Social Engineering

Social engineering is information security discusses to psychological manipulation of people into performing actions or telling private information. Social engineering is an attack direction that depends on seriously on human interaction and regularly involves manipulating people into breaking normal security actions and best practices to improve access to systems,networkand locations. The first step in most social engineering attacks is for the attacker to perform research and investigation on the target. If the target is an enterprise, for example, the hacker may gather intelligence on the employee building, internal operations, shared lingo used within the industry and possible business partners, among other information. Most common of social engineers is to focus on the behaviours and forms of employees with low level but opening access, such as a security guard or receptionist. Some Hackers can take photograph the person’s social media profiles for information and watching their conversation online and listen to their talking. (Anderson, Ross J, 2008)

For example, the attacker might pretend to be an employer who has a crucial problem that needs access to added network resources.

Types of social engineering:

  • PhishingPhishing is when a malicious party sends a fake email disguised as a real email, often claiming to be from a trusted source. The message is meant to trick the recipient into sharing personal and financial information.
  • Honey trap: An attack is using the social engineer pretends to be an attractive person to interact with a person online and using the fake picture and fake ID name and gather searching information through that relationship like a family, friend and employer

Social Engineering Recommendations:  

  • Do not open any emails and text from unknown sources– make sure to contact your friend and family member in person or the phone. if you ever receive an email message that is not from your friends and An easier way to block them.

Return to table of contents