WELCOME
Chào mừng quý vị đến với Blog Tin học PT- CNTT&GD.
Quý vị chưa đăng nhập hoặc chưa đăng ký làm thành viên, vì vậy chưa thể tải được các tư liệu của Thư viện về máy tính của mình.
Nếu chưa đăng ký, hãy đăng ký thành viên tại đây hoặc xem phim hướng dẫn tại đây
Nếu đã đăng ký rồi, quý vị có thể đăng nhập ở ngay ô bên phải.
Module 9 V 3.0

- 0 / 0
(Tài liệu chưa được thẩm định)
Nguồn:
Người gửi: Cao Minh Nhân
Ngày gửi: 11h:00' 03-04-2009
Dung lượng: 3.8 MB
Số lượt tải: 5
Nguồn:
Người gửi: Cao Minh Nhân
Ngày gửi: 11h:00' 03-04-2009
Dung lượng: 3.8 MB
Số lượt tải: 5
Số lượt thích:
0 người
Ethical Hacking
Module IX
Social Engineering
Module Objective
What is Social Engineering?
Common Types of Attacks
Social Engineering by Phone
Dumpster Diving
Online Social Engineering
Reverse Social Engineering
Policies and Procedures
Employee Education
What is Social Engineering?
Social Engineering is the human side of breaking into a corporate network.
Companies with authentication processes, firewalls, virtual private networks and network monitoring software are still wide open to attacks
An employee may unwittingly give away key information in an email or by answering questions over the phone with someone they don`t know or even by talking about a project with co workers at a local pub after hours.
Art of Manipulation.
Social Engineering is the acquisition of sensitive information or inappropriate access privileges by an outsider, based upon building of inappropriate trust relationships with outsiders.
The goal of a social engineer is to trick someone into providing valuable information or access to that information.
It preys on qualities of human nature, such as the desire to be helpful, the tendency to trust people and the fear of getting in trouble.
Human Weakness
People are usually the weakest link in the security chain.
A successful defense depends on having good policies in place and educating employees to follow the policies.
Social Engineering is the hardest form of attack to defend against because it cannot be defended with hardware or software alone.
Common Types of Social Engineering
Social Engineering can be broken into two types: human based and computer based
1. Human-based Social Engineering refers to person to person interaction to retrieve the desired information.
2. Computer based Social Engineering refers to having computer software that attempts to retrieve the desired information.
Human based social engineering techniques can be broadly categorized into:
Impersonation
Posing as Important User
Third-person Approach
Technical Support
In Person
Dumpster Diving
Shoulder Surfing
Human based - Impersonation
Example
Example
Computer Based Social Engineering
These can be divided into the following broad categories:
Mail / IM attachments
Pop-up Windows
Websites / Sweepstakes
Spam Mail
Reverse Social Engineering
More advanced method of gaining illicit information is known as "reverse social engineering"
This is when the hacker creates a persona that appears to be in a position of authority so that employees will ask him for information, rather than the other way around.
The three parts of reverse social engineering attacks are sabotage, advertising and assisting.
Policies and Procedures
Policy is the most critical component to any information security program.
Good policies and procedures are not effective if they are not taught and reinforced to the employees.
They need to be taught to emphasize their importance. After receiving training, the employee should sign a statement acknowledging that they understand the policies.
Security Policies - Checklist
Account Setup
Password change policy
Help desk procedures
Access Privileges
Violations
Employee identification
Privacy Policy
Paper documents
Modems
Physical Access Restrictions
Virus control
Summary
Social Engineering is the human side of breaking into a corporate network.
Social Engineering involves acquiring sensitive information or inappropriate access privileges by an outsider.
Human-based Social Engineering refers to person to person interaction to retrieve the desired information.
Computer based Social Engineering refers to having computer software that attempts to retrieve the desired information
A successful defense depends on having good policies in place and diligent implementation.
Module IX
Social Engineering
Module Objective
What is Social Engineering?
Common Types of Attacks
Social Engineering by Phone
Dumpster Diving
Online Social Engineering
Reverse Social Engineering
Policies and Procedures
Employee Education
What is Social Engineering?
Social Engineering is the human side of breaking into a corporate network.
Companies with authentication processes, firewalls, virtual private networks and network monitoring software are still wide open to attacks
An employee may unwittingly give away key information in an email or by answering questions over the phone with someone they don`t know or even by talking about a project with co workers at a local pub after hours.
Art of Manipulation.
Social Engineering is the acquisition of sensitive information or inappropriate access privileges by an outsider, based upon building of inappropriate trust relationships with outsiders.
The goal of a social engineer is to trick someone into providing valuable information or access to that information.
It preys on qualities of human nature, such as the desire to be helpful, the tendency to trust people and the fear of getting in trouble.
Human Weakness
People are usually the weakest link in the security chain.
A successful defense depends on having good policies in place and educating employees to follow the policies.
Social Engineering is the hardest form of attack to defend against because it cannot be defended with hardware or software alone.
Common Types of Social Engineering
Social Engineering can be broken into two types: human based and computer based
1. Human-based Social Engineering refers to person to person interaction to retrieve the desired information.
2. Computer based Social Engineering refers to having computer software that attempts to retrieve the desired information.
Human based social engineering techniques can be broadly categorized into:
Impersonation
Posing as Important User
Third-person Approach
Technical Support
In Person
Dumpster Diving
Shoulder Surfing
Human based - Impersonation
Example
Example
Computer Based Social Engineering
These can be divided into the following broad categories:
Mail / IM attachments
Pop-up Windows
Websites / Sweepstakes
Spam Mail
Reverse Social Engineering
More advanced method of gaining illicit information is known as "reverse social engineering"
This is when the hacker creates a persona that appears to be in a position of authority so that employees will ask him for information, rather than the other way around.
The three parts of reverse social engineering attacks are sabotage, advertising and assisting.
Policies and Procedures
Policy is the most critical component to any information security program.
Good policies and procedures are not effective if they are not taught and reinforced to the employees.
They need to be taught to emphasize their importance. After receiving training, the employee should sign a statement acknowledging that they understand the policies.
Security Policies - Checklist
Account Setup
Password change policy
Help desk procedures
Access Privileges
Violations
Employee identification
Privacy Policy
Paper documents
Modems
Physical Access Restrictions
Virus control
Summary
Social Engineering is the human side of breaking into a corporate network.
Social Engineering involves acquiring sensitive information or inappropriate access privileges by an outsider.
Human-based Social Engineering refers to person to person interaction to retrieve the desired information.
Computer based Social Engineering refers to having computer software that attempts to retrieve the desired information
A successful defense depends on having good policies in place and diligent implementation.
 





















Các ý kiến mới nhất