
Users "need to be taught" to spot social engineering attacks
By Tom Espiner
Published: 27 June 2007 08:58 BST
Security firm McAfee has said that cybercriminals are using increasingly sophisticated social-engineering techniques and that IT managers need to make users aware of the psychological tricks that make the techniques work.
The vendor worked with University of Leicester forensic psychologist Professor Clive Hollin to analyse why users fall for online scams.
According to Hollin, the first part of the process is persuading the user that an email comes from a respectable source. People tend to respond to authority - for example, a lawyer - but will also respond to endorsements from trusted sources, as well as familiarity and banter.
Once trust has been gained, fraudsters attempt to get users to click on a link which takes them to malicious websites by either threatening an unwanted event, such as legal action, or by offering a reward, such as a commodity for a bargain price, said Hollin.
Users who fall for scams are not necessarily technophobes or the innocent, said the psychologist. Risk-takers might be fooled by the prospect of high gain, while the tech-savvy might be vulnerable due to over-confidence.
Hollin said: "Given the right conditions in terms of the persuasiveness of the communication and the critical combination of situational and personal factors, most people may be vulnerable to misleading information. This point is true both for experienced and inexperienced computer users; while naivety may be a partial explanation, even sophisticated users can be deceived and become suggestible to misleading messages."
Tom Espiner writes for ZDNet UK
Analyse Legacy Data using Informatica to understand the current data volumes, formats and anomalies. Stakeholders, keeping them informed and ...
Candidates should ideally have about two years experience of working within the information department of a health authority. Skills required for the ...
Youll have gained a good knowledge of the gas industry and ideally specifically in gas forecasting techniques and strong abilities in SQL, VB and ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Martin Brampton Brampton Factor: Open source stands up for its rights Copyright can keep the movement alive...
Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?