CYSE 201S

Career Paper

Introduction

In this paper, students are asked to choose a cybersecurity career that implements and uses the social science principles taught in class for operation. This career paper discusses the role of a Social Engineer Researcher. Someone within this career has the job of studying the techniques and methods used by cyber criminals to create cyber threats by manipulating humans to engage in a certain behavior beneficial to the attacker. A social engineer researcher must be knowledgeable of social sciences, which “refers to a group of scientific disciplines that study social phenomenon” (Introduction to the Social Sciences PowerPoint). The information beneficial to their research is pulled from social sciences such as psychology, sociology, and communications. These social sciences are applied to understand the social influences of attackers and how their methods work for their malicious intentions. The understandings drawn are then applied to develop and implement countermeasures. The goal of a Social Engineer Researcher would be to counter act social engineering which, according to NIST: An Introduction to Information Security, is “a technique that relies heavily on human interaction to influence an individual to violate security protocol and encourages the individual to divulge confidential information.” The knowledge of how to use social engineering to negatively affect people creates a group of those in power and malicious intent to use it, a group without the knowledge that may become victims, as well as a group with the knowledge who will use it to counteract those with malicious intent.

Research

According to Social Science Research, the goal of research is to “discover laws and (form) theories that can explain natural or social phenomena (to) build scientific knowledge.” This research is done on theoretical and empirical levels. At the theoretical level, researchers develop concepts about a phenomenon they are observing to develop a theory about them. The next level of research, empirical, is the testing of these developed theories to see how well they reflect the reality of the phenomena being observed. One example of theoretical research in Social Science Research is the development of models and frameworks. These theoretical models are created to explain the intentions and decision-making processes behind a cyber attacker/criminals’ behavior. The development of theoretical frameworks could hold the purpose of understanding the interactions between security awareness, the culture of an organization, and cybersecurity practices of the organization’s employees. An example of the empirical level of research in this field can be interviews and focus groups. These interviews and focus groups can be conducted with others within the cybersecurity realm with different job expectations such as incident responders and other cybersecurity professionals or maybe even cyber attackers themselves. The purpose of these would be to gain knowledge about related experiences, perspectives and more.

Concluding

Social engineering is a technique of criminal/deviant behavior that affects citizens daily. There are many different types of this behavior, such as phishing, shoulder surfing, social media exploitation and more. With the effects social engineering can have on people such as identity theft, reputation damage, and financial loss, we are fortunate to have professionals within social engineering research. Their positive impact on the knowledge of and how to, we can fight against this behavior. The focus has increased awareness and allowed those who engage in internet usage to exhibit safer behaviors.

Sources

Yalpi, Diwakar. “Introduction to eh Social Sciences.” 2024. Old Dominion University. Canvas.
https://canvas.odu.edu/courses/153113/files/31402237?module_item_id=5838102
Bhattacherjee, Anol, “Social Science Research: Principles, Methods, and Practices” (2012).
Textbooks Collection. 3. http://scholarcommons.usf.edu/oa_textbooks/3
Nieles, M., Dempsey, K., & Pillitteri, V. Y. (2017). An Introduction to Information Security.
NIST Special Publication, 800-12(Revision 1).
https://doi.org/https://doi.org/10.60828/NIST.SP.800-12rl
FIDO Alliance. (2019). W3C and FIDO Alliance Finalize Web Standard for Secure,
Passwordless Logins. https://doi.org/https:/drive.google.com/file/d/1yl6A41T7YrFLF_ItTGY6D9JxeuLWIaCg/view