literature review

profilesindhu16
FinalPaper-UpdatedA.Lakumarapucomments.docx

BIOMETRIC AUTHENTICATION TO SOCIAL ENGINEERING 1

Biometric Authentication as a Solution to Social Engineering

Aditya Lakumarapu

DSRT 736

University of the Cumberlands

Biometric Authentication as a Solution to Social Engineering

Introduction

The idea of social engineering refers to an attempt by computer system hackers to trap or trick individuals into revealing their valuable information or passwords. The attack using this mechanism has always been efficient when companies with sound security systems readily available are tracked down. Intensive research has shown that this kind of attack is challenging to defend against and evolves rapidly. As the world embraces technological changes through social media networks, online-based transactions, and automated engineered processes, there have been everlasting challenges that have continued to impact and handicap the specialized services due to social engineering. Social engineering is one of the significant organizational threats faced due to increased connectivity in digital platforms. Comment by Sarah Nichter: This phrasing doesn’t make sense. What does it mean to have a security system that is readily available? And “tracked down” is slang for finding something that was hard to find or get. This doesn’t really apply to companies, not in this sense. Comment by Sarah Nichter: Be more specific. What specialized services are we talking about. This is the first time in this document the phrase has been used.

The term biometrics refers to the emerging technological field used on individual identification using biological characteristics such as fingerprints, iris scanning, and face recognition. Many countries use biometric authentication, which plays a crucial role in their businesses. These countries include the United States of America, Russia, China, and many more, through cybersecurity attacks have proven to imprison several people living in these countries. Since biometrics uses individual traits in identification, social engineering attacks can be significantly reduced through this technique (Aldawood & Skinner, 2019). This paper goes ahead to explore explores various mechanisms against successful social engineering by using biometrics technology. Comment by Sarah Nichter: This sentence has a mixed grammatical structure. The sentence starts out with one structure then changes to another after the comma after “more”. Additionally, the reference to “imprison several people living in these countries” is unclear. What is this supposed to mean? Is it literal or figurative? And how does it relate to this topic?

Literature Review

This literature review does not explain the identity verification gap. This piece misses in this review as it explains the history of biometric technology and goes ahead to explore it further. However, the identity verification gap is not considered and explored, which provides a considerable gap to the literature. Social engineering and the identity verification gap correlate, given over the last decade, no research study has explored the identity verification gap. The review does not explain the variety of contexts existing in the identity verification gap. The different contexts are the determinants of the magnitude of the harm caused. Comment by Sarah Nichter: Vague, be more specific about what sections come after the history Comment by Sarah Nichter: Word choice

The review fails to discuss the privacy gap and how handling the privacy gap will aggravate the security gap given everything will be occurring in cyberspace; thus, tracking illegal transactions will be hard for the authorities, and service providers will have no clue of their customer. More research needs to be done on the security and privacy gap alongside the identity verification gap to determine their magnitude and impact on identity verification.

Introduction to Biometric Technology

Biometric authentication is a technology that can measure and evaluate a human being's behavioral characteristics such as voice and signature and also analyzes biological features such as iris's pattern, palm, and fingerprint given it has several systems developed with numerous commercial products beginning to appear, especially in the security marketplace. Everyone has unique biometric features, and no one has a similar anatomical characteristic like the fingerprint (Fianyi & Zia, 2016). Therefore, it serves as a solution to social engineering by distinguishing individuals based on these characteristics. (Fianyi & Zia, 2016). Therefore, it serves as a solution to social engineering by distinguishing individuals based on these characteristics. This paper aims to postulate biometric as a solution to existing methods of combating social engineering.

History of Biometrics

The use of fingerprints as a form of biometrics started as early as 1881. It was started by Juan Vucetich when he started collecting fingerprints of criminals in Argentina. David Lyon denotes biometrics as a form of a political tool available today as a form of 'soft control.' David Lyon, a theoretician, underscores the fact that biometrics has since penetrated the civilian market and are being used beyond governmental institutions. The present-day form of biometrics is the automated way of identifying persons using advanced machines. Comment by Sarah Nichter: Citations needed in this paragraph

