Social Engineering & Phishing Platform: Difference between revisions
No edit summary |
(was duplicate to "Social Engineering". Merged both together and left the Phishing Exercises) |
||
| (3 intermediate revisions by one other user not shown) | |||
| Line 1: | Line 1: | ||
== Social Engineering == | == Social Engineering == | ||
[[Social Engineering]] is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information. | |||
==Mail Phishing Exercise== | ==Mail Phishing Exercise== | ||
The exercise "Mail Phishing" is designed to educate users about the risks | The exercise "Mail Phishing" is designed to educate users about the risks associated with freely available personal information. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks, thus highlighting the necessity for cautious communication in work environments. | ||
[[File:Mail.PNG]] | [[File:Mail.PNG]] | ||
===Purpose=== | ===Purpose=== | ||
;Raise Awareness | ;Raise Awareness: | ||
: By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online. | : By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online. | ||
;Educate about Phishing | ;Educate about Phishing: | ||
: Through experiencing the | : Through experiencing the attacker's perspective, participants learn about the tactics used by cybercriminals. | ||
;Promote Alertness | ;Promote Alertness: | ||
: The exercise | : The exercise highlights the importance of exercising caution when sharing online. | ||
===Scenario=== | ===Scenario=== | ||
The | The exercise aims to personalize an email to an employee, faking familiarity. It begins with users being prompted to access publicly available social media data to gather information about the fictional individual. | ||
Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron's employee ID and department. The | Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron's employee ID and department. The email seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details. | ||
If participants successfully fill in Cameron's employee ID | If participants successfully fill in Cameron's employee ID, they "win" the exercise. In the case of a successful spoof, the user receives a short text explaining the tactics behind this attack, highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts. | ||
===Lessons=== | ===Lessons=== | ||
| Line 79: | Line 26: | ||
#Developing critical thinking skills to discern legitimate communication from potential phishing attempts. | #Developing critical thinking skills to discern legitimate communication from potential phishing attempts. | ||
#Implementing best practices for safeguarding sensitive information in online interactions. | #Implementing best practices for safeguarding sensitive information in online interactions. | ||
== Shoulder Surfing Exercise == | |||
==Shoulder Surfing Exercise== | The exercise "Shoulder Surfing" is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker's password and user. | ||
The | |||
[[File:Shoulder.PNG]] | [[File:Shoulder.PNG]] | ||
===Purpose=== | === Purpose === | ||
;Highlighting the Simplicity of Shoulder Surfing | ; Highlighting the Simplicity of Shoulder Surfing: | ||
: By simulating a scenario where participants attempt to obtain a coworker's password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information. | : By simulating a scenario where participants attempt to obtain a coworker's password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information. | ||
; | ; Promoting Good Password Hygiene: | ||
: Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one's surroundings. | : Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one's surroundings. | ||
; | ; Raising Awareness about Password Complexity: | ||
: The exercise encourages participants to consider their password choices. | : The exercise encourages participants to consider their password choices. | ||
===Scenario=== | === Scenario === | ||
The exercise aims to figure out the identity of a coworker by | The exercise aims to figure out the identity of a coworker by "hacking" a web page. It begins with participants suspecting a coworker of stealing a project and needing evidence to confirm their suspicions. Participants are tasked with extracting information based on the work environment and a shoulder surfing snapshot. Using the observed information, participants attempt to access the coworker's given data on the site. Once participants successfully "hack" the profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario. | ||
Using the observed information, participants attempt to | |||
Once participants successfully | |||
===Learning Objectives=== | ===Learning Objectives=== | ||
| Line 110: | Line 54: | ||
== References == | == References == | ||
* C. Hadnagy, Social Engineering: The Science of Human Hacking. Wiley, 2010. | |||
* K. D. Mitnick, The Art of Deception. Wiley, 2002. | |||
* N. Y. Conteh and P. J. Schmick, “Cybersecurity:risks, vulnerabilities and countermeasures to prevent social engineering attacks,” 2016. [Online]. Available: https://api.semanticscholar.org/CorpusID:70178926 | |||
* R. B. Cialdini, Influence: The Psychology of Persuasion. HarperBusiness, 2006. | |||
* R. Salama, F. Al-Turjman, S. Bhatla, and S. P. Yadav, “Social engineering attack types and prevention techniques- a survey,” in 2023 International Conference on Computational Intelligence, Communication Technology and Networking CICTN), 2023, pp.817–820. | |||
[[Category:Documentation]] | [[Category:Documentation]] | ||
Latest revision as of 17:41, 18 December 2024
Social Engineering
Social Engineering is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.
Mail Phishing Exercise
The exercise "Mail Phishing" is designed to educate users about the risks associated with freely available personal information. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks, thus highlighting the necessity for cautious communication in work environments.
Purpose
- Raise Awareness
- By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online.
- Educate about Phishing
- Through experiencing the attacker's perspective, participants learn about the tactics used by cybercriminals.
- Promote Alertness
- The exercise highlights the importance of exercising caution when sharing online.
Scenario
The exercise aims to personalize an email to an employee, faking familiarity. It begins with users being prompted to access publicly available social media data to gather information about the fictional individual. Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron's employee ID and department. The email seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details. If participants successfully fill in Cameron's employee ID, they "win" the exercise. In the case of a successful spoof, the user receives a short text explaining the tactics behind this attack, highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts.
Lessons
- Recognizing the risks associated with freely available personal information on social media.
- Understanding the tactics employed in phishing attacks and how they exploit human psychology.
- Developing critical thinking skills to discern legitimate communication from potential phishing attempts.
- Implementing best practices for safeguarding sensitive information in online interactions.
Shoulder Surfing Exercise
The exercise "Shoulder Surfing" is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker's password and user.
Purpose
- Highlighting the Simplicity of Shoulder Surfing
- By simulating a scenario where participants attempt to obtain a coworker's password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information.
- Promoting Good Password Hygiene
- Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one's surroundings.
- Raising Awareness about Password Complexity
- The exercise encourages participants to consider their password choices.
Scenario
The exercise aims to figure out the identity of a coworker by "hacking" a web page. It begins with participants suspecting a coworker of stealing a project and needing evidence to confirm their suspicions. Participants are tasked with extracting information based on the work environment and a shoulder surfing snapshot. Using the observed information, participants attempt to access the coworker's given data on the site. Once participants successfully "hack" the profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario.
Learning Objectives
- Understanding the risks associated with shoulder surfing and unauthorized access to sensitive information.
- The importance of using strong, unique passwords to protect personal and professional accounts.
- Developing critical thinking skills to identify potential security vulnerabilities in password practices.
- Promoting a culture of security awareness and personal responsibility in safeguarding sensitive data.
The Project
References
- C. Hadnagy, Social Engineering: The Science of Human Hacking. Wiley, 2010.
- K. D. Mitnick, The Art of Deception. Wiley, 2002.
- N. Y. Conteh and P. J. Schmick, “Cybersecurity:risks, vulnerabilities and countermeasures to prevent social engineering attacks,” 2016. [Online]. Available: https://api.semanticscholar.org/CorpusID:70178926
- R. B. Cialdini, Influence: The Psychology of Persuasion. HarperBusiness, 2006.
- R. Salama, F. Al-Turjman, S. Bhatla, and S. P. Yadav, “Social engineering attack types and prevention techniques- a survey,” in 2023 International Conference on Computational Intelligence, Communication Technology and Networking CICTN), 2023, pp.817–820.