangler — University of Skövde, Sweden
Stewart Kowalski — Stockholm University, Sweden
Information Institute Publishing, Washington DC, USA




Social engineering is a term used for techniques to trick, or con, users into giving out information to someone that should not have it. In this paper we discuss and model various notions related to social engineering. By using a broad, cross disciplinary approach, we present a conceptual model of the different kinds of social engineering attacks, and their preparation, the victim and the perpetrator, as well as the cultural aspects. By using this approach a better general understanding of social engineering can be reached. The model is also a good tool for teaching about and protecting against social engineering attacks.




Social Engineering, Information Security, Conceptual Model, Phishing




