Social Engineering Attack Templates
Social Engineering Attack Templates
ScienceDirect
j o u r n a l h o m e p a g e : w w w. e l s e v i e r. c o m / l o c a t e / c o s e
A R T I C L E I N F O A B S T R A C T
Article history: The field of information security is a fast-growing discipline. Even though the effective-
Received 24 December 2015 ness of security measures to protect sensitive information is increasing, people remain
Received in revised form 13 March susceptible to manipulation and thus the human element remains a weak link. A social en-
2016 gineering attack targets this weakness by using various manipulation techniques to elicit
Accepted 15 March 2016 sensitive information. The field of social engineering is still in its early stages with regard
Available online 21 March 2016 to formal definitions, attack frameworks and templates of attacks. This paper proposes de-
tailed social engineering attack templates that are derived from real-world social engineering
Keywords: examples. Current documented examples of social engineering attacks do not include all
Bidirectional communication the attack steps and phases. The proposed social engineering attack templates attempt to
Indirect communication alleviate the problem of limited documented literature on social engineering attacks by
Mitnick’s attack cycle mapping the real-world examples to the social engineering attack framework. Mapping several
Social engineering similar real-world examples to the social engineering attack framework allows one to es-
Social engineering attack detection tablish a detailed flow of the attack whilst abstracting subjects and objects. This mapping
model is then utilised to propose the generalised social engineering attack templates that are rep-
Social engineering attack examples resentative of real-world examples, whilst still being general enough to encompass several
Social engineering attack different real-world examples. The proposed social engineering attack templates cover all
framework three types of communication, namely bidirectional communication, unidirectional com-
Social engineering attack scenario munication and indirect communication. In order to perform comparative studies of different
Social engineering attack templates social engineering models, processes and frameworks, it is necessary to have a formalised
Unidirectional communication set of social engineering attack scenarios that are fully detailed in every phase and step of
the process. The social engineering attack templates are converted to social engineering attack
scenarios by populating the template with both subjects and objects from real-world ex-
amples whilst still maintaining the detailed flow of the attack as provided in the template.
Furthermore, this paper illustrates how the social engineering attack scenarios are applied
to verify a social engineering attack detection model. These templates and scenarios can
be used by other researchers to either expand on, use for comparative measures, create ad-
ditional examples or evaluate models for completeness. Additionally, the proposed social
engineering attack templates can also be used to develop social engineering awareness
material.
© 2016 Elsevier Ltd. All rights reserved.
* Corresponding author.
E-mail address: moutonf@[Link] (F. Mouton).
[Link]
0167-4048/© 2016 Elsevier Ltd. All rights reserved.
computers & security 59 (2016) 186–209 187
There are many models and taxonomies for social engi- The target is curious to exploit the contents of the flash drive
neering attacks (Harley, 1998; Ivaturi and Janczewski, 2011; for personal gain or, motivated by ethical considerations, to
Laribee, 2006; Mohd Foozy et al., 2011; Mouton et al., 2014; Tetri attempt to find the owner of the flash drive. The target inserts
and Vuorinen, 2013). The most commonly known model is Kevin the flash drive into his/her computer, and the infection on the
Mitnick’s social engineering attack cycle as described in his flash drive is activated.
book, The art of deception: controlling the human element of secu- The ontological model also contains components such as
rity (Mitnick and Simon, 2002). Mitnick’s attack model has four a goal, a medium, a social engineer, a target, compliance prin-
phases: research, developing rapport and trust, exploiting trust ciples and techniques. The goal of an attack can be financial
and utilising information. These four phases are not ex- gain, unauthorised access or service disruption. The medium
plained in great detail in Mitnick’s book. In previous research is a way of communication such as e-mail, face-to-face contact,
the authors developed the social engineering attack frame- a telephone call, etc. The social engineer can be either an in-
work that fully expands on each phase (Mouton et al., 2014). dividual or a group of individuals. The target can either be an
According to the authors’ ontological model, a social en- individual or an organisation. Compliance principles refer to
gineering attack “employs either direct communication or the reasons why a target complies with the attacker’s request,
indirect communication, and has a social engineer, a target, and techniques include those used to perform social engi-
a medium, a goal, one or more compliance principles and one neering attacks. Examples of techniques include phishing,
or more techniques” (Mouton et al., 2014). The attack can be pretexting, baiting and quid pro quo (Mouton et al., 2014). Ex-
split into more than one attack phase, and each phase is amples of compliance principles include the following:
handled as a new attack according to the model. The model
is depicted in Fig. 1. • Friendship or liking: People are more willing to comply with
Direct communication, where two or more people are com- requests from friends or people they like.
