Social engineering

Attacks on the 'human factor'

Users are a popular target for hackers. Criminals even prefer the so-called 'human factor' to technology when they want to gain access to sensitive information without being detected. Encryption methods and other technical defences have made it more difficult for hackers to breach systems. Finding and exploiting a security vulnerability often requires a significant investment of time and computing power. In contrast, "it is often child's play to crack the human firewall. This requires … no investment and involves only minimal risk." [1]

The most commonly used attack technique targeting people

is social engineering. Social engineering is a form of targeted manipulation. The attackers (the social engineers) influence their victims in such a way that they act in the attackers' interests and, for example, disclose information. Often, the victims are completely unaware of this attack. Tampered USB sticks or phishing emails are typical forms of social engineering. A USB stick left behind is designed to arouse the finder's curiosity or prompt them to help. They connect the USB stick to their computer to see what's on it – and malware is immediately installed. A phishing e-mail, for example, aims to trick recipients into entering their login details or credit card numbers on the attackers' website.

However, gathering specific information to prepare for an attack is also part of social engineering. Even seemingly innocuous questions, targeted research into organisational structures, and points of contact on social media, or documents carelessly discarded can help social engineers get closer to their goal.

In social engineering, attackers often pretend to be someone else: the boss on a business trip, the helpful IT administrator, an interested research partner, or the intern seeking help. The attackers contact their victims by e-mail or telephone and tell a fabricated story. For example, the supposed IT administrator needs a password or access to a computer; the fictitious intern urgently needs a printout; or the supposed boss needs an immediate bank transfer to a foreign account to save the company’s reputation.

Social engineers are well versed in psychology. They understand how people 'work' and are able to influence them to their own advantage. For example, people tend to trust figures of authority almost blindly and do not necessarily question their decisions. Social engineers deliberately exploit these ingrained behaviours.

Social engineers typically make use of the following five psychological principles in their manipulations [2, 3]:

Authority

People follow instructions from figures of authority such as teachers, parents, police officers, doctors, or bosses, and do not question them. (Perceived) authority can also be established through titles, clothing, or status symbols. Phishing e-mails in which recipients are asked by their bank to enter their login details on a website for identity verification make use of this principle.

Social proof

Particularly in unfamiliar situations, people tend to imitate the behaviour of others. They do not want to attract attention through inappropriate behaviour. To convince victims of the legitimacy of their request, social engineers pretend that many other people – particularly friends or colleagues – have already complied with their request. The information they have previously gathered about organisational structures helps them achieve this goal.

Sympathy, similarity & deception

People are more willing to grant requests from friends than those from strangers. However, this principle also applies when the person making the request is known to the victims, or is likeable, attractive, or similar to them. Social engineers therefore try to manipulate their victims into liking them. A popular method for doing this is to pay compliments and feign common ground, such as shared hobbies or holiday destinations. Points of connection are easy to identify through prior research on social media.

Commitment, reciprocity & consistency

Once people have made a decision, they feel obliged to stick to it until the (bitter) end. They will therefore willingly comply with requests that are consistent with their decision. So once social engineers have managed to elicit even the smallest piece of information from their victims, the victims will be more willing to respond to further enquiries. Furthermore, society expects people to return favours they have received. If victims receive a gift from the attackers – even just a bar of chocolate or a can of cola will do – they feel socially obliged to give something back to the attackers, even if it is just a piece of information.

Distraction

People have a limited capacity to process incoming information. They therefore try to focus on what they perceive to be the most important facts and ignore everything else. Social engineers exploit this by distracting their victims. People can be distracted by, amongst other things, an overload of information, surprises, curiosity, desires and longings, time pressure, fear, greed and scarcity. A typical means of distraction is the use of supposed competitions or time-limited offers. The USB sticks 'lost' by the social engineer arouse the curiosity of those who find them, thereby exploiting this principle.

Social engineers usually combine several of these five principles in a single attack. In the case of a phishing e-mail, time pressure (distraction) often plays a role alongside authority.

The good news is that simply being aware of these psychological manipulation techniques used by social engineers helps you to protect yourself against their attacks. However, even professionals are not immune to social engineering attacks, and it is often very difficult to spot an attack.

Here are a few tips on what you can do:

·        Be vigilant! If something sounds too good to be true, it probably is.

·        Ask for clarification! If you receive an unexpected or unusual e-mail, call the sender to check it out or ask them to come and see you in person.

·        Stay sceptical! Even seemingly harmless questions about contact persons, organisational structures or IT equipment help social engineers to prepare their attacks.

·        Be careful! Only accept friend requests from people you actually know.

·        Take your time! Think carefully about your response to a request, even if pressure is being put on you, and ask for time to consider it.

·        Stick to the guidelines! Insist on compliance with internal rules and regulations. These are often designed to thwart the tricks of social engineers, and no one can blame you for this.

·        Be discreet! Only share the bare minimum of information on social media, do not discuss business matters in public, and never (ever!) give your password to anyone.

·        Get in touch! If something seems suspicious or you fear you may have fallen victim to a social engineering attack, contact the IT Helpdesk.

Contact

If you have fallen victim to social engineering, or even if you merely suspect that you have, do not hesitate to contact the ITSC immediately.

Sources

1.          Mitnick, K.D., Simon, W.L.: The Art of Deception: Controlling the Human Element of Security. John Wiley & Sons, Inc., New York, NY, USA (2002).

2.         Cialdini, R.B.: Influence: the psychology of persuasion. Collins, New York, NY (2007).

3.         Ferreira, A., Coventry, L., Lenzini, G.: Principles of persuasion in social engineering and their use in phishing. In: International Conference on Human Aspects of Information Security, Privacy, and Trust. pp. 36–47. Springer (2015).