Social Engineering

Tenets of Social Engineering

How it works

  1. Phishing
  2. Pretexting
  3. Baiting
  4. Tailgating
  5. Quid Pro Quo
  6. Whaling

Social Engineering in Computer Security

Definition

In computer security, social engineering is used to denote a non-technical type of intrusion that exploits human behavior. Typically, it heavily relies on human interaction and often involves tricking other people into breaking normal security procedures.

How Social Engineering Works

A social engineer runs a "con game" to break security procedures. For example, an attacker using social engineering to break into a computer network might try to gain the trust of the authorized user to access the target network and then extract information to compromise network security. Social engineering is, in effect, a run-through used to procure confidential information by deceiving or swaying people.

An attacker can disguise himself or herself as a user or system administrator to obtain the user's password.

Exploiting Human Nature

Social engineers exploit the fact that people, in general, try to build amicable relationships with their friends and colleagues and tend to be helpful and trusting. Another trait of social engineering relies on the inability of people to keep up with a culture that relies heavily on information technology.

Most people are unaware of the value of the information they possess, and as such, only a handful care about protecting their information.

Information Gathering Tactics

Social engineers typically search dumpsters to acquire valuable information. Furthermore, social engineers find it more challenging to obtain the combination to a safe or a health-club locker, as compared to the case of a password.

Defense and Mitigation

The best defense is to educate, train, and create awareness about this attack and the value of information.