Security

Book Review: The Art of Deception: Controlling the Human Element of Security

September 2, 2009, 08:56 AM — 

Using a handful of well understood ploys, a social engineer makes his target want to trust and help him. He gathers just enough information to make him appear to be an insider and plays the "I need help" (sympathy) or "I'm someone you don't want to refuse" (authority) card. Sometimes, social engineers will feign a favor, leading the target to feel obligated to do a favor in return.

Regardless of which particular ploy is used, social engineers work toward getting you to identify with them, play on your natural tendency to trust and take advantage of the "I'm here to help" ethic that, in general, serves us and our organizations well. They play on your unfamiliarity with the rules or your willingness to circumvent the normal controls for the sake of kindness of efficiency.

The Art of Deception brings home just how social engineers work and why they are so good at wrangling highly valuable and clearly proprietary information out of unsuspecting employees -- many of whom never even suspect that they have been duped or that anything has been lost. It dissects enough successful social engineering attacks to demonstrate that it's possible to trick a senior engineer into exposing the source code for the big project, an engineering team into sharing project plans with an imposter "business partner" and a security guard into allowing two teenagers to tour a production plant after hours. The book shows how small amounts of insider information -- sometimes as little as an industry buzzword or manager's name and phone extension -- can give a social engineer an air of legitimacy. It describes how a social engineer might go about making his phone calls appear to be coming from within the building. It demonstrates over and over, how starting with nothing, a social engineer can quickly ramp up to having enough information to con smart people out of valuable information assets.

After reading (actually listening) to this book, I've come away with a renewed sense of the importance of employee security training -- and not just for new employees, but annual training for everyone. Employees need to know that passwords are *never* divulged to anyone and, if they already know this, they need to know what other types of information should never be divulged. They need to understand that verifying the identity of anyone asking for information or asking for some operation to be performed on a computer is critical and be trained on a procedure that verifies that a requester 1) is who he says he is, 2) still works for the organization and 3) has the authority to make the request he is making.

The Art of Deception includes a lengthy section of well thought out policies that should be considered and likely adopted in just about any organization. This book would be worth the price and the time it takes you to read (or listen to) if this were all the book contained, but you might not be as ready to jump on the task if you hadn't read the preceding chapters.

If you don't want your company's information assets given away by well meaning staff, you should read (or listen to) this book. And, if you want to understand how Mitnick and others like him came around to being successful social engineers, read the Wizzywig books I reviewed in http://www.itworld.com/security/67872/wizzywig-volumes-1-phreak-and-2-ha... a while back.

The audiobook is available from audible.com.

Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
peer-to-peer

Esther Schindler
If the comments are ugly, the code is ugly

claird
SVG a graphics format for 21st century

pasmith
Take Chrome OS for a test spin

Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?

sjvn
64-bits of protection?

jfruh
Android fragments vs. the iPhone monolith

mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive

 

Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325

Join the conversation here

The Daily Tip

The Daily TipQuick, practical advice for IT pros. Made fresh daily.

Hot tips:

Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.

Newsletters

Subscribe to ITWORLD TODAY and receive the latest IT news and analysis.

I would like to receive offers via email from ITworld partners.
By clicking submit you agree to the terms and conditions outlined in ITworld's privacy policy.
Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace