Advertisement
Co Presented By
Co Presented By

People, Corporates Easily Conned Into Parting With Vital Information

Social Engineering in the IT context refers to the art of using social codes and knowledge of human behaviour to get people to provide sensitive information.

Advertisement
FP Archives|Jan 31, 2017, 02:06:26 IST

Both people and corporate organisations, seldom prepared for attacks targeting human gullibility, find themselves easily conned into parting with vital personal information, according to a new study.

For example, people in Sweden received calls from someone posing as a representative of their bank's IT office. He got them to identify themselves using their personal bank encoders, before using those codes to steal money.

Advertisement

Such attacks are called social engineering in the IT context, which refers to the art of using social codes and knowledge of human behaviour to get us to provide information or do things we should not do.

These kind of attacks are the subject of Marcus Nohlberg's dissertation at Stockholm University in Sweden. "I predicted a couple of years ago that this kind of attack would become common, especially account fraud," he says.

biztechMore from Biztech

Despite serious consequences, with many successful fraud attempts, this technique has received little attention among researchers.

Nohlberg's research has led to enhanced knowledge about what methods attackers use and what it is that makes people and organisations so vulnerable.

Somewhat depressingly, Nohlberg's research shows that information and training do not work as well as we think, said a Stockholm University release.

Advertisement

"The best thing is practical training, and it's probable that organisations will need to start running internal checks where they in fact create fictitious attacks in order to identify weaknesses," said Nohlberg.

Social engineering as a method of fraud is costly for the attacker since it requires commitment and time. However, software and technologies already exist that can interact with other people automatically.

"You can easily imagine how serious it will be when such programmes target victims via digital forums like Facebook in the future. When it becomes just as simple as spreading spam, this will present a major threat to social activities on the Internet," he said. (IANS)

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Jan 19, 2009, 16:19:49 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next