The better part of the 1880s witnessed the introduction of fingerprint, where contracts and signatures alongside criminal identification became a means of identification. State laws suggested that fingerprint was accountable for an individual's identity. Thus it became a symbol of recognition. The first fingerprint system, the Henry Classification System, was developed by Edward Henry and was the first to be integrated into the criminal justice system as an identification after Bertillon’s later abandoned techniques. Comment by Sarah Nichter: Word choice Comment by Sarah Nichter: Need citations in this paragraph

Types of Biometrics

Fingerprint Verification

This is the most superior biometric technology used. Research shows that millions of people and companies worldwide depend on this type of technology. The technology functions by identifying the smallest regions/locations present in the fingerprint. However, several environmental factors may affect these prints' readability, including temperature and humidity, among others (Aldawood & Skinner, 2019). For instance, false rejection and acceptance are estimated at less than 1% and about 0.0001%, respectively. Comment by Sarah Nichter: Be more specific. Do not start out new sections or new paragraphs with vague references like this.

Hand Based Verification

The technique is also known as hand geometry. This is one of the biometric technologies commonly used in the biometric industry, especially in time access, attendance, and access control. They are usually based on the geometry measurement of an individual's hand. Perhaps, some hand techniques may take into consideration the measurement of two fingers. The false acceptance of this technique is usually estimated at 1% (Parsons, 2020.). Comment by Sarah Nichter: Be specific

Iris and Retina Scanning

The retina scan is regarded as one of the most accurate biometric authentication technologies. For instance, technology, according to Bendovschi (2015), has proved to offer the most effective solution to every scenario that demands authentication. On the other hand, the Iris technology system has also proved to be effective with a lower false acceptance rate than other existing biometric technology methods, as pointed out by Fianyi & Zia, (2016). The retinal scanning technique utilizes different low-intensity infrared cameras in taking images of the back of an eye. Iris scanning, on the other hand, works by identifying the unique texture patterns of the iris. Research findings show that even identical twins possess different iris texture patterns, which do not change in a lifetime (Alsalom et al., 2017).

Speaker/Voice Verification

In scenarios where an individual's voice is already captured, this is the most suitable biometric technique used. The voice can be captured in telephony, call centers, among others. The technique is most suited in different application systems where other biometric techniques may be challenging to employ. Voice verification is deployed in various areas such as account access, banking, home PC, home imprisonment, and network access, among others.

Dynamic Signature Verification

The Dynamic Signature Verification technique relies on how an individuals' signature is written rather than its physical appearance. A sensitive tablet or a special pen may be used in tracking the hand movements. This system determines the individual's identity since it has the individual's profile, thus has every information of the individual’s identity given several fingerprint types are required to determine a person’s identity.

This system is, however, robust as compared to others though it has the capabilities to execute all commands it receives. Dynamic signature verification will be swift and efficient since global and local features will be used for optimal performance. Functions of time are collected as coordinates x and y, which provide a capturing function that tablets may use through their pens.

Benefits of Biometrics to Social Engineering

The use of biometrics has led to a reduced rate of internet crimes, as described by Abass (2018). Many organizations across the world have embraced the use of biometrics to curb computer crimes. Weak security systems have given hackers an advantage whenever they want to commit a crime in a particular organization. The reliability, ease to use, flexibility, and accuracy have enabled biometrics to be one of the premier authentication techniques among organizations. Furthermore, a human voice, which is always the most common form of communication, is the ideal model for personal identification (Fianyi, & Zia, 2016). In this case, therefore, it can be used in protecting an individual from a social engineering attack. The use of biometric technologies enables one to protect networks from unauthorized access. Voice recognition devices are being embraced in marketplaces, especially with security applications, to enhance security levels. Their ability to combine biometric verification and password protection possess a promising future in the security industry. In human-based social engineering, voice biometrics can provide effective solutions.

Unique Nature of Biometric Authentication

Biometric authentication features are unique to individuals. For example, every individual has a unique fingerprint that differentiates him from another person. Unlike the passwords that one can easily forget, biometric technology does not fail because it stores a person's biological information. It is the most effective method to curb social engineering because criminals cannot steal a person's physical features (Fianyi & Zia, 2016). An excellent example of biometric technology is the phone's fingerprint, which most smartphone operators use to verify identity. Organizations, such as banks, use biometrics to prevent unauthorized individuals from gaining access to sensitive places such as money safes; people must be verified by fingerprint. If a criminal wanted to steal from the bank, their access would get denied by the biometric since it only gives access to legitimate employees who are registered. Research shows that biometric technology has reduced criminal activities in the United States have failed to get access to people's data because of biometric technology (Fianyi & Zia, 2016). Biometric technology is vital to prevent social engineers from accessing critical information.