municating directly with each other, is sub-divided into • Commitment or consistency: Once committed to something,
“Bidirectional communication” and “Unidirectional communi- people are more willing to comply with requests consis-
cation”. Bidirectional communication occurs when both parties tent with this position.
participate in the conversation. For example, an e-mail is sent • Scarcity: People are more willing to comply with requests
from the attacker to the target and the target replies to the at- that are scarce or decreasing in availability.
tacker. Unidirectional communication occurs when the • Reciprocity: People are more willing to comply with a request
conversation is one-way only: from the attacker to the target. if the requester has treated them favourably in the past.
For example, if the attacker sends a message via paper mail • Social validation: People are more willing to comply with a
without a return address, the target cannot reply to the message. request if it is seen as the socially correct thing to do.
Phishing attacks are also a popular type of attack in this category. • Authority: People easily comply with requests received from
Indirect communication is when there is no actual inter- people with more authority than they have.
action between the target and the attacker; communication
occurs through some third party medium. An example of this Once the compliance principles, techniques and medium
type of communication is when the attacker infects a flash drive have been selected, the attack vector can be set up and the
and leaves it somewhere to be found by some random target. social engineer can continue with the actual attacking phase.
The social engineering attack framework can be used to engineering attacks (which have been widely documented in
depict the planning and flow of the full attack. Fig. 2 depicts news articles) to the social engineering attack framework.
the social engineering attack framework. During this research it was found that several pieces of infor-
The social engineering attack framework has six core phases, mation about the social engineering attack were not included
namely attack formulation, information gathering, prepara- in the documentation and that several steps of the social en-
tion, develop relationship, exploit relationship and debrief. gineering attack had to be inferred.
The “attack formulation” phase is used to identify both the The “goal identification” and “target identification” steps are
goal and the target of the specific attack. The “information gath- usually not documented. News articles report on an attack after
ering” phase is used to identify all sources of information on it has occurred and typically focuses on how the attack af-
both the goal and the target, as well as to gather information fected the specific target. There is also very little information
from the identified sources. In the “preparation” phase, all the on what steps were followed during the “information gather-
gathered information is combined and the social engineer- ing” phase. The reader of the news article is to assume that
ing attack vector is developed. It is during the “preparation” the social engineer performed extensive information gather-
phase that all the elements in the social engineering onto- ing on both the goal and the target, which in turn led to a
logical model can be identified. The “develop relationship” phase successful social engineering attack. Depending on the type
is where the attacker establishes communication with the target of attack, the “preparation” phase and the “develop relation-
and attempts to build a trust relationship with the target. The ship” phase normally have information that can be used directly
“exploit relationship” phase is used to prime the target and to in the social engineering attack framework. The “exploit rela-
elicit the target to perform the request or action. The final phase tionship” phase is not always documented as the specific
is the “debrief” phase, in which the target is brought out of a priming and elicitation techniques are not mentioned specifi-
primed state during the “maintenance” step, and the “transi- cally. It is normally only mentioned whether the attack was
tion” step tests whether the goal has been satisfied. successful or not. The “debrief” phase is usually also not covered
The next section describes why a set of detailed social en- in a report or news article as the “maintenance” step is a step
gineering attack templates are required and presents the set the social engineer follows to reassure the victim that he/she
of templates. is not the prey of a social engineering attack. The “transition”
step is something only the social engineer has knowledge of,
as the report or news article only reports on the final success-
ful social engineering attack.
