OPSEC and defense agains social engineering for devels, execs, and sart-ups
Mg.sc.comp. Kirils Solovjovs Possible Security @KirilsSolovjovs on twitter http://kirils.org for more
OPSEC and defense agains social engineering for devels, execs, and - - PowerPoint PPT Presentation
OPSEC and defense agains social engineering for devels, execs, and sart-ups @KirilsSolovjovs on twitter Mg.sc.comp. Kirils Solovjovs http://kirils.org for more Possible Security Contents Problem: Social Engineering concepts
Mg.sc.comp. Kirils Solovjovs Possible Security @KirilsSolovjovs on twitter http://kirils.org for more
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 2/23
– concepts – attacks
– theory – practice
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 3/23
This is how hackers hack you using simple social engineering https://www.youtube.com/watch?v=lc7scxvKQOo
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 4/23
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 5/23
is the use of deception to manipulate individuals into divulging sensitive information that may be used for illegitimate or fraudulent purposes or to further attacks on a larger entity
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 6/23
Build trust Research Target Exploit
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 7/23
– VIP, user, tech – appeal to authority – reverse social engineering – identity theft
–
tailgating
–
key duplication
–
eavesdropping
–
shoulder-surfing
–
dumpster-diving
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 8/23
– phishing, spearphishing – vishing – app impersonation
–
e-mails
–
usb drops
–
instant messages, sms
–
social networks
–
traffic injection
–
malware, adware
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 9/23
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 10/23
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 11/23
– Why? Humans – the weakest link – Solution? OPSEC
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 12/23
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 13/23
– passwords – research data – analytical data
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 14/23
– competitors – entities
– Company B is developing the same product as we and is rumored to have offensive
cyber capability.
– We are travelling to China with corporate laptops and fear intercept.
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 15/23
– Our tech support does not properly identify callers before providing assistance – We don’t have a firewall and do not follow secure coding practices
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 16/23
–
Multiply every potential threat with every weakness to get the risk!
–
Risk = Impact × Probability
–
Impact of tech support not identifying callers is medium (5), because of limited tech support
us, therefore risk = 5 × 8 = 40%. We can require callers to provide secret phrases when connecting over the phone.
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 17/23
–
Prioritize by risk!
–
Our top risk ir rated 40% and costs 1800€ per year in extra workload and lost productivity, so we will be implementing it starting 1st of April 2018 and financing it from the IT support budget.
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 18/23
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 19/23
– create strong passwords – use a password manager or your head – don’t reuse passwords
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 20/23
– If using a VPN is not possible, do not use shared WiFi hot-spots
times, if possible
– talking on the phone, working on a laptop, having a face-to-face conversation
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 21/23
– consider reminders / posters
commits to OPSEC
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 22/23
Kirils Solovjovs, 22/03/2018 possiblesecurity.com OPSEC and defense against social engineering for devels, execs and start-ups 23/23
Slides are available on http://kirils.org Find me on twitter: @KirilsSolovjovs