Biometric Use Today

Various studies have been carried out concerning biometric technology in the recent past. Studies reveal that approximately 90% of organizations and learning institutions have already introduced biometric security to protect their data from social engineers and to ease the burden of monitoring their employees (Aldawood & Skinner, 2019). Supermarkets and malls use biometric security to prevent theft by ensuring every item is registered with a security code that must be scanned before exiting. Biometric technology ensures no one steals anything from these organizations; hence, it is a social engineering solution.

Strength of Biometrics Technology

The use of biometric technology is more efficient and effective compared to other technologies in the same field. The techniques provide a high level of security assurance. An individual trait is used in identification and, therefore, easy to verify. Many scholars believe that biometric authentication is more convenient and faster, thus solve security issues efficiently. The individual traits are non-transferable because every individual has a unique set of biometric characteristics. Social engineering is a technique that cybercriminals used to manipulate people to acquire and access confidential information. They do not use coercion to gain this information; instead, they motivate people to share information such as the identification number, phone number, and year of birth to create fake accounts to withdraw money from the bank and carry out criminal activities. Social engineers manipulate people using a non-technical attack to reveal confidential information (Abass, 2018). Cybercriminals attempt to seek confidential information by tricking people to give bank information or password or access people's personal computers without their knowledge to install software that allows them to steal passwords, control the computer, and access bank information. Thus, the unique features of biometric authentication prove to be its strength since intense security is developed according to the individual's features.

Types of Cyber Security Threats

Cybersecurity threats are acts deemed malicious that aim at infiltrating an individual’s personal data in the digital world. Data breaches and computer viruses are types of cyber threats. A cyber-attack can be launched through cyberspace in the modern world, which makes it a harmful tool in the digital world. The following techniques are used in the existing security methods to breach Cyber-Security.

Phishing

In the phishing process, the attackers strategically incorporate misleading emails to the targeted users, use of the website by creating adds which the users can be attempted to use, and instant or sending messages with the aim of getting access to the users' accounts and stealing the data ("9 Examples of Social Engineering Attacks | Terranova Security", 2020). Social engineering posits adverse effects such as theft on organizational data. One of the challenges is identity theft. Abass (2019) argues that approximately 90% of internet users daily receive phishing messages and emails from hackers. Identity theft involves information regarding the credit card, unauthorized document access, which can put the organization at risk of theft.

Social engineers' most common stealing methods from organizations are phishing emails and online advertisements on social media. Phishing refers to a criminal's act of pretending to be recruiting employees and asks for confidential details from people to help them conduct cyber-attacks (Williams & Joinson, 2020).

Baiting (Williams & Joinson, 2020) Comment by Sarah Nichter: Cite sources in these sections. That is the essence of a literature review – to review all the relevant literature on the topic. It’s not a review if you don’t cite sources. And it is possibly plagiarism if you don’t cite sources. Comment by Sarah Nichter: ???

In the baiting process, attackers promise the users a reward or prize for giving a specific type of information. This type of social attack is very tempting because people are greedy, desperate for things like money. The curiosity and greed of a victim may be their downfall as attackers use false promises to attract the victim. Malware is dispersed via physical media, and this is the most known baiting technique.

This tactic, mostly used by attackers through physical media, makes victims access them without being skeptical of the deal. When the victims try using the media in their machines, the malware installed by the attacker installs automatically. Since the process is not physical, the victim will not suspect anything. Online applications that are infected by malware may be downloaded by users without knowing it is infected, and this makes them victims.

Malware

Casualties are fooled into accepting that malware is introduced on their PC and that they will be taken out if they pay. Networks and devices may be harmed through malware that may make its way to the victim’s computer through malicious ways, and since there is a variety of malware, there may be other harm caused to the victim.

The user may receive emails containing malware links, and for mobile phones, victims will receive malware through short messages. The victim will unsuspiciously clink on the link and open a website containing appealing words to the user. Once the link is clicked, the user's filters are bypassed by the malware, thus penetrating the user's system making the user a victim later on.

