Home arrow Knowledgebase arrow McKinney Way arrow The Weakest Link
The Weakest Link Print

 

ImageBy Rodney Johnson

President of Prescient Consulting Inc.

 

 

“You could spend a fortune purchasing technology and services...and your network infrastructure could still remain vulnerable to old-fashioned manipulation.” -Kevin Mitnick, most successful and infamous hacker in American digital history

 

We've all learned to ignore emails from Sani Abacha or anyone else purporting to have come into large sums of Nigerian cash. If this was the worst that online or email threats aimed at separating unwary computer users from their money could offer the internet would be a comparatively friendly place. It is not, however. New, more virulent threats are constantly emerging. New or old, the one common denominator with all highly successful attacks is that they focus on the weakest link in the security chain - people. Hackers have denoted this method of attacking a system "social engineering". Social engineering is so successful because it works so well. No matter what the goal of the attacker is it is simply the easiest way to gain access to a computer system or confidential information.

Security systems made to protect computers and networks from assault are designed by PhDs, coded by security experts with master’s degrees, and integrated into business computing environments by skilled technicians trained specifically for that purpose. In this specialized security process the users are often forgotten at the end. The simple sad facts are that the chances of breaking a code built by a math professor are worse than the chances of talking the boss's secretary into revealing her password. If you were an attacker, where would you put it?

Predictably, the bad guys put their energy on attacking people. Technologically attacking a computer or network user requires special skills, knowledge, brains, time, and perseverance. Psychologically attacking the same requires just a little fancy footwork. We've all installed virus checkers, firewalls, and other security software aimed at protecting against technological attacks. No firewall available, indeed, no software available can protect against a people attack. There is no magic bullet. Rather, training and awareness are the only real ways to harden the weakest link.

"Amateurs hack systems. Professionals hack people."

A computer security industry joke has it that the definition of an unsecure computer is one that is turned on. We might as well give up on a technological solution to turn cyberspace into a Utopia where the unsuspecting computer user can roam freely without fear of assault - it will never come. Technology itself doesn't wear a white hat, or a black hat. The advances that serve the good guys are just as easily employed by those with bad intentions. The technological race between those who would attack and those would protect is a never ending one, with one side's advance often being met with a reply from the other side within hours.

Too many organizations, scared off by the scope of the problem have delegated authority and responsibility to the propeller-heads. They then sit back in the false belief they've done all that can be done. In reality, no one can depend on technology to batten down the hatches. No software 'solution' can solve all the computer security problems that haunt us, no matter what the software salesman may say. We can only depend on ourselves. At the end of the day, a computer is as secure as the person using it is aware of and ready to meet the dangers facing him or her.

This One's For All the Marbles.

There are many types of attackers in the computer security area, ranging from light to very heavy in degree of seriousness of the threat they pose to computer users and organizations. The purpose of the attacks also varies from simply accepting the challenge of gaining access to a supposedly 'locked' system to disruption and destruction of systems to theft of money and intellectual property.

 

Just as technological advances are made, advances in social engineering schemes are also being made through trial and error. Even in the web's short life, many schemes have had time to go through several generations and evolve into serious strains. Two recent, particularly damaging schemes, phishing and email blackmail, have become very effective at luring in unsuspecting computer users.

 

By definition, phishing involves "The act of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft." In this case, there are two potential victims - the recipient of the email and the company the attacker is claiming to represent.

 

Email blackmail involves sending an email to a target claiming to already have control of that user's computer and threatening to place child pornography or other incriminating material on the computer and then alert the authorities unless a payment is made to the attacker. Even if the threat is not believed entirely, the requested payment is usually small enough as to be seen as less of a burden than potential search and seizure of a person's computer by police. Email blackmail inside companies creatively turns organizational security policies on their heads by using a person’s fear of being caught and fired for corporate internet and computer usage infractions to extort money from them. It is usually easier to pay some money to the blackmailer than to become the object of suspicion and rumors among management and colleagues - even if the computer is found to be clean.

 

Delivering the Attack

Among computer schemes, phishing and email blackmail have been uncommonly successful. The success of the two schemes is directly correlated with their skill in psychologically pushing the right buttons on their targets. These schemes both use the medium of email, but social engineering attacks can be executed using all kinds of media, from physically showing up in an organization, to using the telephone, online methods, and even dumpster diving.

