ФІШИНГ НОВОГО ПОКОЛІННЯ: ЕВОЛЮЦІЯ СОЦІАЛЬНОЇ ІНЖЕНЕРІЇ В УМОВАХ ЦИФРОВОЇ ТРАНСФОРМАЦІЇ

Автор(и)

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1222

Ключові слова:

фішинг, соціальна інженерія, штучний інтелект, кібербезпека, математичне моделювання

Анотація

У статті здійснено аналіз сучасних тенденцій розвитку фішингу, включаючи використання технологій штучного інтелекту для автоматизації створення фішингового контенту, підвищення рівня персоналізації та оптимізації сценаріїв атак. Розглянуто вплив людського фактора як ключового елемента вразливості, що визначає ефективність соціальної інженерії. Проведено кількісний аналіз динаміки фішингових атак за останні роки, який демонструє експоненційне зростання кількості інцидентів та свідчить про активне використання автоматизованих інструментів кіберзлочинцями. Окремо досліджено розподіл каналів реалізації фішингових атак, зокрема електронної пошти, SMS, голосових комунікацій та соціальних мереж, що дозволило визначити їхню відносну ефективність та рівень ризику.

Запропоновано багатофакторну математичну модель оцінки ймовірності успішності фішингової атаки, яка враховує рівень захищеності інформаційної системи, ефективність застосованих методів соціальної інженерії, характеристики каналу поширення, а також поведінкові особливості користувачів. На відміну від існуючих підходів, модель розширено шляхом введення часової функції адаптації, що дозволяє враховувати зміну параметрів атаки в динаміці. Додатково використано елементи теорії ймовірностей для моделювання інтенсивності атак та підхід інформаційної ентропії для оцінки невизначеності у виборі каналів фішингу.

Отримані результати підтверджують, що сучасний фішинг є складною багатовимірною загрозою, яка поєднує технічні, поведінкові та інформаційні аспекти. Запропонована модель дозволяє формалізувати процес оцінки ризику, здійснювати прогнозування ефективності атак та може бути використана для розробки адаптивних систем кіберзахисту. Практична значущість дослідження полягає у можливості застосування отриманих результатів у системах управління інформаційною безпекою, а також у підвищенні рівня обізнаності користувачів щодо сучасних методів соціальної інженерії.

Abstract. This article analyzes current trends in phishing, including the use of artificial intelligence technologies to automate the creation of phishing content, increase the level of personalization, and optimize attack scenarios. It examines the influence of the human factor as a key vulnerability that determines the effectiveness of social engineering. A quantitative analysis of the dynamics of phishing attacks in recent years is conducted, demonstrating an exponential increase in the number of incidents and indicating the active use of automated tools by cybercriminals. The distribution of channels used to carry out phishing attacks -specifically email, SMS, voice communications, and social networks - was examined separately, allowing for the determination of their relative effectiveness and risk level.

A multifactorial mathematical model for assessing the probability of a phishing attack’s success is proposed, which takes into account the level of security of the information system, the effectiveness of the social engineering methods used, the characteristics of the distribution channel, as well as user behavioral patterns. Unlike existing approaches, the model has been extended by introducing a time-dependent adaptation function, which allows for changes in attack parameters over time. Additionally, elements of probability theory are used to model attack intensity, and the information entropy approach is employed to assess uncertainty in the selection of phishing channels.

The results confirm that modern phishing is a complex, multidimensional threat that combines technical, behavioral, and informational aspects. The proposed model allows for the formalization of the risk assessment process, enables the prediction of attack effectiveness, and can be used to develop adaptive cybersecurity systems. The practical significance of the study lies in the applicability of the results to information security management systems, as well as in raising user awareness of modern social engineering methods.

Завантаження

Дані завантаження ще не доступні.

Посилання

Verizon Business. (2024). 2024 data breach investigations report (100 pp.). https://www.verizon.com/business/resources/reports/dbir/

European Union Agency for Cybersecurity. (2023). ENISA threat landscape 2023 (142 pp.).

Anti-Phishing Working Group. (2024). Phishing activity trends report: 4th quarter 2023. https://apwg.org/trendsreports/

Hadnagy, C. (2018). Social engineering: The science of human hacking (2nd ed.). Wiley.

Jain, A. K., & Gupta, B. B. (2022). Phishing detection using machine learning techniques: A comprehensive survey. Computers & Security, 114, 102577.

Khonji, M., Iraqi, Y., & Jones, A. (2013). Phishing detection: A literature survey. IEEE Communications Surveys & Tutorials, 15(4), 2091–2121.

Lastdrager, E. E. (2014). Achieving a consensual definition of phishing. IEEE Security & Privacy, 12(6), 92–95.

Gupta, B. B., & Tewari, A. (2020). A survey of machine learning techniques for detection of phishing. Journal of Ambient Intelligence and Humanized Computing, 11, 1561–1573.

Ferreira, A., & Lenzini, G. (2021). Socio-technical study on phishing. Journal of Computer Security, 29(2), 165–191.

Opara, C., Chen, Z., & Goldsmith, J. (2024). Phishing detection with generative AI: Challenges and opportunities. arXiv. https://arxiv.org/abs/2401.00001

Williams, E. J., Hinds, J., & Joinson, A. N. (2018). Exploring susceptible individuals’ responses to personal and impersonal phishing. Computers in Human Behavior, 87, 227–237.

Alkhalil, A., et al. (2021). Phishing attacks: Recent comprehensive study and a new model for automated detection. Papers in Computer Science, 3(2), 12–25.

Chiew, K. L., et al. (2018). A survey of phishing attacks: Their types, vectors and technical approaches. Expert Systems with Applications, 106, 1–20.

Vishwanath, A., et al. (2011). Why do people click on phishing links? Communications of the ACM, 54(12), 52–59.

Abroshan, H., et al. (2022). Phishing: The role of human error and psychological traits. Frontiers in Psychology, 13, 1–15.

Downloads


Переглядів анотації: 4

Опубліковано

2026-09-24

Як цитувати

Кривокульська, О., Яковенко, О., Марченко, Я., & Якимчук, Є. (2026). ФІШИНГ НОВОГО ПОКОЛІННЯ: ЕВОЛЮЦІЯ СОЦІАЛЬНОЇ ІНЖЕНЕРІЇ В УМОВАХ ЦИФРОВОЇ ТРАНСФОРМАЦІЇ. Електронне фахове наукове видання «Кібербезпека: освіта, наука, техніка», 2(34), 757–765. https://doi.org/10.28925/2663-4023.2026.34.1222