3. Templates for social engineering attacks The proposed templates attempt to address the problem de-
scribed above by detailing every phase and associated steps
The authors previously proved the usefulness of the social en- of the social engineering attack framework in such a way that
gineering attack framework by mapping well-known social each template will provide repeatable results. The templates
190 computers & security 59 (2016) 186–209
are also kept as simple as possible so that they can be ex- generally feel compelled to hold open the door for other in-
panded upon to create more elaborate scenarios with exactly dividuals (Brainard et al., 2006; Brody et al., 2012).
the same principal structures. The templates were developed • The SE can use fake credentials or even just a good story
in such a way that other researchers can use them to perform to gain access to an organisation. This can be done by simply
repeatable experiments of social engineering attacks, with re- printing fake business cards, dressing the part or just car-
peatable results, without having to physically perform the attack rying the correct security badge (Major, 2009).
and potentially cause harm to innocent targets (Mouton et al.,
2013, 2015). This template illustrates a social engineering attack (SEA)
The templates are fairly diverse in order to show and test where the attacker attempts to gain physical access to a com-
different social engineering attack scenarios. They are grouped puterised terminal at the premises of an organisation. The
according to the communication type, namely bidirectional assumption is that when the attacker has once gained access
communication, unidirectional communication or indirect com- to the computerised terminal, he/she is deemed to have been
munication. The classification structure is based on the fact successful. The attacker is now able to install a backdoor onto
that each template has a specific communication method and the computerised terminal for future and further access from
that there is almost no overlap of attacks that use the same the outside.
communication method. The important features of the SEA are specified below:
All of the templates are derived from real-world social en-
gineering attacks that have been documented in either news Communication – The SEA is using bidirectional
articles, technical reports, research reports, films or blogs. The communication.
news articles, technical reports, research reports or blogs do Social Engineer – The Social Engineer (SE) is an individual.
not always contain all of the information regarding the social Target – The target is an organisation.
engineering attack. This lack of information is addressed by Medium – The communication medium is face-to-face.
discussing the template as a more generalised form of the social Goal – The goal of the attack is to gain unauthorised access
engineering attacks provided in the literature. The proposed to a computerised terminal within the organisation.
template combines elements from all of the provided real- Compliance Principles – The compliance principles that are
world examples into a single social engineering attack template. used are authority, commitment and consistency.
The templates are derived in this manner to ensure that each Techniques – The technique that is used is pretexting.
template contains all the elements of a social engineering attack
whilst still being representative of a real-world scenario. The following text dissects and maps the template to the
In the discussion of each template, the real-world social en- Social Engineering Attack Framework (SEAF).
gineering attacks are first provided. Each real-world example
is briefly explained in terms of what actions the social engi- 3.1.1. Step 1: attack formulation
neer (SE) takes in order to get the target to comply to the
specified request, after which, the citation of where the attack [Link]. Goal identification. The goal of the attack is to gain
can be found. Using the the aforementioned examples as a unauthorised access to any computerised terminal within the
guideline, the reader is provided with a short description of a organisation.
generalised template that contains elements from the real-
world social engineering attacks. This generalised template is [Link]. Target identification. The target of the attack is the
then mapped to the social engineering attack framework that organisation as a whole. This allows the attacker to target any
provides more detailed information about every phase and step individual within the organisation who has the capability of
of the social engineering attack. allowing the attacker access to the computerised terminal.
The rest of this section proposes four bidirectional com-
munication templates, three unidirectional communication 3.1.2. Step 2: information gathering
templates and three indirect communication templates.
[Link]. Identify potential sources. The information sources
3.1. Bidirectional communication – template 1 include the company website, any individuals who deal di-
rectly with the technical support organisation contracted by
The detailed template of this attack is developed by using el- the target organisation, and information from the technical
ements from the following examples in literature: support organisation gained directly.
