MARATTO

article · IEEE Access

A Comprehensive Taxonomy of Social Engineering Attacks and Defense Mechanisms: Toward Effective Mitigation Strategies

202427 citationsOpen access

In plain language

Social engineering attacks pose an escalating challenge to organisations relying on technology to protect sensitive data. These threats exploit human behaviour rather than technical flaws, making detection and prevention difficult. Despite existing research on attacks and defences, a comprehensive and layered classification of both threats and countermeasures has been lacking. Following a thorough survey of literature and current classification models, a structured framework has been established. This framework introduces a three-level taxonomy of social engineering attacks, categorising them across environments, approaches, and mediums. Alongside this threat classification, the work provides a taxonomy of countermeasures that integrates both technical and non-technical defence solutions. Together, these taxonomies offer organisations a structured basis for detecting, preventing, and responding to social engineering incidents while supporting ongoing research in cyber security defence.

Key takeaways

  • Social engineering attacks manipulate human behaviour rather than technical vulnerabilities to access sensitive data.
  • Prior literature lacked a comprehensive and layered classification of social engineering threats and defenses.
  • A structured attack taxonomy categorises social engineering incidents across three levels: environment, approaches, and mediums.
  • A complementary countermeasure taxonomy encompasses both technical and non-technical mitigation mechanisms.

Why it matters

Protecting sensitive data requires addressing human vulnerabilities alongside technological safeguards. Because social engineering manipulates people, organisations need systematic ways to identify varied attack paths and deploy balanced defences. Providing structured classifications of both threats and countermeasures helps security teams identify gaps in their protective measures, design better training programmes, and integrate technical controls to reduce the risk of successful deception.

Commercialisation angle

This framework provides an early-stage conceptual foundation for cyber security practitioners and enterprise risk teams seeking to build incident detection, prevention, and response policies. Organisations can use the layered attack and defence taxonomies to audit vulnerabilities and structure combined technical and non-technical security strategies. As a literature-derived taxonomy, it is an early-stage advisory tool rather than a deployable commercial product, requiring organisations to translate the classifications into operational security practices.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

Social engineering (SE) attacks are a growing concern for organizations that rely on technology to protect sensitive data. Identifying and preventing these attacks can be challenging, as they frequently rely on manipulating human behavior rather than exploiting technical vulnerabilities. Although various studies have explored SE attacks and their defense mechanisms, there remains a gap in the literature concerning the holistic and layered classification of these threats and countermeasures. To address this, we conducted a comprehensive literature survey to understand existing taxonomies and subsequently identified areas that required a more structured and exhaustive categorization. Based on the survey results, we propose a comprehensive taxonomy of SE attacks, classifying them based on three levels: environment, approaches, and mediums. Additionally, we present a taxonomy of social engineering countermeasures, encompassing both technical and non-technical solutions. The proposed taxonomies serve as a foundation for future research and offer organizations a valuable framework for developing effective strategies to detect, prevent, and respond to social engineering incidents.

Research topics

  • Information and Cyber Security
  • Advanced Malware Detection Techniques
  • User Authentication and Security Systems

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/access.2024.3403197

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.