Pretexting

Pretexting utilizes bogus characters to fool casualties into surrendering data, for example, pretending to be one of the family members who need some information. However, in the real sense, they are not. They are attackers masquerading as family members targeting the victim with a goal that harms the victim eventually. This technique is deadly; I used to individuals having family members far and communicate less frequently.

Victims are made to believe a legit source is calling them for a specific reason, thus needing personal information. The attacker establishes a good rapport with the victim before completing the scam. The victim is questioned by the attacker and unveils their identity step by step, and this way, the personal data of the victim, is collected enough to cause them harm. A lot may be gathered in this scam, including phone records, phone numbers, personal addresses, and social security numbers.

Close following

Close following depends on the trade of data or administration to persuade the casualty to act. For instance, a message can keep on appearing on your site a thousand times, and then the user is feed-up, and in return, he or she accepts the message with a view that it will not create any disturbance anymore. These messages, once accepted, makes a victim vulnerable.

In short, attackers track their victims for a long time and keeps sending a pop-up message to the user’s screen. Users see this message for some time, and since they keep popping, they think that accepting them will reduce their appearance on the user’s screen, and accepting the message is the first step to being a victim of an attack.

Vishing

Vishing refers to pressing phone messages to persuade casualties to act rapidly to shield themselves from capture or other danger. For example, some attackers pretend to be customer providers who need to get some information quickly, and if they do not give the information, they threaten to close their lines or sites. Neither attacker is what they say they are, and this is a simple way through gaining someone’s money and identity. A message would pop up on the user's screen, making them unsuspicious of what is about to happen. When called, the scammer would make the call look legit, making the victim less suspicious, and many people may be victims in a short period.

Water Holing

This is one of the most severe social assault which contaminates the site and the entire system with malware at a go. The one consistent idea connecting these social designing methods is the human component. Cybercriminals realize that exploiting human feelings is the ideal approach to take. Generally, organizations have zeroed in on the specialized parts of online protection – however, it is an ideal opportunity to adopt a people-driven strategy to network safety mindfulness. Studies suggest that cyber insecurity will continue to rise if strength measures fail to get implemented. Human emotions make humans vulnerable and encourage attacks to give victims who may be organizations or individuals are vulnerable to water holding.

Shortcomings of Non-biometric security Techniques

One may get a message telling them they are under scrutiny for charge tax fraud and call quickly to forestall capture and criminal examination. This is an everyday situation that attackers may use to instill fear in humans. This social designing assault occurs mostly during the tax pay season when individuals are worried over their duties. Cybercriminals go after the pressure and nervousness that accompanies documenting charges and utilize these dread feelings to fool individuals into agreeing to their conning voice message. This is one of the most efficient ways of conning people, which the cyber attackers use (Fianyi & Zia, 2016).

Suppose one could move $10 to a speculator and see it change or grow to $10,000 with no exertion for personal benefit? Cybercriminals utilize the real human feelings of trust and avarice to persuade casualties that they genuinely can get something in vain. A deliberately phrased bedeviling email advises casualties to give their financial data, and the assets will be moved immediately.

As the saying says, curiosity killed the cat; Cybercriminals focus on functions catching a ton of information, including curious people, and afterward exploit human interest to fool social designing casualties into acting. For instance, after the second Boeing plane crash accident, cybercriminals sent messages which connections that professed to incorporate spilled information about the accident. Their main target was to introduce a rendition of the worms on users' PC. This worked perfectly well because people are curious. Comment by Sarah Nichter: Use more accurate laguage Comment by Sarah Nichter: cite

Naturally, People need to trust and help each other on different occasions because they think their time will come when they need to be helped. In the wake of examining an organization, cybercriminals target a few workers in the organization with an email that seems as though it originates from the administrator. The email requests that they send the supervisor the secret key for the bookkeeping information base – focusing on that the chief requirements for the information are to ensure everybody gets paid on schedule. The email tone is dire, fooling the casualties into accepting that they are assisting their chief by acting quickly. Such messing is very convincing, and many people can be encountered such a dilemma in their workplace. Comment by Sarah Nichter: this paragraph needs citations

Most of the attackers use an urgent tune tone to convince users. For instance, in this case, one would get an email from client service entrusted and often purchase and inform you that they need master card confirmation to record the purchase. The language used in such an email requires one to react faster to ensure that hoodlums do not take their Visa data. Without reconsidering because one would use the online store, an individual will defiantly send all card information required. One may find themselves disclosing other personal information like email and phone numbers, which they can easily use to get the passwords. A couple of weeks after the encounter, one may get a call from the bank department informing them that many dollars have been withdrawn from their account to purchase deceitful goods. This kind of awareness, when created by people they can have some guide on how attackers use emotional venerability to ground people (Fianyi & Zia, 2016). Comment by Sarah Nichter: more citations needed.

