Authors

A.A. AZAROV, A.V. SUVOROVA, A.L. TULUPIEV, T.V. TULUPIEVA

Abstract

The article discusses an approach to assessing the security of users of information systems from the social engineering attack of an attacker, based on a model of a random process with discrete time. The approach is based on previously proposed user vulnerability profile models. The study is devoted to the analysis of changes in the state of an information system and users of this system who are under the influence of socio-engineering attacking influences of an attacker. These effects are considered as a random process with discrete time, which allows you to simulate changes in the state of the system from the moment when the system is at rest, that is, not attacked by an attacker. Modeling using Markov networks makes it possible to identify users and their vulnerabilities, which are more susceptible to socioengineering attack influences than all others.

Keywords

social engineering attacks, user protection, random process with discrete time, user vulnerability profile.