{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T16:46:59Z","timestamp":1783788419475,"version":"3.55.0"},"publisher-location":"Cham","reference-count":21,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319170152","type":"print"},{"value":"9783319170169","type":"electronic"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-17016-9_14","type":"book-chapter","created":{"date-parts":[[2015,3,29]],"date-time":"2015-03-29T00:52:41Z","timestamp":1427590361000},"page":"216-232","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["Analysis of Social Engineering Threats with Attack Graphs"],"prefix":"10.1007","author":[{"given":"Kristian","family":"Beckers","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Leanid","family":"Krautsevich","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Artsiom","family":"Yautsiukhin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2015,3,28]]},"reference":[{"issue":"5","key":"14_CR1","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1201\/1086.1065898X\/46353.15.4.20060901\/95427.3","volume":"15","author":"TR Peltier","year":"2006","unstructured":"Peltier, T.R.: Social engineering: concepts and solutions. Inf. Syst. Secur. 15(5), 13\u201321 (2006)","journal-title":"Inf. Syst. Secur."},{"key":"14_CR2","doi-asserted-by":"crossref","unstructured":"Algarni, A., Xu, Y., Chan, T., Tian, Y.C.: Social engineering in social networking sites: Affect-based model. In: Proceedings of the 8th International Conference on Internet Technology and Secured Transactions, pp. 508\u2013515. IEEE (2013)","DOI":"10.1109\/ICITST.2013.6750253"},{"key":"14_CR3","doi-asserted-by":"crossref","unstructured":"Dimkov, T., van Cleeff, A., Pieters, W., Hartel, P.: Two methodologies for physical penetration testing using social engineering. In: Proceedings of the 26th Annual Computer Security Applications Conference, pp. 399\u2013408. ACM (2010)","DOI":"10.1145\/1920261.1920319"},{"key":"14_CR4","doi-asserted-by":"crossref","unstructured":"Laribee, L., Barnes, D., Rowe, N., Martell, C.: Analysis and defensive tools for social-engineering attacks on computer systems. In: Proceedings of the Information Assurance Workshop, pp. 388\u2013389. IEEE (2006)","DOI":"10.1109\/IAW.2006.1652125"},{"key":"14_CR5","volume-title":"The Art of Deception","author":"KD Mitnick","year":"2009","unstructured":"Mitnick, K.D., Simon, W.L.: The Art of Deception. Wiley, Indianapolis, Indiana (2009)"},{"key":"14_CR6","doi-asserted-by":"crossref","unstructured":"Krombholz, K., Hobel, H., Huber, M., Weippl, E.: Social engineering attacks on the knowledge worker. In: Proceedings of the 6th International Conference on Security of Information and Networks, pp. 28\u201335. ACM (2013)","DOI":"10.1145\/2523514.2523596"},{"issue":"2","key":"14_CR7","first-page":"80","volume":"26","author":"D Kvedar","year":"2010","unstructured":"Kvedar, D., Nettis, M., Fulton, S.P.: The use of formal social engineering techniques to identify weaknesses during a computer vulnerability competition. J. Comput. Sci. Coll. 26(2), 80\u201387 (2010)","journal-title":"J. Comput. Sci. Coll."},{"key":"14_CR8","unstructured":"Beckers, K., Heisel, M., Krautsevich, L., Maritnelli, F., Yautsiukhin, A.: Considering attacker motivation in attack graphs analysis in a smart grid scenario. In: Proceedings of the Second Open EIT ICT Labs Workshop on Smart Grid Security, Springer (2014, To appear)"},{"key":"14_CR9","doi-asserted-by":"crossref","unstructured":"Ahmadi, N., Jazayeri, M., Lelli, F., Nesic, S.: A survey of social software engineering. In: Workshop Proceedings of the 23rd IEEE\/ACM International Conference on Automated Software Engineering, pp. 1\u201312. IEEE (2008)","DOI":"10.1109\/ASEW.2008.4686304"},{"key":"14_CR10","doi-asserted-by":"crossref","unstructured":"Mills, D.: Analysis of a social engineering threat to information security exacerbated by vulnerabilities exposed through the inherent nature of social networking websites. In: Proceedings of the Information Security Curriculum Development Conference, pp. 139\u2013141. ACM (2009)","DOI":"10.1145\/1940976.1941003"},{"issue":"2","key":"14_CR11","first-page":"45","volume":"1","author":"A Chitrey","year":"2012","unstructured":"Chitrey, A., Singh, D., Singh, V.: A comprehensive study of social engineering based attacks in india to develop a conceptual model. Int. J. Inf. Netw. Secur. 