Sabaragamuwa University of Sri Lanka

Comprehensive Study on User-Centric Approaches to Preventing Social Engineering Attacks

Show simple item record

dc.contributor.author Pathirana, E.P.K.H.
dc.contributor.author Abeysinghe, D.V.D.S.
dc.date.accessioned 2025-12-12T07:16:12Z
dc.date.available 2025-12-12T07:16:12Z
dc.date.issued 2025-02-19
dc.identifier.citation Abstracts of the ComURS2025 Computing Undergraduate Research Symposium 2025, Faculty of Computing, Sabaragamuwa University of Sri Lanka. en_US
dc.identifier.isbn 978-624-5727-57-5
dc.identifier.uri http://repo.lib.sab.ac.lk:8080/xmlui/handle/susl/4949
dc.description.abstract Social engineering attacks are a critical threat to organizational security because they exploit human psychological vulnerabilities. Most users are generally unprepared to detect and mitigate the impact of such attacks despite the availability of technical safeguards. It highlights a gap in current practice and prevention strategies. This study employs a mixed-methods approach, which combines a literature review with primary data collected through questionnaires and interviews conducted with 75 participants from diverse professional backgrounds in Sri Lanka, selected through purposive sampling to ensure a representative sample. The term mixed-methods indicates both analysis of open-ended and closed-ended questions through qualitative and quantitative methods. The results showed that 78.7% of respondents were aware of the existing social engineering attacks, but most were less confident in identifying such an attack, with only 25.3% very confident in identifying them. Behavioral factors such as cognitive biases (trust, fear, and urgency) and overconfidence especially gained recognition as one of the key critical factors influencing vulnerability. Users make substandard choices even with knowledge of potential dangers because biases cloud their judgment. On the other hand, real-time simulations and personalized interactive training tools have been identified as more effective for improving user readiness than traditional training methods. These findings have identified the need for user-centered cybersecurity education that integrates psychological and technological measures as a means of better positioning users against the threats of social engineering attacks. Further research should focus on developing such tools and the expansion of adaptive training programs for a wide range of user groups. en_US
dc.language.iso en en_US
dc.publisher Faculty of Computing, Sabaragamuwa University of Sri Lanka en_US
dc.subject Adaptive Cybersecurity Education en_US
dc.subject Interactive Security Tools en_US
dc.subject Social Engineering Attacks en_US
dc.subject User-Centric Security en_US
dc.title Comprehensive Study on User-Centric Approaches to Preventing Social Engineering Attacks en_US
dc.type Article en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account