Experience in Social Engineering by eCommerce Platforms in Kenya
Lawrence Mwagoti Mwasambo, Christopher A. Moturi
Current Journal of Applied Science and Technology · pp. 1–12 · Published 3 Dec 2016
10.9734/BJAST/2016/30312Abstract
eCommerce systems have been targeted by cyber criminals as they receive and use the money, rely on technology, outsourced services and use of payment technologies like mobile money and online banking channels to carry out their day-to-day transactions. This study sought to investigate social engineering and its mitigation in eCommerce platforms in Kenya. An existing Social Engineering Defensive Framework was adopted and its dimensions were used to create questionnaires and interview guides. The study used 30 out of the 34 pure-play eCommerce firms operating in Nairobi, Kenya. The results indicate that phishing/spear phishing as the leading threat followed by baiting/Trojan Horse, social media/fraudulent websites, search engine poisoning among others. Mitigation measures indicate organizations need to regularly check their website listing in hacking sites (such as pastebin.com and ghostbin.com) and periodically document and update new policies regarding social engineering and information security. This paper proposes social engineering mitigation best practices, emphasizing the need for organizations using the derived best practices and incorporating security culture.
Cited by 0
No indexed citations yet.
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
0
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.