The Rumsfeld Matrix as an effective tool in the decision-making process
During a briefing on the Iraq War, Donald Rumsfeld divided information into 4 categories: known known, known unknown, unknown known, unknown unknown. ...
One of the most popular attacks now is social engineering attack. Such attacks help cybercriminals gain effortlessly access to the network. The victim of the attack transfers all the keys into attacker’s hands.
Social engineering in the context of cybersecurity is the process of obtaining people’s personal information by deceiving them. There are many types of social engineering attacks: infected emails with links to malicious sites, a phone call from a cybercriminal who pretends to be a helpdesk and extorts confidential information etc. Social engineering is used not only in the digital realm, but in any other areas where specific information is required from the victim for malicious purposes.
Cybercriminals use social engineering techniques to hide their real identity. To do this, they present themselves as reliable organizations or individuals. The purpose of these actions is to obtain the necessary personal information to access the target network through deception and manipulation. Social engineering is used as the first stage of a major cyberattack to infiltrate a system, install malware, or expose sensitive data. The popularity of the method is due to the implementation ease. It is much easier to undermine cybersecurity using human weaknesses than using network vulnerabilities.
To carry out such an attack, it is necessary to collect targeted information (information about the corporate structure, internal operations, third-party vendors etc.). Public employees’ profiles in social networks can also become a target for malefactors. After data collecting, the cybercriminal chooses his first target to strike. Most often, this target is a low-level employee who is being manipulated into gaining access. It is rarely possible to instantly use confidential resources. Attackers roam the network to discover credentials with a higher level of access. Their activity is usually hidden behind legitimate processes to avoid detection by antivirus.
At the core of all social engineering tactics are aspects of human interaction and decision making known as cognitive biases. Such biases can be called vulnerabilities in human software, which are used to obtain the necessary access.
Basic social engineering principles:
Ways to prevent social engineering attacks: