
Figure 1
Step-by-step process of Kevin Mitnick’s social engineering attack.

Figure 2
Rise and prevalence of social engineering attacks (Chheda 2024).

Figure 3
Different forms of social engineering attacks.

Figure 4
Statistics of Sony picture revenue before and after 2014 hack.

Figure 5
Impact of OCBC Bank phishing scam.

Figure 6
Consequences of database integrity loss.
Table 1
Comparison of existing techniques used for mitigation of social engineering attacks.
| EXISTING TECHNIQUE | TYPE OF ATTACK | METHOD USED | ADVANTAGE | LIMITATION |
|---|---|---|---|---|
| Butt et al. (2022) | Phishing (Email) | Machine Learning and Deep Learning models | Improvement in mitigation by combining dynamic phishing and legitimate emails. | 1. Relying solely on pre-defined features 2. It limits the model’s adaptability |
| Salahdine et al. (2021) | Phishing (Email) | Machine Learning based models | Achieved high accuracy in phishing detection. | Attackers can manipulate search engine rankings to make malicious webpages appear legitimate, reducing the effectiveness of heuristic-based method. |
| Benavides-Astudillo et al. (2023) | Phishing (Webpage) | NLP and Deep Learning | BiGRU model achieved the best results with a mean accuracy of 97.39%. | Explores web page text rather than URLs, phishing attacks often manipulate URLs in deceptive ways |
| Fakieh & Akremi (2022) | Vishing | Blockchain based mechanism | Secure, transparent, and immutable records to enhance security, effective for vishing attacks. | Lack of ability to address more complex social engineering attacks that use multiple vectors like phishing, smishing, or in-person manipulation. |
| Al-Hamar et al. (2021) | Spear-phishing (Email) | Domain authenticity analysis | Outperformed existing email security systems in detecting spear-phishing and whaling attacks. | It may not be effective against phishing attacks using compromised legitimate domains or non-domain-based tactics. |
| Sonowal et al. (2021) | Phishing (Email) | Multi-dimensional feature analysis | Enhanced detection using multiple features and an additional verification layer. | Use of whitelist-based profile for spear-phishing detection may limit its effectiveness against targeted attacks that exploit familiar contacts. |
| Allen et al. (2020) | Water-holing | Forensic analysis engine (Mnemosyne | Reduced manual analysis effort by 98%, enhanced post-attack investigation. | Limited visibility when investigating attacks that rely on a drive by download. |
| Irani et al. (2011) | Reverse social engineering | Analysis of social networks feature | Demonstrated novel RSE attack strategies and their effectiveness, highlighting the need for countermeasures on social networks. | Overlook contextual factors, such as variations in user behavior, platform policies, and the evolving nature of social engineering tactics. |
| Akati & Conrad (2021) | Tail-gaiting | Anti-tailgating solution | Effective prevention of tailgating by overcoming limitations of prior methods. | Lacks full physical implementation and practical testing, confining it to theoretical design and minimal software experimentation. |
| Girinoto et al. (2022) | Pretexting | Social Engineering Session (SES) attack methodology | Successfully gathered sensitive information using pretexting, demonstrating the potential for fraud or marketing exploitation. | Does not account for the broader applicability of the findings across different user groups or platforms. |
Table 2
Social Engineering attacks protective measures.
| MEASURE | SOURCE | BENEFITS | CHALLENGES | RECOMMENDATIONS |
|---|---|---|---|---|
| Employee Education & Training | Weaver et al. (2021); Thomas (2018) | Increases awareness and ability to identify threats. | Time and resources required for effective training. | Schedule regular training sessions and updates. |
| Multi-layered Security Protocols | Montanez et al. (2022); Siadati et al. (2017) | Reduces risk of unauthorized access. | Complexity can lead to user frustration or non-compliance. | Regularly review and update protocols for effectiveness. |
| Continuous Monitoring | Vadrevu & Perdisci (2019) | Early detection of potential threats. | Requires robust infrastructure and resources | Invest in monitoring tools and regular audits. |
| Phishing Detection Training | Weaver et al. (2021) | Empowers users to make informed decisions. | Users may still fall for sophisticated attacks. | Use real-life examples to illustrate threats effectively. |
| Tailgating Prevention | Salahdine & Kaabouch (2019) | Enhances physical security and reduces risk of breaches. | Difficult to enforce consistent behavior. | Conduct regular drills and emphasize the importance of vigilance. |
| Flow Whitelisting | Vadrevu & Perdisci (2019) | Reduces attack surface and improves overall security. | can be challenging to maintain an updated whitelist. | Regularly review and adjust whitelists based on new threats. |
| Access Control | Montanez et al. (2022) | Minimizes potential damage from insider threats | Complexity in managing access rights can arise. | Regular audits to ensure appropriate access levels. |
| Multi-factor Authentication | Siadati et al. (2017) | Significantly increases security against credential theft. | Users may resist additional steps in the login process | Educate users on the importance and benefits of multi factor authentication. |
