Information Leakage through Online Social Networking: Opening the Doorway for Advanced Persistence Threats

نویسندگان

  • Nurul Nuha Abdul Molok
  • Shanton Chang
  • Atif Ahmad
چکیده

The explosion of online social networking (OSN) in recent years has caused damages to organisations due to leakage of information by their employees. Employees’ social networking behaviour, whether accidental or intentional, provides an opportunity for advanced persistent threats (APT) attackers to realise their social engineering techniques and undetectable zero-day exploits. APT attackers use a spear-phishing method that targeted on key employees of victim organisations through social media in order to conduct reconnaissance and theft of confidential proprietary information. This conceptual paper posits OSN as the most challenging channel of information leakage and provides an explanation about the underlying factors of employees leaking information via this channel through a theoretical lens from information systems. It also describes how OSN becomes an attack vector of APT owing to employees’ social networking behaviour, and finally, recommends security education, training and awareness (SETA) for organisations to combat these threats.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

The State of Online Social networking among Library and Information Sciences Students

Background and Aim: The present paper discusses results of a study which aimed to explore the knowledge and use of Online social networking by MLIS students in Iran and to explore their perceptions of using that technology for academic and professional purposes, and challenges they face for using them. Method: The research method was explorative and empirical. Data was collected through a web-b...

متن کامل

Online Social Networking: A Source of Intelligence for Advanced Persistent Threats

The professionalization of computer crime has resulted in a shift in motivation away from bragging rights towards financial gain. As a result, the operational tactics of cyber criminals is beginning to incorporate reconnaissance and intelligence gathering to inform attack planning. This paper discusses why information leakage in general, and Online Social Networking (OSN) in particular has beco...

متن کامل

Exploring The Use Of Online Social Networking By Employees: Looking At The Potential For Information Leakage

The proliferation of online social networking (OSN) in recent years has caused organizations information security threats due to disclosure of information by their employees on their sites. The accessibility of OSN to anyone, at any time, using any devices, causes confidential and sensitive organizational information to be disclosed to unauthorised individuals, whether accidentally or intention...

متن کامل

Paradigm Shift in the Security-n-Privacy Implementation of Semi-Distributed Online Social Networking

Social Networking Applications has gained tremendous response from all the sections of people across the entire world from last few years. Social networking has crossed all the boundaries and glued whole world population together. Users of OSN (Online Social Networking) sites can re-connect with school friends, find some activity or even life partners, and make new friends. OSN has also revolut...

متن کامل

A Sudy on Information Privacy Issue on Social Networks

In the recent years, social networks (SN) are now employed for communication and networking, socializing, marketing, as well as one’s daily life. Billions of people in the world are connected though various SN platforms and applications, which results in generating massive amount of data online. This includes personal data or Personally Identifiable Information (PII). While more and more data a...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010