arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

利用调查与社交媒体数据评估社会-网络脆弱性

Assessing Socio-Cyber Vulnerability Using Survey and Social Media Data

Shutonu Mitra, Qi Zhang, Tomas Neguyen, Hossein Salemi, Fengxiu Zhang, Michin Hong, Chang-Tien Lu, Hemant Purohit, Jin-Hee Cho

arXiv 2608.26388首次发表:更新:

AI 中文总结

该研究针对现有网络脆弱性评估工具的不足,提出社会-网络脆弱性指数(SCVI),结合调查与社交媒体数据验证其有效性,可更好区分受害者与非受害者,助力高风险人群识别及新型AI诈骗干预优先级确定。

AI 中文摘要

社交媒体参与度的快速增长增加了人们遭受社会工程网络威胁(如钓鱼、情感诈骗、技术支持诈骗)的风险,但现有评估工具仍存在碎片化问题:通用漏洞评分系统(CVSS)主要关注技术层面,很大程度上忽略了人的易感性;社会脆弱性指数(SVI)以社区为导向,缺乏针对网络的建模。为解决这一差距,我们提出社会-网络脆弱性指数(SCVI),这是一种可解释、考虑不确定性的指标,包含两个部分:(i)个人脆弱性指数(IVI),涵盖意识、行为、心理因素及过往受害经历;(ii)攻击严重程度指数(ASI),涵盖攻击频率、后果及复杂程度。我们通过异质模态验证SCVI:全国范围的调查(iPoll;4596名美国成年人)和社交媒体叙事(2016-2024年Reddit平台r/scams板块的450篇帖子),证明其可从结构化问卷和文本的因果推理(CI)驱动特征提取两种方式计算。敏感性分析和10000次迭代的蒙特卡洛模拟显示,在合理权重变化下排名稳定,并揭示了依赖情境的驱动因素。SCVI捕捉到独特的社会-技术信号(与CVSS的斯皮尔曼相关系数ρ=0.33;与SVI的ρ≈-0.01),并呈现人口统计和区域差异。SCVI在区分受害者与非受害者群体方面的能力远强于CVSS和SVI,支持识别高风险人群并优先应对新型AI驱动的诈骗。

英文摘要

The rapid growth of social media participation has increased exposure to socially engineered cyber threats (e.g., phishing, romance fraud, and tech-support scams), yet prevailing assessment tools remain fragmented: the Common Vulnerability Scoring System (CVSS) is primarily technical and largely omits human susceptibility, while the Social Vulnerability Index (SVI) is community-oriented and lacks cyber-specific modeling. To address this gap, we propose the Social Cyber Vulnerability Index (SCVI), an interpretable, uncertainty-aware metric combining two components: (i) an Individual Vulnerability Index (IVI), capturing awareness, behavior, psychological factors, and prior victimization, and (ii) an Attack Severity Index (ASI), capturing attack frequency, consequences, and sophistication. We validate SCVI across heterogeneous modalities: a nationally scoped survey (iPoll; 4,596 U.S. adults) and social-media narratives (450 Reddit r/scams reports, 2016-2024), demonstrating computation from both structured questionnaires and CI-driven feature extraction from text. Sensitivity analysis and 10,000-iteration Monte Carlo simulations show stable rankings under plausible weight variability and reveal context-dependent drivers. SCVI captures distinct socio-technical signals (Spearman correlation with CVSS $ρ= 0.33$; with SVI $ρ\approx -0.01$) and surfaces demographic and regional disparities. SCVI also provides substantially stronger separation between victim and non-victim groups than CVSS and SVI, supporting identification of high-risk populations and prioritization of interventions against emerging AI-enabled scams.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