An automatic generation method for social engineering attack defense strategy based on security model
Through an automatic generation method based on security patterns, the problems of lack of systematicness and time-consuming manual analysis in existing social engineering attack defense strategies are solved, and automated, comprehensive and efficient defense strategy generation is achieved, which is suitable for large-scale social technical systems.
Patent Information
- Application Number
- CN202211492203.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-25
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2042-11-25
AI Technical Summary
Existing technologies lack systematic and specific strategies for defending against social engineering attacks, rely on manual analysis, which is time-consuming and labor-intensive, and cannot be applied on a large scale to social technical systems.
An automatic generation method based on security patterns is adopted to automatically match social engineering attack threats and generate defense strategies through scenario modeling, formalizing scenario models, generating candidate patterns and sorting defense plans.
It achieves efficient and automated generation of defense strategies for social engineering attacks, which is applicable to large-scale socio-technical systems and improves the comprehensiveness and practicality of defense strategies.
Smart Images

Figure CN116527293B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of social engineering attack defense, and in particular to a method for automatically generating a social engineering attack defense strategy based on a security model, which is suitable for generating a social attack defense strategy based on a security model for known attack threats. Background Art
[0002] Today, social engineering attacks are posing a serious threat to large-scale socio-technical systems. Compared to software vulnerabilities that have been explored for decades, more attackers are using social engineering techniques to exploit people's vulnerabilities to achieve their malicious goals.
[0003] While social engineering attacks have long attracted attention, their interdisciplinary nature requires expertise from multiple fields (such as information security, sociology, and psychology) and has not been systematically and thoroughly studied. Specifically, one group of social engineering researchers focuses on conceptualizing social engineering to lay the ontological foundation for social engineering research. Another branch of research focuses on identifying potential social engineering threats. Currently, there is a lack of comprehensive and effective countermeasures to protect systems from social engineering attacks.
[0004] Some studies have attempted to identify countermeasures to social engineering, but have yielded limited results. For example, training and educating system stakeholders can be used to defend against social engineering attacks. For example, Mann (2011) highlighted the importance of correlating human vulnerabilities with social engineering attack techniques, identifying high-threat social engineering attacks through an analysis of system stakeholders and implementing targeted training. Aldawood and Skinner (2012) synthesized existing knowledge, identified the most common social engineering threats, and developed information security education programs. Schaab et al. conducted a literature review from the perspectives of IT security and social psychology and developed two training strategies, outlining how interdisciplinary research between computer science and social psychology can lead to more comprehensive defenses against social engineering. Training and educating system stakeholders is indeed an effective way to defend against social engineering attacks. However, some proposed training and education methods are not specific enough and have no practical effect. Furthermore, most countermeasures to social engineering remain undiscovered.
[0005] Recently, some studies have mentioned protocols and policies that include a range of physical means to eliminate the risk of attack and some clear procedures and guidelines to protect systems from social engineering attacks. For example, Saleem and Hammoudeh outlined common social engineering mitigation strategies.
[0006] However, they only outlined these defense strategies without specific implementation details. Yasin et al. proposed social engineering countermeasures tailored to specific attack scenarios to defend against these attacks. While the proposed countermeasures provide implementation details, the methodology is not systematic and comprehensive enough. For example, Yasin only proposed six social engineering countermeasures. More importantly, all existing social engineering defense research relies heavily on manual analysis, which is time-consuming and labor-intensive, making it impractical for practical application to large-scale sociotechnical systems. Summary of the Invention
[0007] Aiming at the method of defending against social engineering attacks in the field of social engineering, in order to solve the above-mentioned problems existing in the prior art, the present invention provides a method for automatically generating social engineering attack defense strategies based on a security model, which is suitable for generating social attack defense strategies based on a security model for known attack threats.
[0008] The present invention comprises the following steps:
[0009] Step (1) Modeling the input attack threat scenario:
[0010] The enterprise provides specific social engineering attack threat information and models the attack scenario based on the ontology model of the present invention. The specific attack scenario modeling process is as follows: Figure 3 When the modeling is completed, proceed to step (2).
[0011] Step (2) Formalize the scenario model:
[0012] Existing social engineering defense research relies heavily on manual analysis, which is time-consuming and labor-intensive, and cannot be practically applied to large-scale socio-technical systems. We designed formal predicates to formalize attack scenarios to automatically match social engineering security patterns. The specific content of the formal predicates is shown in Table 1. Once the scenario formalization is completed, proceed to step (3).