 

Phone attacks are the most popular form of non-computer-related methods of gaining unauthorized access or information. For phone attacks, an attack's chances of success are made greater the more the caller can appear legitimate. There are many ways to gain the information necessary to make the crucial phone call, some simple and legal, like reading a company's website for names, titles, and phone numbers, and some illegal like dumpster diving, or calling other people in the company in a circle in order to learn progressively more and more. Even the smallest bit of information may give an attacker enough 'clout' to pull off a successful phone attack. Once confident that a call can be made, there is no limit to how creative an attacker can be on the phone, and even senior people who should know better are often taken in.

 

An online example of social engineering would be sending an offer form to the target person requesting they visit a website and sign-up to receive a free gift. Online the user is required to create a membership account and create a password for it. Attackers know that there is a good chance that the password created will be the same password the target uses for many other online accounts they possess. If the attacker is lucky, and the user unlucky, the password the user chooses for the new account will be golden - it will be the same password used for their bank account, office computer, and various personal email accounts. Once access is gained to one person's systems, a flood of confidential information is released potentially valuable for attacks on others.

 

Son, Let Me Show You How It's Done

Attackers have enormous patience. They will often take a long time to get close to the target so as to gain the target's confidence and hopefully become intimate. The attacker will use every psychological trick in the book to create the right mindset in the target to comply with later requests he might have.

 

Phone attacks may include:

Impersonation ("I'm from MIS and..."),

Ingratiation ("I'm coming to you with this because everyone says how capable you are."),

Diffusion of responsibility ("Mr. Jones, SVP in engineering, is asking for this...")

Threatened ostracizing ("You're the only one who's info I don't seem to have..." or "You're the last person on my list."),

Seeming helplessness ("I've got to get this done and really need your help."),

or just being very friendly.

 

On the other hand, email phishing attacks rely on the use of trademarks and images that the target is already familiar with or already trusts. This puts the phishing attack one step ahead of the game. In fact, people who have had their personal information compromised may never even know it. Others may find out there has been a breach, but they may not be able to track it back to where it occurred, still believing the phishing interaction to have been legitimate.

 

Attackers who thrive on social engineering thrive on understanding what people need, want, and will do. Some emails literally beg to be opened. The Love Bug virus was released by targeting the psychological need of its recipients to be loved. 

 

Next Month – "Fighting Back"  your energy?

 

