Social Engineering for Key Discovery
Social engineering exploits human behavior to trick individuals into revealing sensitive authentication information, such as access codes or cryptographic keys.
3 slides · 1 min read · Domain 3
Social engineering is the use of deception or intimidation to get people to provide information to someone not authorized to have it. Techniques may include coercion, bribery, or deception by attackers to gain access to systems without the use of technical means.
Social engineering attacks on cryptographic systems have proved to be successful throughout history, and their use today continues to be a part of an advanced persistent threat's plan of attack.
All cryptography systems, just like security controls, ultimately rely on humans to implement and operate properly. Unfortunately, this is one of the greatest vulnerabilities and has led to some of the greatest compromises of a nation's or organization's secrets or intellectual property. Defending against social engineering requires a constant focus on awareness, education, and training.
One of the most notable examples (and there are hundreds) of social engineering compromises occurred at RSA Corporation in 2011. Its SecurlD tokens provide a twofactor authentication (2FA) mechanism, and possession of the token is required to authenticate. However, this technology only works if the 2FA technology is secure.
The attack against RSA used two different phishing emails. Together, these emails enticed an employee to open an attached Microsoft Excel spreadsheet. Once opened, the spreadsheet, a zero-day Adobe Flash vulnerability, installed a backdoor to the target system. While the exact information stolen by the attacker was not disclosed, the attack compromised the network security of multiple U.S. defense contractors. RSA initially minimized the effect, but ultimately it replaced all tokens then in service, costing approximately US $66 million to correct the problem.
