Register TODAY to Save $350 on Security West, Jan 24 - Feb 1 >> More Info
the most trusted source for computer security training, certification and research


A Multi-Level Defense Against Social Engineering

Sandstorm Enterprises, Inc.
Abstract
Social engineering, the process of deceiving people into giving away access or confidential information, is a formidable threat to most secured networks. While there is plenty of information on social engineering, the threat is considered very real and not easily defended. This paper will discuss the basics of social engineering by giving a general overview. It will then discuss the psychological triggers that make social engineering so successful. These triggers include strong affect, overloading, reciprocation, deceptive relationships, diffusion of responsibility and moral duty, authority, and integrity and consistency. Finally, this paper will define a multi-level defense that will address these psychological triggers. The levels of defense that are defined are security policy, security awareness training, resistance training, ongoing reminders, social engineering land mines and incident response. Social engineering land mines (SELM) are procedures or policies that, when implemented, act as an intrusion detection system for social engineering.
<<Reading Room Home     <<Back to Category

Contact us: (301) 654-SANS(7267)
Monday - Friday 9am-8pm EST/EDT