July 22, 2005

Hacker Mitnick preaches social engineering awareness

Mitnick says people are the weakest link and organizations must build 'human firewall'

SYDNEY -- Properly trained staff, not technology, is the best protection against social engineering attacks on sensitive information, according to security consultant and celebrity hacker Kevin Mitnick.

"People are used to having a technology solution [but] social engineering bypasses all technologies, including firewalls," Mitnick said. "Technology is critical but we have to look at people and processes. Social engineering is a form of hacking that uses influence tactics."

During his keynote address at this year's Citrix iForum conference in Sydney Thursday, Mitnick said hackers are analyzing the "bigger picture" and are looking for the weakest link, which is "people like you and me".

"Why do hackers use social engineering? It's easier than exploiting a technology vulnerability," he said. "You can't go and download a Windows update for stupidity... or gullibility."

Mitnick said social engineering appeals to hackers because the Internet is so widespread, it evades all intrusion detection systems, it's free or very low cost, it's low risk, it works on every operating system, leaves no audit trail, is nearly 100 percent effective, and there is a general lack of awareness of the problem.

"Social engineering attacks can be simple or complex and take from minutes to years," he said, adding that surveys have revealed that nine out of 10 people will give their password in exchange for a chocolate Easter egg.

Mitnick spoke of how social engineering has been used to extract millions of dollars from banks and how he used the technique to siphon source code for a mobile phone out of Motorola by posing as an employee in its own R&D department.

Mitnick also mentioned how he is not immune to the social engineering scourge and was sent an e-mail 'phishing' for information from his PayPal account earlier this year.

"The attacks are real and the threat is real so I encourage everyone to do something about it," he said, adding the main target is the helpdesk because "it's there to help".

Pretexting, where the hacker takes on an acting role, is the heart of social engineering, Mitnick said, because people need reasonable justification to fulfill a request.

Hackers establish an identity and role, build a rapport through linking or other influence tactics, and leave an "out" to avoid "burning" the source.

Intelligence gathering exercises may include seeking titles of company positions so hackers know who to target, and good old "dumpster diving" where the company's garbage is screened for information.

Mitnick said even large companies participate in dumpster diving, as Oracle was recently caught sifting through Microsoft's garbage. When Mitnick was 17, he did some dumpster diving and found an employee directory and source code in piles of rubbish.

To combat social engineering attacks, Mitnick said organizations need to build a "human firewall" and fill existing holes such as illusions of invulnerability. "It can happen to anyone," he said. "People naturally want to help people and underestimate the value of information."

Mitigation techniques begin with top management buy-in and demonstrating personal vulnerability.

"Establish an employee participation program," he said. "Develop simple rules to define what is sensitive information [and] build a human firewall by raising awareness."

Mitnick recommends performing social engineering pen-tests, and not forgetting the periodic dumpster diving, and modifying the organization's politeness norms - "it's OK to say No!

"Use technology to remove employee decision making," he said. "The big challenge is to balance productivity and sensitivity."

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.