The Weakest Link: How to Diagnose, Detect, and Defend Users from Phishing
暫譯: 最弱的環節:如何診斷、檢測及防範用戶遭受釣魚攻擊

Vishwanath, Arun

  • 出版商: Summit Valley Press
  • 出版日期: 2022-08-16
  • 售價: $1,280
  • 貴賓價: 9.5$1,216
  • 語言: 英文
  • 頁數: 272
  • 裝訂: Hardcover - also called cloth, retail trade, or trade
  • ISBN: 0262047497
  • ISBN-13: 9780262047494
  • 相關分類: 資訊安全Computer-networks駭客 Hack
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

An expert in cybersecurity lays out an evidence-based approach for assessing user cyber risk and achieving organizational cyber resilience.

Phishing is the single biggest threat to cybersecurity, persuading even experienced users to click on hyperlinks and attachments in emails that conceal malware. Phishing has been responsible for every major cyber breach, from the infamous Sony hack in 2014 to the 2017 hack of the Democratic National Committee and the more recent Colonial Pipleline breach. The cybersecurity community's response has been intensive user training (often followed by user blaming), which has proven completely ineffective: the hacks keep coming. In The Weakest Link, cybersecurity expert Arun Vishwanath offers a new, evidence-based approach for detecting and defending against phishing--an approach that doesn't rely on continual training and retraining but provides a way to diagnose user vulnerability.

Vishwanath explains how organizations can build a culture of cyber safety. He presents a Cyber Risk Survey (CRS) to help managers understand which users are at risk and why. Underlying CRS is the Suspicion, Cognition, Automaticity Model (SCAM), which specifies the user thoughts and actions that lead to either deception by or detection of phishing come-ons. He describes in detail how to implement these frameworks, discussing relevant insights from cognitive and behavioral science, and then presents case studies of organizations that have successfully deployed the CRS to achieve cyber resilience. These range from a growing wealth management company with twenty regional offices to a small Pennsylvania nonprofit with forty-five employees.

The Weakest Link will revolutionize the way managers approach cyber security, replacing the current one-size-fits-all methodology with a strategy that targets specific user vulnerabilities.

商品描述(中文翻譯)

一位網路安全專家提出了一種基於證據的方法,用於評估用戶的網路風險並實現組織的網路韌性。

網路釣魚是網路安全最大的威脅,甚至能說服經驗豐富的用戶點擊電子郵件中的超連結和附件,這些連結和附件隱藏著惡意軟體。網路釣魚導致了每一個重大的網路違規事件,從2014年臭名昭著的索尼駭客事件,到2017年民主全國委員會的駭客事件,以及最近的Colonial Pipeline違規事件。網路安全社群的回應是進行密集的用戶訓練(通常隨之而來的是對用戶的指責),但這被證明是完全無效的:駭客攻擊仍然不斷發生。在《最弱的一環》中,網路安全專家Arun Vishwanath提供了一種新的基於證據的方法,用於檢測和防禦網路釣魚——這種方法不依賴於持續的訓練和再訓練,而是提供了一種診斷用戶脆弱性的方法。

Vishwanath解釋了組織如何建立網路安全文化。他提出了一個網路風險調查(Cyber Risk Survey, CRS),幫助管理者了解哪些用戶面臨風險以及原因。CRS的基礎是懷疑、認知、自動化模型(Suspicion, Cognition, Automaticity Model, SCAM),該模型具體說明了導致用戶被網路釣魚欺騙或檢測到網路釣魚的思維和行為。他詳細描述了如何實施這些框架,討論了來自認知和行為科學的相關見解,然後展示了成功部署CRS以實現網路韌性的組織案例研究,這些組織包括一家擁有二十個地區辦公室的快速成長的財富管理公司,以及一家擁有四十五名員工的小型賓夕法尼亞非營利組織。

《最弱的一環》將徹底改變管理者對網路安全的看法,取代當前的統一方法,採用針對特定用戶脆弱性的策略。

作者簡介

Arun Vishwanath, a leading expert in cybersecurity, has held faculty positions at the University at Buffalo, Indiana University, and the Berkman Klein Center for Internet & Society at Harvard University. He has written on human cyber vulnerability and related topics for CNN, the Washington Post, and other major media.

作者簡介(中文翻譯)

阿倫·維斯瓦納斯(Arun Vishwanath)是網路安全領域的領先專家,曾在布法羅大學(University at Buffalo)、印第安納大學(Indiana University)以及哈佛大學的伯克曼·克萊因網路與社會中心(Berkman Klein Center for Internet & Society)擔任教職。他曾為CNN、《華盛頓郵報》(Washington Post)及其他主要媒體撰寫有關人類網路脆弱性及相關主題的文章。