1(2), 45\u201353 (2012)","journal-title":"Int. J. Inf. Netw. Secur."},{"key":"14_CR12","unstructured":"Winkler, I.S., Dealy, B.: Information security technology?...don\u2019t rely on it: a case study in social engineering. In: Proceedings of the 5th Conference on USENIX UNIX Security Symposium, p. 1\u20131. USENIX Association (1995)"},{"key":"14_CR13","unstructured":"Gonzalez, J.J., Seasick, A.: A framework for human factors in information security. In: Proceedings of WSEAS International Conference on Information Security (2002)"},{"key":"14_CR14","doi-asserted-by":"crossref","unstructured":"Twitchell, D.P.: Social engineering in information assurance curricula. In: Proceedings of the 3rd Annual Conference on Information Security Curriculum Development, pp. 191\u2013193. ACM (2006)","DOI":"10.1145\/1231047.1231062"},{"key":"14_CR15","unstructured":"International Organization for Standardization (ISO), International Electrotechnical Commission (IEC): Information technology - Security techniques - Information security management systems - Requirements. ISO\/IEC 27001 (2013)"},{"key":"14_CR16","unstructured":"BSI: Grundschutzhandbuch IT. Bundesamt f\u00fcr Sicherheit in der Informationstechnik (BSI) (2007). http:\/\/www.bsi.bund.de\/gshb\/index.htm"},{"key":"14_CR17","unstructured":"Jha, S., Sheyner, O., Wing, J.: Two formal analyses of attack graphs. In: Proceedings of the Computer Society Security Foundations Workshop. IEEE (2002)"},{"key":"14_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1007\/978-3-642-37119-6_23","volume-title":"Foundations and Practice of Security","author":"L Krautsevich","year":"2013","unstructured":"Krautsevich, L., Martinelli, F., Yautsiukhin, A.: Towards modelling adaptive attacker\u2019s behaviour. In: Garcia-Alfaro, J., Cuppens, F., Cuppens-Boulahia, N., Miri, A., Tawbi, N. (eds.) Foundations and Practice of Security. LNCS, vol. 7743, pp. 357\u2013364. Springer, Heidelberg (2013)"},{"key":"14_CR19","doi-asserted-by":"crossref","unstructured":"LeMay, E., Ford, M.D., Keefe, K., Sanders, W.H., Muehrcke, C.: Model-based security metrics using adversary view security evaluation (advise). In: Proceedings of the 8th International Conference on Quantitative Evaluation of SysTems, pp. 191\u2013200. IEEE (2011)","DOI":"10.1109\/QEST.2011.34"},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Noel, S., Jajodia, S.: Managing attack graph complexity through visual hierarchical aggregation. In: Proceedings of the Workshop on Visualization and Data Mining for Computer Security. ACM (2004)","DOI":"10.1145\/1029208.1029225"},{"key":"14_CR21","unstructured":"Sheyner, O., Haines, J., Jha, S., Lippmann, R., Wing, J.M.: Automated generation and analysis of attack graphs. In: Proceedings of the 2002 IEEE Symposium on Security and Privacy. IEEE (2002)"}],"container-title":["Lecture Notes in Computer Science","Data Privacy Management, Autonomous Spontaneous Security, and Security Assurance"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-17016-9_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,21]],"date-time":"2025-05-21T18:12:54Z","timestamp":1747851174000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-17016-9_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319170152","9783319170169"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-17016-9_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015]]},"assertion":[{"value":"28 March 2015","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}