Social engineering is the art of convincing users to infiltrate information systems. Instead of using technical attacks on systems, social engineers target people who have access to specific information and encourage them to disclose sensitive information, or even carry out malicious attacks by infiltrating and persuading people. The purpose of this study is to provide a model for identifying social engineering attacks and to provide solutions to increase the security of military organizations against social engineering attacks, especially ransomware in the form of a model for identifying attacks based on social engineering.In this study, information and data were collected in two ways: library and field. The instrument of the present study is an interview with experts and a questionnaire containing a number of questions about the variables measured from the study population, the validity and reliability of which have been calculated, which is desirable. The statistical population of this study includes all experts and employees of the military organization studied in Tehran. The number of statistical samples of the research is calculated based on Morgan's innovative table and the method of random sampling is simple class. Data analysis was performed in two descriptive and inferential sections. At the end, the pattern of identifying attacks based on social engineering in military organizations, including 7 dimensions and 20 components, was developed and a suitable tool for standardization and evaluation of the organization to prevent and counter attacks. Social engineering presentation
basiri M, fathabadi H. Provide a model for identifying attacks based on social engineering in military organizations. C4I Journal 2023; 6 (4) :63-77 URL: http://ic4i-journal.ir/article-1-356-en.html