Challenges Facing Non-Biometric Techniques

Cyber theft

Cyber theft is mostly committed by cybercriminals who want to get money through questionable origins. It is a criminal activity that mainly targets the computer or a network device. Cyber theft employs highly skilled techniques to acquire information that would help them steal from individuals or organizations. They target computers by sending viruses that damage the device, steal, or delete the data. Most organizations continue to receive numerous cyber-attacks; one of the most popular attacks is malware attacks. A malware attack involves a computer infected with a virus, affecting its functionality (Bossler & Belenblum, 2019). Therefore, cyber theft deletes information or steal data from the computer, which may help hackers steal money. According to Bossler & Belenblum (2019), the number of research concerning cyber theft has continued to grow over the years; most of the works in this area focuses on studying and exploring how cyber theft has continued to affect organizations in most parts of the world. The European Society of Criminology (ESC) reveals that cyber thefts have increased in the United States.

Psychological challenges

Psychological factors such as an individual's personality, mostly if they work in a low environment, may compel them to turn into cyber thieves. For instance, if someone is working in a bank and the atmosphere is not conducive, their pay does not equal the work, this may prompt them to hack the systems to steal money. Motivation is crucial in ensuring that people do not turn into hackers, especially those who work in such environments (Bossler & Belenblum, 2019). Therefore, cyber theft emanates from psychological factors such as personality and lack of proper motivation, so it is essential to ensure employees get treated relatively; otherwise, they may turn into thieves. Comment by Sarah Nichter: What does this mean? Comment by Sarah Nichter: Relatively what?

The research to determine how psychological factors may compel people to embrace cyber theft is growing. Bossler & Belenblum (2019) note that psychological factors, such as stress and burnout, can also lead to cyber theft. Research carried out by cyber theft scholars is considered a vital source of information for every country's policy formulators. Governments should intervene by educating the vulnerable people on the need to stay vigilant; they should also implement laws to ensure cyber criminals get incarcerated to mitigate the levels of cyber thefts (Sarre et al., 2018). Lastly, there is exponential growth in cyber theft, scholars have embraced innovative methods, and their research is making significant impacts, especially in the United States of America.

Hacking

When the world continues to grow and become more sophisticated due to technology, the reason for hackers getting motivated to access people's personal information and data also increases. According to Alsalim et al. (2017), a hacker is someone who illegally tampers with information in a computer system. Therefore, the definition of hacking is an attempt to exploit a private network or a computer system to achieve an illicit purpose. The common types of hacking are grey, black, and white hat hackers. Hacking leads to damage of digital data because hackers have skills in using computer software.

Hackers try to blackmail people and organizations using their information. Hackers will try to acquire specific information to help them threaten national security. Most politicians' trust built with their audiences has been eroded by fake posts that originate from genuine account owners. Anonymous posts have been released on social media, propagating fake news that Russia interfered with the 2016 US elections, which resulted in economic and political tensions between the presidents of two nations; that is, Donald Trump and Vladimir Putin. (Alsalim et al. 2017;), ( Parsons, 2020). Therefore, people need to be vigilant to avoid falling into the traps of hackers. Further, Abass (2018) notes that research reveals technical disaster is a recipe for hacking. Besides. In 2011, the number of cybercriminals in the United States rose exponentially due to the lack of an appropriate firewall to prevent hacking. Comment by Sarah Nichter: To cite two sources in one in-text citation, include them both in the parenthesis and separate them with a semicolon like this.

Social engineering can be curbed through various methods. However, it is vital to select the most effective solutions to enhance people's information security. Non-governmental organizations are assisting to curb cyber theft. For instance, the (SDF) Secure Domain Foundation helps individuals and organizations expose, avoid, and arrest cybercriminals involved in hacking information by analyzing data to provide a secure connection to the internet users (Secure domain Foundation, 2020). According to Bendovschi (2015), Google has begun developing strategies that counter cyber-criminal activities. They have developed Project Zero to analyze vulnerability and codes from companies to create and enhance software that mitigates cyber-attack risks among internet users worldwide. Therefore, the shortcomings that emanate from social engineering are manageable when stringent countermeasures are employed.

