Learning Objective 1.1.A: Identify common indicators of social engineering tactics.
- 1.1.A.1 Social engineering attacks employ psychological tactics to manipulate users into revealing sensitive information (elicitation), downloading a malicious file, or clicking on a malicious link. Social engineering can be performed in person but is often done by email, by text message, or through social media messages.
- 1.1.A.2 Adversaries often use psychological tactics like intimidation and urgency to achieve their goals. Intimidation is when an adversary threatens a target with negative consequences if they don’t comply. Urgency is when an adversary creates reasons why a target should act quickly.
Learning Objective 1.1.B: Explain how social engineering tactics influence victims to perform a desired action.
- 1.1.B.1 Social engineering tactics rely on common psychological principles that influence human behavior.
- 1.1.B.2 Intimidation leverages a natural human aversion to negative consequences. By drawing attention to possible negative consequences, adversaries use fear to incite targets to act.
- 1.1.B.3 Urgency leverages a natural human response to react quickly to time-sensitive needs. When targets detect a sense of urgency in a message, they feel pressured to respond or act quickly, which can prevent them from taking the time to consider whether an action is reasonable or safe.
Learning Objective 1.1.C: Describe possible impacts for victims of social engineering attacks.
- 1.1.C.1 Victims may give an adversary personal information that could lead to impersonation, such as name, phone number, address, workplace, pets’ names, or birthdate. These types of information, and information like them, are often used on websites as challenge questions to verify a user’s identity.
- 1.1.C.2 Victims may give an adversary secure information like a one-time password (OTP) or authentication login code, which could allow an adversary to log in to a service as the victim.
- 1.1.C.3 Victims may download malware or click a link that installs malware on their device, steals information from their web browser, or directs them to a website where their login credentials can be captured by an adversary.
מטרת לימוד 1.1.A: זיהוי סימנים נפוצים של טקטיקות הנדסה חברתית.
- 1.1.A.1 התקפות הנדסה חברתית משתמשות בטכניקות פסיכולוגיות כדי להניע משתמשים לחשוף מידע רגיש (הוצאת מידע), להוריד קובץ רע או ללחוץ על קישור רע. הנדסה חברתית יכולה להתבצע בפנים אך לרוב נעשית באמצעות דוא"ל, הודעות טקסט או הודעות ברשתות חברתיות.
- 1.1.A.2 מתקיפים משתמשים לעיתים קרובות בטכניקות פסיכולוגיות כמו הפחד ודחיפות כדי להשיג את מטרתם. הפחד מתרחש כאשר המתקיף מאיים על היעד בתוצאות שליליות אם הוא לא יעשה כפי שנתבקש. דחיפות מתרחשת כאשר המתקיף יוצר סיבות לכך שהיעדaction quickly.
מטרת למידה 1.1.B: הסבר כיצד טקטיקות הנדלן חברתי משפיעות על קורבנות כדי לבצע פעולה רצויה.
- 1.1.B.1 טקטיקות הנדלן חברתי מתבססות על עקרונות פסיכולוגיים נפוצים המשפיעים על התנהגות אנושית.
- 1.1.B.2 אינטimidation (הערכה) מנצלת סירוב טבעי של בני אדם לתוצאות שליליות. על ידי משיכת תשומת לב לתוצאות שליליות אפשריות, אויבים משתמשים בחשש כדי לגרם ליעדים לפעול.
- 1.1.B.3 דחיפות מנצלת תגובה אנושית טבעית להגיב במהירות לצרכים התלויים בזמן. כאשר יעדים מזהים תחושת דחיפות בהודעה, הם מרגישים לחץ להגיב או לפעול במהירות, מה שיכול למנוע מהם לקחת זמן לשקול האם פעולה היא סבירה או בטוחה.
מטרת למידה 1.1.C: תיאור השפעות אפשריות עבור קורבנות של התקפות הנדלן חברתי.
- 1.1.C.1 הקורבנות עשויים לתת לאויב מידע אישי שיכול להוביל להסתגר, כמו שם, מספר טלפון, כתובת, מקום עבודה, שמות חיות מחמד או תאריך לידה. סוגי מידע אלו, ומידע דומה, משמשים לעיתים קרובות באתרי אינטרנט כשאלות בדיקה כדי לאמת זהות משתמש.
- 1.1.C.2 הקורבנות עשויים לתת לאויב מידע מאובטח כמו סיסמת חד-פעמית (OTP) או קוד הזדהות, שיכול לאפשר לאויב להתחבר לשירות כקורban.
- 1.1.C.3 הקורבנות עשויים להוריד תוכנת רוע או ללחוץ על קישור המניח תוכנת רוע על ההתקן שלהם, גנבת מידע מדפדפן האינטרנט שלהם, או הפנייתם לאתר אינטרנט בו את פרטי ההזדהות שלהם יכולים להיות נתפסים על ידי אויב.
