In stock

IET Digital Library
This title is available electronically
in the IET Digital Library
Phishing for Answers: Risk identification and mitigation strategies

Phishing for Answers

Risk identification and mitigation strategies  

by Terry R. Merz, Lawrence E. Shaw

In the context of information security, social engineering is the manipulation of people into performing actions or divulging information for the purpose of gathering, defrauding, or gaining unauthorized system access. While some of the most common forms of social engineering involve telephone or social networks where criminals pose as employees of targeted organizations, phishing accounts for 96% of all successful cyber-attacks. Governments and private organizations have responded through various means such as training employees, executing internal vulnerability assessments, and ad campaigns. Despite all these efforts, phishing continues to provide the primary cyber-attack vector for nefarious entities.

Phishing attacks continue to escalate, with over 300,000 reported incidents in the US alone last year. This book provides an in-depth look at the anatomy of modern phishing threats and how they are evolving with AI technologies. Readers will learn about the latest social engineering tactics used by cybercriminals, including deepfakes for audio/video manipulation and AI-generated spear-phishing campaigns, and discover emerging defensive tools that leverage machine learning to detect anomalies and protect against hyper-personalized phishing attempts. With phishing losses averaging millions per breach, this book equips readers with the knowledge to identify risks and implement robust countermeasures as these attacks become increasingly sophisticated and difficult to spot.

Written by two experts in the field, bringing together their wide experience in academic research, security engineering, incident response and cyber forensics, this book offers valuable insights for researchers, engineers, cybersecurity professionals and organizational leaders working in cyber security, information technology, network and infrastructure security, endpoint protection, data governance, risk and compliance, digital forensics, incident response, operational technology and industrial control systems.

About the Author

Terry R. Merz is a senior research scientist at the Pacific Northwest National Laboratory (PNNL), USA and an adjunct professor at the State University of New York (SUNY) College of Emergency Management, Homeland Security and Cybersecurity (CEHC). Her work in the field of cybersecurity spans two decades and involves security engineering, testing, and incident response. Since 2014, she has focused exclusively on research and is researching self-healing, situationally aware architectures for power systems, long-term exploratory research on data collected from commercial industrial control systems, the development of theoretical models for the testing and evaluation of binary analysis tools, behavioral information security, and advanced persistent threats. Her current area of research involves the integration of AI in asymmetric cyber operations and analytics. She holds a Doctor of Computer Science from Colorado Technical University, USA.

Lawrence E. Shaw is the former lead of the CSSP Cyber Forensic Team at the Missile Defense Agency (MDA), USA. His cybersecurity experience covers the areas of incident response, forensics, and malware analysis and cybersecurity testing (Blue/Red Team testing). In his role as a senior incident responder with Microsoft Cyber Defense Operations Center, he focused on cyber incidents related to the Microsoft enterprise. In addition to incident response, he has spent several years in law enforcement-related cyber forensics with the Florida Department of Law Enforcement. He holds a master's degree in computer science, with a concentration in cyber security from the Western Governors University, Utah, USA.



Item Subjects:
Security

Publication Year: 2024

Pages: 342

ISBN-13: 978-1-83953-667-0

Format: HBK

Available Formats

Recommendations For You

Purchased With