Daily using/supporting

Get Firefox browser!
Get Thunderbird!
Get Opera browser!
Get The Gimp!
Get Inkscape!
Get LibreOffice!
Get Videolan!
Get Linux!
Get Mandriva!
Get Joomla!
Hacker Emblem

Archives

Which topics would you like us to cover more?

Latest comments

Latest tweets

about 1 day ago Using REDIPS.drag to add drag and drop to your .Net webapplication #li #dib0 http://t.co/n8zY3s7d
about 7 days ago http://t.co/cknQcDbo #Kindle
about 15 days ago Freedom isn't the ability to choose what to do or say, but the ability to choose what not to do or say #freedom
about 29 days ago http://t.co/61KTQknI #Kindle
12 Apr 2012 Force the use of a networking adapter using C# #li #dib0 http://t.co/ZTJOPzOz
9 Apr 2012 Mandriva 2010.2 and USB devices in Virtualbox http://t.co/fwq9gbHB
9 Apr 2012 Execute a http request to you own site with PHP http://t.co/DIvWPrpd
Home Architecture, security and coding Social engineering: The wolf and the seven little goats.
Social engineering: The wolf and the seven little goats.
Written by Division by Zero   
Tuesday, 06 September 2011 11:02

Today I was reading the story of the wolf and the seven little goats to my daughter. I could help thinking that the wolf applied social engineering to get in to the house of the little goats.

DeceptionThe old story, written down by the brothers Grimm, is about seven little goats. They are left alone in the house by their mother with explicit instructions not to open the door to anyone. The mother knows that the wolf wants the little goats for dinner. She instructs the little ones with two ways to distinguish the wolf from herself. The has a soft voice, unlike the wolf. The wolf has dark hair, the mother has white hair. Of course the wolf shows up. He is challenged and discovered as a wolf two times. But he does find a way to make his voice sound soft and make his arms white. In the end the little goats think he is their mother and let him in.

What can we learn about this old story? Social engineering, the art of deception, is often used to breach the security of a company. But what can we do about it? In the story the little goats are trained to recognize an intruder. But this doesn't prove to be enough. Teaching your employees how to challenge possible intruders is not enough.

The goats make two errors. The first one is to give away the specific challenges. This is most of the times inevitable. But this has to be taken in to account in their judgment. The second is that they fail to recognize a-typical behavior. The wolf comes back multiple times and tries hard to convince them that he is their mother. The mother probably will do this another way. For example by using a key to open the door.

The cognitive bias, well know in social psychology (as mentioned in this paper), is referred to as Fundamental Attribution Error (FAE). It is the tendency in forming ones judgment of others to underestimate the importance of the specific situation in which the behavior is shown. In the case of the story the two errors made fall in this category.

Now: what to do about this within your security protocol. You have to train your staff in recognizing odd behavior within a specific situation. Not only do they need to understand standard challenges from the protocol, but they have to learn to challenge odd behavior. And foremost they have to never open the door if there is any doubt.

 

Add comment


Security code
Refresh

Prayer does not change God, but it changes him who prays. - Soren Kierkegaard


© 2009 - 2012, Division by Zero

Template based on the empire template by joomlashack 

Valid XHTML 1.0 Strict  Valid CSS!  Creative Commons License
This work by Division by Zero is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Netherlands License.