الجمعة، 10 أغسطس 2012

Social Engineering Defense


When discussing IT security it is very common to pair up defenses with attacks. Firewalls counter network attacks, anti-virus for viruses, anti-spyware for spyware and so forth. So what is paired up with social engineering? What is the best way to defend against the attacker using deception, lying, and pretexting?
If you read just about any column or article on the topic the universal answer appears to be training. I beg to differ. Are quarterly, half-day training sessions really the best way to get employees to use screen savers and passwords? Is customer education the way to counter phishing attacks? Should you invest in security awareness training?

Social Engineering Podcast



Social engineering, in the context of security, is understood to mean the art ofmanipulating people into performing actions or divulging confidential information.[1] While it is similar to a confidence trick or simple fraud, it is typically trickery or deception for the purpose of information gathering, fraud, or computer system access; in most cases theattacker never comes face-to-face with the victims.

"Social engineering" as an act of psychological manipulation had previously been associated with the social sciences, but its usage has caught on among computer professionals