Raj Samani
R E L A T E D   C O N T E N T
Jargon Buster

ADVERTISEMENT

You won't get fooled again

Understanding social engineering and implementing a leak prevention policy is essential, says Raj Samani

Raj Samani, Computing 17 Jul 2008
ADVERTISEMENT

Do you remember the induction you were given when you started your job? From the many presentations paraded before you, do you remember the five-minute talk about the information security function?

There is a general belief that an induction presentation and the occasional email constitute mitigation against a range of threats.

But such a standard approach ­ – which usually concentrates on the risk of being duped into providing information and best practice guidelines on the use of technology ­ – is not good enough.

New employees are often left ill-equipped to deal with professionals who use proven psychological techniques to extract information.

Documents seized by the Information Commissioner’s Office (ICO) provide an insight into the market for unlawful personal data.

In one example, the ICO uncovered “literally thousands” of Section 55 offences, which refers to an area of the Data Protection Act that concerns the wrongful use of personal data.

Such practices generally glean information in one of two ways.

Conscious collusion involves techniques such as financial incentives, blackmail or the threat of violence.

Under such circumstances, the individual marked for the sting is fully aware of what is happening.

In unconscious collusion, the naivety of the mark is exploited. This is referred to as social engineering and is broken into two categories.

First, farming ­ – where the attacker builds a relationship with the mark at the target firm and uses manipulative techniques to extract information. The aim is to milk information over a long period of time.

Second, hunting ­ – the attacker uses manipulative techniques to extract information without establishing a relationship first. The attacker normally performs a single interaction and ends it after getting the data.

The ICO reports that media firms, insurance companies, lenders, creditors, criminals and people involved in matrimonial and family disputes are likely customers for such information.

In many cases, individuals making a request for information will aim to not stand out from normal social interaction.

Social psychologist Robert B Cialdini says there are six basic human compliance tendencies which successful social engineers aim to exploit:

  • Authority ­ – We look to experts to show us the way forward.
  • Liking ­ – The more we like people, the more we say “yes.”
  • Reciprocation – ­ We feel obliged to return favours.
  • Consistency ­ – We act consistently with our commitments and values.
  • Social validation ­ – We look to others to guide our behaviour.
  • Scarcity ­ – The less available a resource, the more we want it.

What can be done to prevent social engineering? Using simple induction courses to mitigate potential threats is not only inadequate but also provides a false sense of security.

Your approach to preventing information leaks should be multi-layered and include a mix of people, process and technology.

The first step is to understand the scale of the problem within your company, so any controls can be tailored to be more effective.

Raj Samani is vice president of communications for ISSA UK and a security consultant at Capgemini

Tags: Strategy

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Berkshire, Reading, United Kingdom | Foster Wheeler
PDS/PDMS Administrator Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & gas, midstream & LNG, refining, petrochemicals & chemicals, pharmaceuticals ... more >
Solihull, United Kingdom | Enzen Global Limited
Business Analyst - £30,000 - £35,000 - Solihull We are in need of a Business Analyst with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas industry in ... more >
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
Head of Technology -Excellent Salary + Car + Benefits - Buckinghamshire Grass Roots is leading player at providing employee reward and benefits solutions to major blue chip companies.   This part of the business has grown ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Buildmaster - Welwyn Garden CityWho's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under £1 ... more >
More job opportunities