• The SE pretends to be someone who works on the man- [Link]. Gather information from sources. Gather information
agement floor and convinces a cleaner of his supposed role. from all above mentioned sources that relate directly to how
The cleaner grants the social engineer access to the build- and when technical support is requested and performed.
ing. This allows the SE to gain physical access to the
computerised terminals on the management floor (Dimkov [Link]. Assess gathered information. Determine which tech-
et al., 2010; Janczewski and Fu, 2010). nical support company used by the target organisation is most
• The SE pretends to be part of the organisation, dresses in likely to have the authority to gain physical access to the com-
the appropriate attire, and then tailgates into the building puterised terminal. In addition, determine what time slots can
behind other employees (Granger, 2001; Long, 2011). This is be used to gain physical access to the computerised terminal
one of the more difficult attacks to prevent, because people and whether additional information is required, such as
computers & security 59 (2016) 186–209 191
whether the technical support organisation staff must wear 3.2. Bidirectional communication – template 2
corporate uniforms.
The detailed template of this attack is developed by using el-
ements from the following examples in literature:
3.1.3. Step 3: preparation
[Link]. Maintenance. After the attacker has performed all tasks The following text dissects and maps the template to the
required on the computerised terminal, he approaches the tar- SEAF.
geted individual again and assures the latter that all concerns
with regard to the computerised terminal have been addressed. 3.2.1. Step 1: attack formulation
[Link]. Transition. The attacker was able to successfully gain [Link]. Goal identification. The goal of the attack is to get the
unauthorised access to the computerised terminal and can thus target to disclose information, which the attacker is not au-
proceed to the “goal satisfaction” step. thorised to have.
[Link]. Goal satisfaction. The SE has attained his initial goal [Link]. Target identification. The target of the attack is an in-
of gaining unauthorised access. dividual whose workstation the SE needs to access.
192 computers & security 59 (2016) 186–209
3.2.2. Step 2: information gathering desire to be part of the group, the target is likely to feel obliged
to supply his log-on credentials.
[Link]. Identify potential sources. The information sources
include the places the target visits, any social gatherings the
3.2.6. Step 6: debrief
target attends and any interests that the target might have.
[Link]. Development of an attack vector. Develop an attack plan • The SE pretends to be a network administrator and re-
that contains the chosen event the SE will attend and that states quests the organisation to provide or reset a user’s password
the time interval when the SE will interact with the target. In on the organisation’s system (Granger, 2001).
addition, develop conversational guidelines that will be used • The SE gathers information from a third party organisation
during the SEA. that can then be used against another organisation (Bader
et al., 2010; Tam et al., 2010).
• The SE pretends to be an authoritative figure who is re-
3.2.4. Step 4: develop relationship questing the target to perform a task. Since the target is
reluctant to deny requests from such an authoritative figure,
[Link]. Establishment of communication. Take the physical the target may feel compelled to comply with the request
action of engaging in conversation with the individual at the
(Peltier, 2006).
chosen event. • The SE pretends to be the organisation’s bank, requesting
information to address security concerns. The SE requests
[Link]. Rapport building. The SE, in this case a group of in- that the target navigates to a web address and enter con-
dividuals, is required to engage in friendly conversation with
fidential information (CERT Insider Threat Team, 2014;
the target and make him/her feel part of the group. The SE at- Greitzer et al., 2014).
tempts to build a trust relationship with the targeted individual. • The SE convinces a domain registrar to change the default
e-mail account associated with a financial institution. The
3.2.5. Step 5: exploit relationship SE also convinced the registrar to reset the default pass-
word (CERT Insider Threat Team, 2014).