Use of Passwords

A strong password is one that both human beings and computers cannot easily detect because it has complex characters that include a combination of words, symbols, and letters, making it difficult for social engineers to access. Salahdine & Kaabouch (2019) argue that a strong password must have eight characters or more; that is, it must be long enough. For instance, instead of using "Password1" as the password, instead, use a strong one like "Inerduytr@1". Using a strong password is because most hackers exploit the systems quickly. Strong passwords are crucial to preventing cyber theft; they need to log in first for someone to access the computer. It is also vital to ensure the password remains a secret that means no one should know your password. After all, criminals guess the password. Comment by Sarah Nichter: Word missing

Therefore, a strong password is recommended. Research has revealed that approximately 1.5 billion people worldwide get scammed every year due to a lack of strong passwords, giving cybercriminals easy access to people's accounts starting in 2015 (Salahdine & Kaabouch, 2019). Federal Bureau of Investigation (FBI) shows that 60% of financial institutions in the United States faces fraud cases from social engineers due to inadequate knowledge of the risk factors; this has increased cybercrimes rates (Norris et al., 2019). The high speed of hackings emanates from creating weak passwords, enabling cybercriminals to have an opportunity to hack.

Use of Antivirus

An antivirus protects a computer from hacks, spam attacks, viruses, and other related threats. A virus is a program designed by cybercriminals and enters the computer system; it spreads and replicates, affecting computer performance, equivalent to a human body virus. The antivirus enables the computer to counter any virus attacks. It is vital to install an antivirus on the computer because it cannot get eliminated in its absence. Antiviruses are developed by social engineers to illegally steal or hack the computer system to acquire information (Bendovschi, 2015). Researchers argue that it is crucial to verify the security systems to ensure that the antivirus is operating to protect the computer from malicious hackers (Safarkhanlou et al., 2015). Research conducted by Safarkhanlou et al. (2015) note that antivirus applications such as Kaspersky and Avira are essential in curbing virus infection in computers. These applications are used by approximately 20 billion people all over the world. Therefore, to avoid malicious attacks from cyber thieves, every individual or organization needs to install antivirus applications on their computers.

Passwords and Antiviruses not a Solution

People use similar passwords in almost all the online platforms, making it easy for the attackers to access because one disclosure will mean losing all personal information. Numerous online users do not change default passwords; this implies that attackers can quickly access personal data through these passwords. More so, default passwords are freely accessible from all available manuals; additionally, they are pretty simple to figure. Passwords are regularly shared among employees who work in standard organizations (Salahdine & Kaabouch, 2019). Social engineers use a perpetual scope of strategies. They use persuading messages on the websites to approach individuals to share their usernames to compromise their antivirus security. Most attacks are not virus-based, which makes antiviruses impractical in curbing such attacks. (Safarkhanlou et al., 2015). Antiviruses fail to offer individuals full protection from social engineer's attacks.

The password cracking system has advanced the use of similar passwords for a long time makes it easy for hackers to gees the passwords. Secret key breaking instruments are getting great at speculating passwords due to technological advancement. The innovative advances inside this zone go super quick – it is merely a question of time before passwords are viewed as substantial to getting access. Individuals regularly utilize too weak passwords (Salahdine & Kaabouch, 2019). This can even make it workable for individuals to figure the secret word without the guide.

Antiviruses are effortlessly taken through social designing. A shockingly level of individuals share their login data. Passwords are sent over unstable websites, for instance, the use of an unprotected network, which makes it simple to get the passwords sent through the same means. Associations' secret word information bases get hacked substantially more frequently, and employees do not figure it out. Much of the time, the programmer assault never gets detected, or it takes a long to be noted. It implies that the programmers can utilize the passwords and get the targeted information (Salahdine & Kaabouch, 2019). Comment by Sarah Nichter: This doesn’t make sense.