[0013] Step (3) generates candidate patterns for each attack threat:
[0014] In this step, we generate candidate patterns for each threat scenario to defend against social engineering attacks. We design matching rules to match candidate patterns for each threat scenario. The specific matching rules are shown in Table 2.
[0015] Step (4) Generate defense plans and sort the generated defense plans:
[0016] Finally, in order to generate a comprehensive defense plan to defend against social engineering attacks, defense plans for all attack threats are generated based on the candidate patterns of each attack threat and the defense plans are ranked according to security, usability, economy and the number of patterns in the defense plans. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 Flow chart of the method of the present invention.
[0018] Figure 2 This is a schematic diagram of the social engineering ontology model of the present invention.
[0019] Figure 3 A flowchart for scenario modeling of the present invention. DETAILED DESCRIPTION
[0020] A brief overview of the present invention is provided below to provide a basic understanding of certain aspects of the present invention. It should be understood that this overview is not an exhaustive overview of the present invention. It is not intended to identify key or important aspects of the present invention, nor is it intended to limit the scope of the present invention. Its purpose is simply to present certain concepts in a simplified form as a prelude to the more detailed description discussed later.
[0021] The method for automatically generating social engineering attack defense strategies based on security patterns mentioned in this paper includes the following steps: step (1) modeling the input attack threat scenario, step (2) formalizing the scenario model, step (3) generating candidate patterns for each attack threat, and step (4) generating defense plans and sorting the generated defense plans.
[0022] Step (1) Model the input attack threat scenario:
[0023] Existing ontology models generally describe social engineering scenarios from the perspectives of attackers, attack techniques, attack vectors, assets, etc. However, they all neglect the analysis of victims and the social engineering attack process. Based on the existing ontology models, this paper analyzes the relationship between victims in the scenario and the process of the complete social engineering attack. The specific social engineering ontology model is as follows: Figure 2 shown.
[0024] The specific process of scene modeling in step (1) above is as follows: Figure 3 The specific contents are described as follows:
[0025] Step (1.1) Modeling roles and role relationships:
[0026] Based on the attack scenario, we identify all roles and their relationships. These relationships can be considered based on the role concept in the ontology model. In real-world social engineering attack cases, we compiled five role relationships into the ontology model: supervisor, colleague, collaborator, stranger, and authority figure. Furthermore, attackers often play a role when carrying out social engineering attacks. We also modeled the attacker and used the play relationship to represent the role played by the attacker.
[0027] Step (1.2) Modeling goals, assets and tasks:
[0028] Based on the attack scenario information, we determine the goals, assets, and tasks for all roles. Goals and tasks are the specific company business objectives and tasks of the roles. Assets can be considered based on the concept of human assets in the ontology model. In the ontology model, human assets are categorized into information assets, software assets, equipment assets, and permissions.
[0029] Step (1.3) Social Engineering Techniques, Attack Media, and Attack Steps:
[0030] Based on the attack scenario, we identify the social engineering techniques and attack media used by the attacker in the scenario. We then identify the attack steps, as closely as possible, based on the attack step concepts in the ontology model. If none exist, we skip identifying the attack steps and focus solely on identifying the social engineering techniques and attack media. In the ontology model, we categorize social engineering techniques into dumpster diving, shoulder surfing, attention-grabbing techniques, reverse social engineering techniques, masquerading techniques, phishing techniques, incentive manipulation techniques, responsibility manipulation techniques, intimidation manipulation techniques, authority manipulation techniques, and tailing techniques; and we categorize attack media into face-to-face, telephone, email, and website.
[0031] Step (2) Formalize the scenario model:
[0032] All existing research on social engineering defenses relies heavily on manual analysis, which is time-consuming and labor-intensive, making it impractical for large-scale socio-technical systems. To address these issues, we designed formal predicates to formalize attack scenarios, enabling automated matching of social engineering security patterns to defend against social engineering attacks. The specific formal predicates are shown in Table 1.
[0033] Step (3) generates candidate patterns for each attack threat:
[0034] To match social engineering security patterns, we designed matching rules for social engineering security patterns. Each pattern is applicable to a specific social engineering attack scenario. Based on the scenario information formalized in step (2), we match the security pattern corresponding to each attack threat in the scenario to defend against the attack threat. The specific matching rules are shown in Table 2.
