Chapter 7

Social Engineering

Valerie Thomas    Securicon, Lorton, VA, USA

Abstract

A common misconception is that all attacks are purely technical in nature. Social engineering is the art of gaining trust or acceptance in order to persuade someone to provide information or perform an action to benefit the attacker. The attacker then combines the newly acquired information, which is usually obtained through research and multiple attacks, with a technical attack to produce a result that is disastrous to the target.

Keywords

Social engineering

Phishing

Spear phishing

Dumpster diving

Deception

What is Social Engineering?

“Nice weather we're having,” Mark said with a grin as he flicked his lighter to the cigarette in his mouth while struggling ...

Get Building an Information Security Awareness Program now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.