透過您的圖書館登入
IP:18.119.131.178
  • 學位論文

資訊安全事件與資訊安全認知關係之研究-以社交工程為例

The Study of the Relation of Information Security Events and Information Security Awareness-A Case of Social Engineering

指導教授 : 劉士豪
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


隨著資訊科技的運用與資訊安全風險的不斷發生,資訊安全認知與資安事件防範成為各企業、組織高度受重視的議題,依據文獻探討顯示,社交工程郵件的問題愈來愈嚴重,但針對社交工程郵件的相關研究則不多,社交工程郵件防不慎防,許多被社交工程郵件攻擊的受害者自己都無法察覺,甚至連具有資訊安全背景的人也曾經遭受社交工程郵件攻擊成功。因此本研究的目的,主要在探討個人具有資訊安全認知仍然會遭受社交工程郵件攻擊成功的原因、哪些類型的資訊安全認知對防止社交工程郵件攻擊最有效及哪些因素可降低社交工程郵件攻擊成功。 本研究選定我國行政院A機關內部人員216位及國內B大學資管所碩專班學生33位為社交工程電子郵件測試對象,以研究者本身電子郵件帳號及虛擬帳號測試A機關人員及B大學資管所碩專班學生,再以抽樣方式隨機選取A機關人員與B大學資管所碩專班學生實施資訊安全認知評量問卷,並對A機關人員與B大學資管所碩專班資訊安全認知評量問卷加權分數較低(評量加權分數後1/3)與加權分數較高(評量加權分數前1/3)人員實施面對面的訪談,最後就所蒐集之相關數據與訪談資料提出敘述性分析與探索性研究。 本研究發現:一、大部分資訊安全認知較高,而仍然會點選社交工程測試郵件的受訪者,是因為資安警覺不足。二、大部分的受訪者認為「社交工程」、「資安事件與防範」、「資安基本觀念」方面的資訊安全認知,對防止社交工程郵件攻擊最有效。三、大部分的受訪者認為「資安警覺」、「良好使用習慣」、「資安訓練」是降低社交工程攻擊成功的重要因素。四、經過資訊安全訓練提高的資訊安全認知,對防止社交工程郵件攻擊成功機率有正向關係。五、資訊安全認知高低對判斷電子郵件是否安全的能力有正向關係。六、資訊安全認知高低對社交工程電子郵件瞭解程度有正向關係。七、資訊安全認知高低與會不會瀏覽來路不明電子郵件或開啟附件檔案無顯著關係,而是在於「資安警覺」與「良好使用習慣」。八、大部分點選社交工程測試郵件的受訪者表示,因為認識寄件者才會點選郵件,顯見一般人對認識的親友,比較不防範,而這也是資訊安全管理部門與管理人員必須注意和教育的重點。

並列摘要


With the wider applications of information technology, and information security breaches continuing to occur on a regular basis, information security awareness and the active prevention of information security incidents have received increased attention in most enterprises and organizations. Based on the literature research, in recent years, social engineering e-mails have increasingly become an issue; however, the related research on the impact of social engineering e-mails has not increased accordingly. Existing computer security systems seem unable to guard against social-engineering e-mails; many e-mail messages contain social engineering attacks, and even those who have previously been victims have failed to detect a future attack, even if they have an information security background.The purpose of this study is to find out the reasons of the successful attacks on individuals with cognitive social engineering related backgrounds, the types of information security awareness which are most effective in preventing social- engineering e-mail attacks, and the factors which can reduce the number of successful attacks. In this study, 216 internal staffs of Executive Yuan A department and 33 Information Management postgraduate students of B University were selected as the sample group. The researcher first created a number of virtual e-mail accounts. He then sent requests to each of the sample group, both from his own account and the virtual accounts, inviting the group to complete an assessment questionnaire of information security awareness. The results were then assessed and the respondents in the top 1/3rd and lower 1/3rd (using a weighted score assessment technique) of the sample group were interviewed face to face. The information from the interviews increased the understanding of the attitudes to information security of the sample group; this was combined with the results of the questionnaire assessments to provide the exploratory study and narrative analysis, and the following conclusions: 一、 Most of the member with a high security awareness click on e-mail respondents in the social engineering tests because of lack of awareness of information security. 二、 The majority of respondents believed that the aspects of information awareness such as "social engineering", "information security events and prevention", and "Basic concepts of information security" are the most effective means of preventing social engineering e-mail attacks. 三、 The majority of respondents also believed that "information security awareness", "good habits", and "information security training" are the major factors to reduce the success of social engineering e-mail attack. 四、 Increased security awareness has a positive impact on the prevention of successful attack through social engineering e-mails. 五、 Information security awareness has a strong impact on the level of ability to judge the safety of e-mail. 六、 The extent of understanding of social engineering e-mail has a positive relationship with the level of information security awareness. 七、 There is no significant relation between information security awareness level and browsing or opening unsolicited e-mail attachment, however, the factors, "information security awareness" and "good habits", are the important issues for the e-mail attachment. 八、 Most of the respondents click the social engineering test message based on the familiar to the sender. This demonstrates that most people have less awareness of the risk of attack if e-mails come from, or appear to come from, relatives and friends. These conclusions are what information security management department and the managers should be addressed and, then, pay attention to reduce the success of attack by social engineering e-mail.

參考文獻


6. 洪國興、趙榮耀 (2003)。資訊安全管理理論之探討。資管評論,12,17-47。
3. 行政院國家資通安全會報(2005)。建立我國通資訊基礎建設安全機制計畫。
7. 侯皇熙(2004)。植基於BS7799 探討政府部門的資訊安全管理—以海關資訊部門為例。國立成功大學工程科學系碩士論文,未出版,台南市。
1. Debi Ashenden(2008). Information security management:A human challenge cha. Information Security Technical Report,13(4),195-201.
2. Eirik,A. & Jan,H.(2009). The information security digital divide between information security managers and users. Computers & Security,28(6),476-490.

延伸閱讀