In cyberspace, the user has become the system’s biggest vulnerability. Social engineering has become a prevalent technique for cyber attackers, as 98 % of cyber attacks rely on it. Social engineering is designed to rely on human vulnerability when exploiting system security. Thus, attackers can obtain critical intrusion information without extensive technical input. Social engineering is a big concern for companies, as attackers target employees to attack information resources in an organization.
This diploma presents forms of social engineering and attack mechanisms that describe how attackers exploit human traits to access sensitive data. Human vulnerabilities are also presented or how certain human characteristics increase the vulnerability of a specific person.
A questionnaire was also conducted where 60 people of different ages and educational backgrounds answered questions about social engineering. The purpose of the study was to find out how aware people are of social engineering attacks and how they would react in certain situations described in the questions.
Finally, there is an example of a test phishing attack that was sent to 20 people. The email included a suspicious link that allegedly led to a page of a popular social network.
|