[0035] Step (4) Generate defense plans and sort the generated defense plans:
[0036] Finally, a defense plan is generated for the attack scenario modeled in step (1). Based on the candidate patterns of each attack threat, a defense plan for all attack threats is generated and the defense plans are ranked according to security, availability, economy, and the number of patterns in the defense plan. A specific implementation example can be shown in Table 3. Based on the framework for automatically generating social engineering attack defense strategies by applying social engineering security patterns, a corresponding defense plan is generated for the input attack threat to defend against social engineering attacks.
[0037] Table 1 Formalized predicates of the scenario model
[0038]
[0039]
[0040] Table 2 Security pattern matching rules
[0041]
[0042] Table 3 Algorithm for generating and ranking social engineering defense plans
[0043]
[0044]
Claims
1. A method for automatically generating a social engineering attack defense strategy based on a security model, characterized in that: The following steps are involved: Step (1) Modeling the input attack threat scenario: Enterprises provide specific social engineering attack threat information and model attack scenarios based on the ontology model; When modeling is completed, execute step (2); Step (2) Formalize the scenario model: Formal predicates are designed to formalize the attack scenario to automatically match the social engineering security model; When the scenario formalization is completed, execute step (3); Formalized predicates include: Type Predicates, Association Relation, Has, Need and Depend, and Social Engineering Attack. In the type predicates, role and agent are used to represent the concepts of role and attacker, task represents task, asset represents asset, label represents label, goal represents goal, and technique represents social engineering technique. The related relationship predicates colleague, stranger, cooperator, supervisor, and authority are all used to represent the relationship between roles. The predicate play represents the role played by the attacker. In the permission-asset predicate, the predicate has-task indicates that a role has a task, the predicate has-asset indicates that a role has an asset, and the predicate has-goal means that the attacker achieves a goal through social engineering techniques; The dependency predicates need and depend represent the relationship between assets and tasks; The social engineering attack predicates tailgating, reverse social engineering, shoulder surfing, dumpster diving, intimidation, impersonation, incentive, responsibility, distraction, authority, and phishing respectively indicate that the attacker uses the corresponding social engineering techniques to carry out the attack through the attack medium; Step (3) Generate candidate patterns for each attack threat: Generate corresponding candidate patterns for each attack threat in the scenario to defend against social engineering attack threats; design matching rules to match the candidate patterns of each attack threat in the attack scenario; Step (4) generates defense plans and ranks the generated defense plans. In order to generate a comprehensive defense plan to defend against social engineering attacks, defense plans for all attack threats are generated based on the candidate patterns of each attack threat and the defense plans are ranked according to security, availability, economy and the number of patterns in the defense plans.
2. The method for automatically generating a social engineering attack defense strategy based on a security model according to claim 1, characterized in that: The specific process of scene modeling in step (1) is as follows: Step (1.1) Modeling roles and role relationships: Based on the attack scenario information, determine all roles and their relationships. The relationships between roles are considered based on the role concept in the ontology model. In real social engineering attack cases, five role relationships are compiled in the ontology model: supervisor, colleague, collaborator, stranger, and authority figure. Attackers often play a role when carrying out social engineering attacks. The attacker is modeled and the role played by the attacker is represented using the play relationship. Step (1.2) Modeling goals, assets, and tasks: Based on the attack scenario information, determine the goals, assets, and tasks of all roles. The goals and tasks are the specific company business goals and tasks of the roles. Assets are considered based on the concept of human assets in the ontology model. In the ontology model, human assets are divided into information assets, software assets, equipment assets, and permissions. Step (1.3) Modeling social engineering techniques, attack media, and attack steps: Based on the attack scenario information, we determine the social engineering techniques and attack media used by the attacker in the scenario; then, we identify the attack steps based on the attack step concept in the ontology model; if there are no attack steps, we skip identifying the attack steps and only identify the social engineering techniques and attack media; in the ontology model, social engineering techniques are divided into trash can rummaging, shoulder surfing, attention-grabbing techniques, reverse social engineering techniques, disguise techniques, phishing techniques, incentive manipulation techniques, responsibility manipulation techniques, intimidation manipulation techniques, authority manipulation techniques, and tailing techniques; The attack media are divided into face-to-face media, telephone media, email media, and website media.