Análisis de los esfuerzos por generar confianza en las relaciones: El caso del pretexto, un ataque de ingeniería social
DOI:
https://doi.org/10.51247/8wys1v42Palabras clave:
Pretexto, ingeniería social, confianza, ciclo de ataqueResumen
La ingeniería social representa una de las principales amenazas para la seguridad de la información, al explotar factores psicológicos y conductuales para obtener acceso a datos confidenciales. Entre sus modalidades, el ataque de pretexto destaca por la construcción deliberada de escenarios creíbles que buscan generar confianza y persuadir a las víctimas para revelar información sensible. El objetivo de este estudio fue analizar la influencia de los esfuerzos por generar confianza mediante el pretexto y su relación con la vulnerabilidad de los estudiantes de Sistemas y Tecnologías de la Información de la Universidad de KwaZulu-Natal (UKZN) frente a este tipo de ataques. La investigación adoptó un enfoque cuantitativo, con un diseño no experimental y de alcance explicativo, utilizando la técnica de encuesta para la recolección de datos entre estudiantes de Sistemas de Información y Tecnología. Los datos obtenidos fueron analizados mediante procedimientos estadísticos para evaluar la relación entre la calidad de la comunicación, los esfuerzos de persuasión, la confianza, el compromiso relacional y la susceptibilidad al ataque de pretexto. Los resultados evidenciaron que la calidad de la comunicación no ejerció una influencia estadísticamente significativa sobre la confianza de los participantes. En contraste, los esfuerzos de persuasión incrementaron significativamente la confianza, fortaleciendo el compromiso en las relaciones y aumentando la vulnerabilidad frente a los ataques de ingeniería social basados en pretextos. Se concluye que los mecanismos de persuasión constituyen un factor determinante en la efectividad del pretexto, lo que resalta la necesidad de fortalecer la formación en concienciación sobre seguridad y el desarrollo de competencias para identificar estrategias de manipulación social
Descargas
Referencias
Abdullah, Z., & Musa, R. (2014). The effect of trust and information sharing on relationship commitment in supply chain management. Procedia-Social and Behavioral Sciences, 130, 266-272.
Adams, J. S., & Freedman, S. (1976). Equity theory revisited: Comments and annotated bibliography. In Advances in experimental social psychology (Vol. 9, pp. 43-90). Elsevier.
Adu, E. O., Ojo, O., & Adu, K. O. (2019). Evaluation of South Africa University Lecturers Accessibility and Utilization of E-Learning Infrastructure for Teaching. EdMedia+ Innovate Learning,
Aiden, M. K., Chhabra, S., Sabharwal, S. M., & Hameed, A. A. (2025). Social Engineering Attacks: Detection and Prevention. Emerging Threats and Countermeasures in Cybersecurity, 349-387.
Alabdan, R. (2020). Phishing attacks survey: Types, vectors, and technical approaches. Future Internet, 12(10), 168.
Albladi, S. M., & Weir, G. R. (2018). User characteristics that influence judgment of social engineering attacks in social networks. Human-centric Computing and Information Sciences, 8(1), 5.
Aliyu, M., Abdallah, N. A., Lasisi, N. A., Diyar, D., & Zeki, A. M. (2010). Computer security and ethics awareness among IIUM students: An empirical study. Proceeding of the 3rd International Conference on Information and Communication Technology for the Moslem World (ICT4M) 2010,
Alseadoon, I. M. A. (2014). The impact of users' characteristics on their ability to detect phishing emails Queensland University of Technology].
Ball, D., Coelho, P. S., & Machás, A. (2004). The role of communication and trust in explaining customer loyalty. European journal of marketing.
Benavides-Astudillo, E., Silva-Ordoñez, L., Rocohano-Rámos, R., Fuertes, W., Fernández-Peña, F., Sanchez-Gordon, S., & Bastidas-Chalan, R. (2021). Analysis of Vulnerabilities Associated with Social Engineering Attacks Based on User Behavior. International Conference on Applied Technologies,
Bhattacherjee, A., & Sanford, C. (2006). Influence processes for information technology acceptance: An elaboration likelihood model. MIS quarterly, 805-825.
Broadhurst, R., Skinner, K., Sifniotis, N., Matamoros-Macias, B., & Ipsen, Y. (2018). Phishing and Cybercrime Risks in a University Student Community. Available at SSRN 3176319.
Bryman, A., & Bell, E. (2011). Business Research Methods.
Butavicius, M., Parsons, K., Pattinson, M., & McCormac, A. (2016). Breaching the human firewall: Social engineering in phishing and spear-phishing emails. arXiv preprint arXiv:1606.00887.
Chandarman, R., & Van Niekerk, B. (2017). Students' cybersecurity awareness at a private tertiary educational institution. African Journal of Information and Communication, 20, 133-155.
Conteh, N. Y. (2021). The dynamics of social engineering and cybercrime in the digital age. In Ethical Hacking Techniques and Countermeasures for Cybercrime Prevention (pp. 144-149). IGI Global.