Unique Biometric Authenticators

The retina is the first type of biometric authenticators; it produces a picture of a person's inner vein of the eye using light. Iris examiners are used to identifying users by distinguishing the shape of the pupil of the user's eye. Finger scanning is a computerized adaptation that uses the ideology of ink-and-paper printings, looks at the users' identity by checking the human finger's branches. Finger vein ID: it uses the vascular in a person's body to detect the user, for example, in a person's finger. Facial acknowledgment: it is a framework that works with codes known as face prints that distinguish nodal found in the user's face. Voice recognizable depends on the qualities of the sound made from the state of the speaker's mouth and throat (Malathi & Jeberson, 2016).

Biometric authenticators Outstanding Features is the Current Era.

It has High security and assurance. Biometric ensures a high level of confidence; it uses the rightful person by verifying non-duplicable aspects of a person, for example, DNA. A security breach faces other data protection methods because they are readily available or obtained by funders (Malathi & Jeberson, 2016). The biometric authenticators make it hard for fraudsters to circumnavigate. Additionally, modern authenticators depend on non-error characters like robots, hard to bribe or pass through if you are not an authorized person. (Malathi & Jeberson, 2016). Biometric authenticators are convenient and fast. Malathi & Jeberson (2016) note that the Use biometric authenticators are easy and quick, for instance, placing a finger on the sensor and looking at the scanning device. S More so, forgetting the passwords is a forgone because the primary password is in you, and you have not necessarily remembered it. They are Non-transferable. Biometric verification requires its information is available upon approval. You cannot move or share a physical biometric carefully – the best way to use most biometric confirmation frameworks is with an actual application.

Biometric-Social Engineering Solutions

Employees` Security

Biometric authentication protects the employer's and employees' information from social engineers. It is vital because it distinguishes real employees from fake ones; the technology gives a person the true identity by storing personal information such as palm print, which uses the palm to verify an individual, making it easy to detect the hackers (Kloppenburg & van der Ploeg, 2018). Since 2008 research has shown that society has become digital, 80% of people use digital technology, thus, increasing the number of cyber-crimes because most users are vulnerable due to inadequate security systems like weak passwords (Kloppenburg & van der Ploeg, 2018).

The employers should educate the employees to ignore unspecified links sent to them and avoid malicious emails from hackers; they should report such to the organization's relevant authorities. Employers should install biometric authentication to mitigate the challenge of cyber theft (Malathi & Jeberson, 2016). The topic is vital because it raises awareness among the employees to embrace biometric authentication to avoid getting hacked.

The technology of biometric authentication security plays a vital role in securing businesses and other large organizations and learning institutions. The Security curbs theft because it includes the iris scanning cameras mounted on walls; they pick unique eye patterns, scan, and store the data to distinguish individuals at the workplace, thus curbing cybercrime (Malathi & Jeberson, 2016). As the world embraces biometric authentication, security posits numerous challenges to people's health and could lead to cancer due to radioactivity. According to Malathi & Jeberson (2016), biometric authentication is harmful to people due to radioactivity. The study notes that; those who work in large organizations where biometric technology is used are at a greater risk of contracting cancer due to radioactivity.

Data and Information Security

Biometric authentication is a security cycle that depends on a person's exceptional organic characteristics to check their real identity. Generally, a Biometric authenticator compares the data or the stored information with the captured dater, to affirm the user's credibility. The biometric verification is used to administer both physical and software fraud, for instance, buildings, houses, organizations, rooms, and computer registers (Malathi & Jeberson, 2016).

Biometric authenticators are used by most secret services, for example, the military, to ensure security because it is hard to fake individual biological traits. More so, acknowledging biometric confirmation has been contributed by its convincing character: it is hard to lose data because Thumbprints made on earth seals cannot be used to open or access data on behalf of the owner. A current biometric confirmation has been improved by precise with the appearance of electronic information bases and digitizing all the pieces of information (Malathi & Jeberson, 2016).

Internet and Network Security

Social engineering has numerous impacts on people's daily lives, also leads to cyber insecurity. Therefore, social engineers can access information by manipulating people to provide confidential information. According to Abass (2018), research reveals that in 2015, cyber insecurity cases had risen by 95% due to inadequate security systems in most organizations in the United States of America. Organizations should encrypt their network with a virtual private network (VPN). A VPN is software to ensure the data is not intercepted by cybercriminals while sending it to another destination; thus, it ensures it is safe (Kyeremeh et al., 2019). Comparing the two studies, it is worth noting that cyber insecurity will continue to rise if strength measures fail to get implemented.

