Monthly Archives: November 2014

Infosecurity Magazine Social Engineering Webinar

We have posted a webinar by infosecurity magazine on our Film Festival page.  Look near the bottom of the page.

The security experts discuss how easy it is to deceive people.  They make the point that given a choice between infiltration by technical means  and attacking people, attacking people with social engineering is the attack of choice because it is fast, easy and has a high probability of success.

The attackers are targeting users to infiltrate systems. Users need tools that assist them in identifying cleverly constructed spearphishing emails. That is the function of SP Guard.

State Department Compromised

It is being widely reported in the press that the US State Department has been compromised in a cyberattack.

 

Truman Building

US State Department

USA Today  reports that although no classified information was  compromised, the attack has forced the State Department to take down its unclassified email system. USA Today reports:

To learn that additional government agencies beyond the White House were attacked, “is not at all surprising,” said Rick Holland, a principal analyst and cybersecurity expert at Forrester Research. “What is surprising is that we are two weeks into it and it’s just now coming out. Likely, the attacker is using the same type of technique to break into these networks and maybe through an investigation (the State Department) just learned that it was worse.”

How could this happen?  Holland discussed this in a Federal Times interview:

“This year in particular, it seems overwhelming,” he said. “It indicates how easy it is to break into these environments.”

Judging from the fact that State Department email was shut down to remediate the breach, Holland posited that the attack was likely in the form of spear-phishing, in which a specially tailored email is sent to someone within an organization to prompt them to click through.

This tactic is often seen in cyber espionage, he said, and can be incredibly effective.

“Even for us cybersecurity guys, if we get a well-crafted email we might click on it,” he admitted. “Security awareness and training has a component … But ultimately it comes down to agencies themselves to have situational awareness — the ability for quick detection and response.”

Regrettably, situational awareness is not the hallmark of email.  The three Carronade studies at West Point showed that people did a poor job processing email. In “Why do people get phished?”, researchers led by Prof. Arun Vishwanath explored the detailed psychology of spearphishing and concluded that the way the human mind works makes people very susceptible to spearphishing attacks.

The attackers are targeting users to infiltrate systems. Users need tools that assist them in identifying cleverly constructed spearphishing emails. That is the function of SP Guard.

Google Discovers — People

Google, in association with the University of California, San Diego, has released research which analyses spearphishing attacks against gmail accounts from 2011-2014.

The researchers found that the success of a spearphishing attacks ranged from a low of 3% to a high of 45%.  The researchers determined that the greater the effort put into the targeting of the message, the higher the probability of a successful attack.

google chart

The researchers made this observation regarding financial scam attacks:

Thus, despite the appearance of simplicity, in reality, the scam emails are well-formed and thought-out in a way to maximize efficiency by preying on known human physiological

[sic] [recte psychological] principles.

They also noted:

Targeted attacks include industrial espionage and state-sponsored break-ins. In our experience, these attacks are carried out by highly sophisticated parties who have the resources to extensive profile targets and launch tailored attacks.

The attackers target the people! And the better the message is crafted to the sensibilities of the target, the more likely the success of the attack. While many call this “social engineering,” at Iconix we prefer the old-fashioned term “deception” –  for “deception” makes it clear that this is not a computer engineering problem, this is a problem of people deceiving people.  The attackers are not  using IT engineering tools, but are engaging operations that are “well-formed and thought-out in a way to maximize efficiency by preying on known human physiological principles.”

The attackers use deception.  The defenders need to fight deception.  This is the purpose of Truemark and SP Guard from Iconix.