Awareness of social engineering among IIUM students

Although most organizations around the world currently pay more attention to securing information systems by means of sophisticated security tools, their information systems still remain breachable. The interpretation of this reality is that the hackers resort to the use of social engineering instea...

Full description

Bibliographic Details
Main Authors: Adam, Mutasim Elsadig, Yousif, Omer, Amodi, Yusra, Ibrahim, Jamaludin
Format: Article
Language:English
Published: WCSIT 2011
Subjects:
Online Access:http://irep.iium.edu.my/38043/
http://irep.iium.edu.my/38043/
http://irep.iium.edu.my/38043/1/Awareness_of_Social_Engineering_Among_IIUM_Students.pdf
Description
Summary:Although most organizations around the world currently pay more attention to securing information systems by means of sophisticated security tools, their information systems still remain breachable. The interpretation of this reality is that the hackers resort to the use of social engineering instead of using their technical skills to acquire information. The concept of social engineering is essentially to manipulate the users of a system, that are considered to be the weakest links on the chain, in order to get said information. The objective of this study is to prove that users of information systems are considered to be the real threat themselves. In this study, we assume that the lack of awareness of social engineering among users makes information systems susceptible to numerous kinds of breaches. In addition to that, the study aims to examine whether IT students possess more awareness of social engineering than students from other faculties. To address these problems, the data was collected from 245 students of the International Islamic University Malaysia (IIUM), via an online survey and questionnaire. Moreover, a phishing phone experiment conducted among a small number of students. The exhibited results showing that a total of 114 students were exposed to social engineering attacks during the last six months, and almost 38% of these attacks through E-mail.