Summary

Biometric technology evaluates people's biological features. It is essential in protecting data from social engineers. Social engineering is the act of manipulating people to acquire sensitive information. Social engineers develop attacks and techniques that allow them to penetrate well-protected environments, thus compromising user's data integrity and confidentiality; the damages caused by social engineers most of the time remain untraceable. Most organizations have developed techniques to curb the everlasting cases of hackings due to cyber-attacks. An example of a method is through biometric authentication, which is a process that secures people's data from cybercriminals; this form of security matches the features of an individual to verify who they are as a way of securing their personal information. The paper has discussed how it has resulted in cyber insecurity in the US. An Individual's personality could compel people to become social engineers. The technology of biometric authentication security plays a vital role in securing businesses and other large organizations and learning institutions. Preventing social engineering requires strong passwords, antiviruses, and awareness for employees to embrace biometric authentication technology. Biometric authenticators are fast and convenient. The reason why passwords are not a solution is that people use them. The study noted that antivirus and strong passwords are essential in securing computers from malicious attacks from cyber theft. It can also be used to raise awareness among employees working in various organizations.

References

Abass, I. A. M (2018). Social Engineering Threat and defense: A Literature Survey. Information Security. 9, 257-264. https://doi.org/10.4236/jis.2018.94018.

Alsalom, M., Alsalim, A, M., Al-Madhagi., & Shahen, S, M. (2017). Information Security Threats: Computer Hacking. International Journal of Advanced Research. 5(1), 349-356. http://dx.doi.org/10.21474/IJAR01/2753.

Aldawood & Skinner. (2019). Reviewing Cyber Security Social Engineering Training and Awareness Programs—Pitfalls and Ongoing issues. Future Internet. 11(73), pp. 1-17. http://doi:10.3390/fi11030073.

Bossler, A, M., & Beremblum, T. (2019). Introduction: New directions in cybercrime Research. Journal of Crime and Justice. 42, 5, 495-499. https://doi.org/10.1080/0735648X.2019.1692426.

Bendovschi, A. (2015). Cyber-Attacks – Trends, Patterns, and Security Countermeasures. Procedia Economics and Finance. 28, 24-31. https://doi.org/10.1016/S2212- 5671(15)01077-1.

Fianyi, I., & Zia, T. (2016). Biometric Technology Solutions to Counter Today's Terrorism. International Journal of Cyber Warfare and Terrorism. 6(4). 28-40. https://www.researchgate.net/publication/309818563_Biometric_Technology_Solutions_ to_Countering_Today's_Terrorism.

Kyeremeh, K., Bright, B., & Mutilda, A. (2019). A Sty into the Social Engineering Risk in the Public Institutions. Electronic Journal. 1, pp. 1-28. https://www.researchgate.net/publication/333981453.

Kloppenburg, S., & van der Ploeg, I. (2018). Securing Identities: Biometric Technologies and the Enactment of Human Bodily Differences. Science as Culture, 1–20. https://doi.org/10.1080/09505431.2018.1519534.

Malathi, R., & Jeberson, R. (2016). An Integrated Approach of Physical Biometric Authentication System. Procedia Computer science. 85, 820-826. https://doi.org/10.1016/j.procs.2016.05.271

Parsons, D. (2020.). The Impact of Fake News on Company Value: Evidence from The Impact of Fake News on Company Value: Evidence from Tesla and Galena Biopharma Tesla and Galena Biopharma. https://trace.tennessee.edu/cgi/viewcontent.cgi?article=3363&context=utk_chanhonoproj.

Salahdine, F., & Kaaabouch, N. (2019). Social Engineering Attacks: A survey. Future Internet. 11(89), 1-17. https://doi.org/10.3390/fi11040089.

Sarre, R., Lau, L. Y.-C., & Chang, L. Y. C. (2018). Responding to cybercrime: current trends. Police Practice and Research, 19(6), 515–518. https://doi.org/10.1080/15614263.2018.1507888.

The Secure Domain Foundation (2020). Empowering the Internet Community's Fight Against Cybercrime. Securedomain.org. https://securedomain.org/.

Williams, E. J., & Joinson, A. N. (2020). Developing a measure of information seeking about phishing. Journal of Cybersecurity, 6(1). https://doi.org/10.1093/cybsec/tyaa001.