透過您的圖書館登入
IP:3.139.64.23
  • 學位論文

電子郵件社交工程與資訊安全認知行為之研究探討-以某企業為例

A Study of E-mail Social Engineering and Information Security Behavior Recognition – Case Study of An Enterprises

指導教授 : 胡念祖
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


摘 要 在資訊科技普及的今日,我國不遺餘力的推廣資訊對生活方面的應用。但隨著網路環境的普及,資安事件之層出不窮;致使政府開始逐漸重視資訊安全之各項領域。所以行政院研究發展考核委員會,開始積極推動國家資通安全會報組織的成立,並協助政府機關民間企業導入資訊安全相關政策及輔導措施。 由於企業員工對資訊安全防護認知的不足與輕忽,造成了企業資訊安全的一大漏洞,公司即使投資了各種網路防護等軟硬體及加上良好的保全系統保護機房的安全,結果仍可能不堪一擊。因為社交工程利用人性容易相信而上當的弱點,避開了不容易破解的網路防火牆,應用了簡單的溝通和欺騙技巧,便突破了企業耗資千萬的安全防護,所花費的成本竟然只有幾封e-mail郵件,或者利用一、兩通電話就有可能造成企業的莫大損失。 本研究希望透過企業內部電子郵件社交工程的演練、資安教育訓練及資安宣導,讓企業員工了解由於個人之因素可能導致企業遭受資安事件的危害,並且進一步建立員工之資訊安全基本認知。經由以上3點架構希望能夠使員工在資訊安全認知上有更深一層的了解,並且培養員工正確的使用習慣,以便改善企業資訊環境的體質。 就以上之敘述在此規劃二大主題方向進行研究探討: 一、企業內部員工在電子郵件社交工程演練後,探討員工在演練前後之差異性以及在點擊郵件篩選之認知上是否有明顯之提升,進而降低機密文件及個人資料外洩等資安事件之發生。 二、透過資安教育訓練與宣導,探討是否能夠提升員工之資訊安全認知。當了解資訊安全對企業之重要性後,進而避免個人及企業遭受到資安的危害。 結合以上二大主題透過企業內部社交工程演練及單位內部問卷調查實證,探討企業內部員工對電子郵件社交工程演練及資訊安全認知上的了解程度。

並列摘要


ABSTRACT Because most of the employees are careless with information security, that will cause the security vulnerability in an enterprise. Although the company constructs the system with hardware/software for network protection, however, that is still indefensible. Moreover, the hacker may use social engineering (communication and cheat skills) to pass-through the firewall. The attack just costs several telephone-call fees but brings huge damage to an enterprise. Employees usually do not care about business about information security. They believe that such the issues should be handled by department of information, and this concept will cause unexpected damage. Consequently, the company (TS) (research objective of this study) helps employees to construct the essential of information security by importing the training courses of social engineering based on internal e-mail system, related practice and propagation are included. Therefore, this study comprises two topic listed below: 1.After performing the practice of social engineering, does the company (TS) successfully improve the employees’ cognition of such issues (ex. clicking e-mails)? 2.After importing training and propagation of information security, do employees actually understand the importance of information security? If yes, that can keep the enterprise away from the damage. Finally, we can verify and confirm whether the employees have learned about the importance of social engineering and information security or not by analyzing of questionnaires.

參考文獻


[11] Lloyd Guyot,“Essential Information Security For Corporate Employees”,SANS GIAC GSEC Practical Version 1.4b Option 1 , June , 2003。
[12] McDaniel, George, ed., IBM Dictionary of Computing, McGraw-Hill, New York,1994。
[16] Shaw, E., Post J. & Ruby, K., (2000), Managing the Threat From Within, Information Security, July, pp.62-72。
[20] 邱瑩青著,2008,載自I Security。
[24] 謝惠玲,2007,資訊安全機制規劃及建置之現況調查與分析,靜宜大學,資訊管理學系碩士論文。

被引用紀錄


王思惠(2016)。組織社交工程行為之研究-以委託C公司為例〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2016.00655
林維國(2012)。從惡意電子郵件攻擊樣本探討未來我國政府機關社交工程演練之方向–以A機關為例〔碩士論文,國立中央大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0031-1903201314434103

延伸閱讀