Social engineering, says Gartner...
Published: 1 November 2004 08:19 GMT
The greatest security risk facing large companies and individual internet users over the next 10 years will be the increasingly sophisticated use of social engineering to bypass IT security defences, according to analyst firm Gartner.
Gartner defines social engineering as "the manipulation of people, rather than machines, to successfully breach the security systems of an enterprise or a consumer". This involves criminals persuading a user to click on a link or open an attachment that they probably know they shouldn't.
Rich Mogull, research director for information security and risk at Gartner, said social engineering is more of a problem than hacking.
"People, by nature, are unpredictable and susceptible to manipulation and persuasion. Studies show that humans have certain behavioural tendencies that can be exploited with careful manipulation.
"Many of the most-damaging security penetrations are, and will continue to be, due to social engineering, not electronic hacking or cracking," said Mogull.
According to Mogull, identity theft is a major concern because more criminals are "reinventing old scams" using new technology.
"Criminals are using social engineering to take the identity of someone either for profit, or to gather further information on an enterprise. This is not only a violation of the business, but of someone's personal privacy," said Mogull.
Rob Forsyth, managing director at Sophos in Australia and New Zealand, told ZDNet Australia about a 'malicious and cynical' scam that recently targeted unemployed Australians.
According to Forsyth, the potential victim received an email that purported to come from Credit Suisse bank advertising a job opportunity. The email asked the recipient to go to a website that was an almost exact replica of the actual Credit Suisse site - but this version contained an application form for the 'vacancy'.
Forsyth said the replicated website was recreated so thoroughly that it took experts 'some time' to confirm that it was actually fake.
"It took us some time to determine it was a fake site. It was not necessarily groundbreaking but quite a clever combination of technology.
"They are targeting those people in the community that are most in need - those seeking work. It is exactly those people that might be vulnerable to this kind of overture,” said Forsyth.
Gartner's Mogull said: "We believe social engineering is the single greatest security risk in the decade ahead."
Munir Kotadia writes for ZDNet Australia.
BT plans passport checks to slash ID fraud
But you'll still need to keep an eye on your bin...
'Witness intimidation' hampering fraud convictions
Courts and legal system are ill-prepared for hearing technical cases...
Zombies are after your ID
Bot nets are increasingly looking to steal valuable personal information...
SurfControl rides the spyware wave
But warns time is running out for anybody favouring "buy" rather than "build" as an entry strategy...
Bloggers become spyware spreaders
Unwitting accomplices...
Stories from around the web...
Identity theft - the facts VNUNet.com
Got an identity crisis? Join the queue The Observer
White-Collar Crime: What's your identity? LegalWeek
Drop the jargon from privacy policies, says privacy chief Out-Law.com
ID 'neglect' harming consumers This is Money
Make your voice heard
silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.
Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.
Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.
For more about the Research Panel and how to join, click here
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page