 
< Prev   Next >
Copyright 2006-2008, McKinney Consulting, Inc.
#821 Gwanghwamun Officia Bldg., 163 Shinmunno 1-Ga, Jongno-Gu, Seoul, 110-999, Korea
TEL: +82.2.725.3830, FAX: +82.2.725.3802, EMAIL: business@mckinneyconsulting.com
80rfskihhr6alapha blueblood bulldog effects of mixing risperdal with zoloft baby sitter masturbate 2006 jeep commander lean adjustable ecu aic imperial 500 000 guaranteed visitors bon voyage anything goes adjustment disorder with mixed emotional features 2002 plush cherrished teddies chilis kendall drive antenna cell flashing motorola phone v180 20 person rotating schedule 4x4 evolution requirements 1962 vw front end 2.24 sacred trainer underworld 175 s range colby ks 67701 difficult airway management emt acrylic binding vs satin cooks baking supply west allis animated gifs chicken hen rooster asymetrical hair cuts for women 2007 fleetwood discovery motorhome 4-ingredient diabetic cookbook alternate deposit methods online casinos 10 code police across body handbags boise home inspector charmed chris wyatt fanfiction 110 card stock pin feed easy layered biscuit recipes beauty college wausau wi a pizza stayton or 50 carmel glaze loreal andrea collier king website 1796 light cavalry sword deaf dominatrix madtv apple pigeon forge tn 1-888 meditub 633-4882 address 0x800c0019 error and fix 1994 lexus es300 blown motor .223 green tip captain robert holt usn retired banker beacon coldwell realty bulgarian translations agarose base pair range 4 mm cyst in breast aero grow garden kit aeg american express bon jovi presale blogathon blogging for a cure caps and home infusion 2007 derby post positions archies clyde did it braes of fife actors agents ireland circumcision and cervical cancer car insurance hagerstown md coffee banana peanut butter smoothie bolens mtd cultivator a to z hobbies model rockets arranging fractions least to greatest 09 this love mp3 7324 sw freeway houston texas black emo backround bendix tru flo 550 aimer arena download jusqua limpossible tina bike and gary fischer and tarpon 400 n lake shore drive add stealing frisbee by the masters california pantry classic ceramic muggs ar10 grip od green cheapest airfars cheapest airfares oman a friend in need lyrics placebo 1300 am baltimore agriculture and education anti spy ware free cnet dbz quizes army recruiter polk county fl 10x10 pe gazebo biscayne bay abortion rights coalition of canada blueberry pie filling congealed salad andrus family travels adult superhero footed pajamas fixed income housing in hoboken nj bdsm street fairs amazon com cradle bedding bedding baby elvis presley frankie 1 kelsey road st pauls cray a scenic attraction in bankok afn podcast 12v com apct refrigerator rv airforce and marijuana ashtabula house pendleton sc 4 winds interactive doppler heartbeat ranges asia pacifics phuket aunty lou im gonna fuck activities for kindergarten children 2007 feng fax numbers bait launcher .22 commando tactical quad rail system 44 by nucleus poker powered remember biofeedback music hypertension 16x32 inground pool liner dennis banks longest walk 2008 1963 fairlane hobby toy betty winslow 400 drink machine vision aloha airlines flight 243 photo 1995 pontiac bonneville service brendan benson 8 bacillus subtilis race molecular weight bc glory engineered wood floor aphabet bingo absolute value and or statements aquifer information plains cala nova ibiza alvin and the chimpunks chirstmas sonf achromycin give with milk a blizzard bathroom remodeling hubbard tx actress kristin thomas 10t6 tv arthur morton eos russia fond brandon and marianne stories disney princess magical throne basement slab waterproofing are airbags dangerous 105 opal st walterboro sc bobs outdoor sportswear complete concordance to miscellaneous writings check air india partners arc 1701 family handyman magazine web site 07 avalanche water leak 3 recommendations avoid negligent hiring american dj dr dmx 15v dual power supply 2006 united states government employees ets springboard walkthroughs a1 tank nicknames body smash training flex chase durer typhoon 1980 s dude ranches california alyssa tower om blizzard 1917 1858 remington pistol birdie ashcraft niles michigan astrology reading tarot relationships accommodation dublin serviced amd 64 heat sinks dolce amp gabbana shoes adventure cheat four sword zelda 2006 care conference wound 105mm self propelled gun rca 121 flight plane snake crime stopper safety tips 761 ch des sources montreal qc 50 000 signature loan claude alexander dance 98 infinity 340 b drug pricing adding to my network places billow cremation services akron ohio act american diagram disability airedale breeders california dog in terrier barcode recognition systems for laptops be a man hulk 5 gallon quick dry cement captain scarlet and the mysterons army jag internship agricultural pollution due to pesticides 401k pasco county biomechanics relative phase analysis 8407 appalachian dr caloric stimulation for unilateral neglect 1960s pepsi logo 10 trends windows images tips top converting a drive to ntfs dragon quest monsters joker synthesizing guide all-american rejects ends tonight 50 largest colleges 1905 men nurse training 55 communities in kentucky aluminum compass charm 231233330 cell free nokia phone air tatum thong hacked by powerful analysis sir philip sidney sonnet 31 4 tier pineapple fountain corey aldridge 2 blue controller dualshock ps2 sony 206 shiloh station 62269 cape breton pork pies boris vallejo girl pics anchor resorts destin alojamiento en punta del este activites to do in madrid spain bahrain bars f1 2002 and 1977 ncaa championship game bleachers chapter summaries absenttee vote in jackson co missouri atrazine selectively toxicity weeds not corn claudia maurice green barry fruendel homosexuality 2006 3 month calendar free templates 6 round sofa leg set 2001 auto center arlington heights diana l fritz appleton wi trane granny is a hippie arts beats ans eats acute megakaryoblastic leukemia survivors aerobics for great legs boethius de musica afroman nobody knows your name 10 vent hood wall cap ada showers and supplies diversified arts chatsworth california box ea live sports x 22 mag banana clip 18 volt cordless drils 24 top load washing aircraft inventory systems adavantages nic accent pillow shapes dr zeus mp3 wma african adventures uninstall issue carbamazepine and minors bebo is blocked absence seizures and l taurine anet morales manila adjusted serum calcium level ctdirect magazine tomb editorial slippery slope 108th div it unit crest bollinger band squeeze amibroker agrizzi enterprises corp husqvarna 1 embroider cheap magazine subscriptions m ernie alderete 1000w amplifier audio circuit diagram fin inn grafton il 24 hour military clocks compatibility matches of signs 2009 ford gt 350 sr af chiefs 10meg free sex vids ames 202 dial indicator 1500 john f kennedy blvd alcoholism and gender genetics alpine cda 9853 eq access boardwalk chevrolet