Cropanzano, R., Anthony, E. L., Daniels, S. R., & Hall, A. V. (2017). Social exchange theory: A critical review with theoretical remedies. Academy of Management Annals, 11(1), 479-516.
Daniel, W. W., & Cross, C. L. (2018). Biostatistics: a foundation for analysis in the health sciences. Wiley.
Garcia, T. A., Fairlie, A. M., Litt, D. M., Waldron, K. A., & Lewis, M. A. (2018). Perceived vulnerability moderates the relations between the use of protective behavioral strategies and alcohol use and consequences among high-risk young adults. Addictive behaviors, 81, 150-156.
Hameed, M. A., & Arachchilage, N. A. G. (2019). On the Impact of Perceived Vulnerability in the Adoption of Information Systems Security Innovations. arXiv preprint arXiv:1904.08229.
Hargie, O. (2016). Skilled interpersonal communication: Research, theory and practice. Routledge.
Huo, B., Zhang, C., & Zhao, X. (2015). The effect of IT and relationship commitment on supply chain coordination: A contingency and configuration approach. Information & management, 52(6), 728-740.
Information & Communication Services. (2019). Phishing and spam awareness. University of KwaZulu-Natal. Retrieved 13 February from https://ics.ukzn.ac.za/wp-content/uploads/2018/03/Phishing_4.pdf
Jeong, M., & Oh, H. (2017). Business-to-business social exchange relationship beyond trust and commitment. International Journal of Hospitality Management, 65, 115-124.
Krejcie, R. V., & Morgan, D. W. (1970). Determining sample size for research activities. Educational and psychological measurement, 30(3), 607-610.
Lord, N. (2020). Social engineering attacks: Common techniques & how to prevent an attack. Digital Gurdian.
MacFarland, T. W., & Yates, J. M. (2016). Mann–whitney u test. In Introduction to nonparametric statistics for the biological sciences using R (pp. 103-132). Springer.
Mitnick, K. D., & Simon, W. L. (2003). The art of deception: Controlling the human element of security. John Wiley & Sons.
Mouton, F., Leenen, L., & Venter, H. S. (2016). Social engineering attack examples, templates and scenarios. Computers & Security, 59, 186-209.
Mouton, F., Malan, M. M., Leenen, L., & Venter, H. S. (2014). Social engineering attack framework. 2014 Information Security for South Africa,
Muslah Albladi, S., & Weir, G. R. (2019). A conceptual model to predict social engineering victims.
Ofusori, L. O., & Subramaniam, P. R. (2021). The Influence of Technical and Social Factors in Mitigating Threats in a BYOD-Enabled Environment. International Journal of Information Systems in the Service Sector (IJISSS), 13(1), 1-30.
Perrin, A., & Duggan, M. (2015). Americans’ Internet access: 2000--2015. Retrieved 28 June from http://www.pewinternet.org/2015/06/26/americans-internet-access-2000-2015/
Redmond, M. V. (2015). Social exchange theory.
Rege, A., Williams, K., & Mendlein, A. (2019). A social engineering course project for undergraduate students across multiple disciplines. 2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security),
Roy, A. B. (2025). A Review of Understanding the Social Engineering in the Context of Cybersecurity. Unveiling Social Dynamics and Community Interaction in the Metaverse, 357-388.
Sharma, S., Avasthi, A., Kapoor, S. K., Keswani, B., Gupta, S., & Goyal, N. K. (2026). Psychological Dimensions of Social Engineering in Cybercrime. In Cyber Forensic Frameworks for User-Centric Human Threat Intelligence Analysis (pp. 119-148). IGI Global Scientific Publishing.
Stergiou, D. (2013). Social Engineering and Influence: A Study that Examines Kevin Mitnick’s Attacks through Robert Cialdini’s Influence Principles. In.
Tavakol, M., & Dennick, R. (2011). Making sense of Cronbach's alpha. International journal of medical education, 2, 53.
Tian, C., Jensen, M. L., & Durcikova, A. (2018). Phishing Susceptibility across Industries: The Differential Impact of Influence Techniques. Proceedings of the 13th Pre-ICIS Workshop on Information Security and Privacy,
Walker, L. E. (2016). Deception of Phishing: Studying the Techniques of Social Engineering by Analyzing Modern-day Phishing Attacks on Universities.
Zulkurnain, A. U., Hamidy, A., Husain, A. B., & Chizari, H. (2015). Social engineering attack mitigation. Int. J. Math. Comput. Sci, 1(4), 188198.
Descargas
Publicado
Número
Sección
Licencia
Derechos de autor 2026 Lizzy Ofusori, Prabhakar Rontalal-Subramaniam

Esta obra está bajo una licencia internacional Creative Commons Atribución-NoComercial-CompartirIgual 4.0.