[Link]. Priming the target. After the trust of the target has been
gained, the group of individuals is required to steer the con- This template illustrates an SEA where the attacker
versation onto the topic of password security and how people attempts to gain the password of a specific individual’s
rarely use complex passwords. e-mail account where the e-mail account is managed by an
organisation. This attack is aimed at the organisation who is
[Link]. Elicitation. One of the individuals in the group close in control of the individual’s e-mail account and not directly
to the target is required to start off by asking another indi- at the individual. Due to this, the individual is considered to
vidual in the group what their log-on credentials are to illustrate be the primary target while the organisation that is targeted
that most users use insecure passwords. After the individual is considered a secondary target. The assumption is made that
has provided his log-on credentials, each of the other indi- after the attacker has been able to successfully request a
viduals should comply with the request and provide their log- password reset for the individual’s e-mail account from the
on credentials as well. When all the other individuals in the organisation, the attacker will be able to gain access to
group have provided their log-on credentials, the target must the e-mail account. This is then deemed to be a successful
be requested to provide his log-on credentials. Because of his SEA.
computers & security 59 (2016) 186–209 193
The important features of the SEA are specified below: reset, and assess the validity of all gathered personal infor-
mation of the primary target.
Communication – The SEA is using bidirectional
3.3.3. Step 3: preparation
communication.
Social Engineer – The SE is an individual.
[Link]. Combination and analysis of gathered information. Using
Target – The primary target is an individual. This indi-
all the assessed information, determine the best time slots
vidual has an e-mail account at a specified organisation,
during which a specific staff member of the organisation who
and the latter is considered to be a secondary target.
has control over the password request process (the second-
Medium – The communication medium is a telephone.
ary target) can be contacted. In addition, it is required to develop
Goal – The goal of the attack is to gain unauthorised access
a full profile of the primary target’s personal information. This
to the individual’s e-mail account.
profile is used to ensure that the attacker will be able to answer
Compliance Principles – The compliance principles that are
any questions that the secondary target may direct at the at-
used are authority and scarcity.
tacker during the password reset request.
Techniques – The technique that is used is pretexting.
[Link]. Goal identification. The goal of the attack is to gain 3.3.4. Step 4: develop relationship
unauthorised access to the primary target’s e-mail account by
requesting a secondary target to have the password for the [Link]. Establishment of communication. The physical action
e-mail account reset. of making the phone call to the organisation, up to the point
where the secondary target can assist the attacker with the
[Link]. Target identification. The primary target of the attack password reset request.
is an individual with an e-mail account at the specified
organisation. The specified organisation has control over the [Link]. Rapport building. The attacker is required to develop
target’s e-mail account and thus an individual at the a friendly relationship with the individual (secondary target)
organisation (which is considered the secondary target) will who can assist with the password reset request. The attack-
be persuaded by social engineering to provide access to the er’s intention is to get the targeted individual to trust the
primary target’s e-mail account. This allows the attacker to attacker.
target any individual within the organisation who has the ca-
3.3.5. Step 5: exploit relationship
pability of allowing the attacker to reset the password of the
target’s e-mail account.
[Link]. Priming the target. The attacker who is impersonat-
ing the primary target will explain to the individual (secondary
3.3.2. Step 2: information gathering
target) that he/she (the attacker) urgently requires to regain
access to “his/her” e-mail account. One example of a way in
[Link]. Identify potential sources. The information sources
which a sense of urgency is created is telling the individual
include the organisation’s website, organisational policies and
how important it is for the attacker to retrieve a specific docu-
any source that can provide personal information of the primary
ment from the primary target’s e-mail account and that this
target.
document is required immediately for some emergency.
[Link]. Assess gathered information. Determine what process [Link]. Transition. Since the attacker was able to success-
is followed during the password reset request, what informa- fully request a password reset for the primary target’s e-mail
tion is requested from the individual requesting a password account, he/she can thus proceed to the “goal satisfaction” step.
194 computers & security 59 (2016) 186–209
[Link]. Goal satisfaction. The SE has attained his initial goal organisation who have access to the information, and any
of gaining unauthorised access. organisational policies and procedures.
3.4. Bidirectional communication – template 4 [Link]. Gather information from sources. Gather information
from all above-mentioned sources that relate directly to the
The detailed template of this attack is developed by using el- access level of each employee and his/her status in the
ements from the following examples in literature: organisation.
• The SE pretends to be a customer who has in-depth knowl- [Link]. Assess gathered information. Determine which of the
edge of the services that an organisation offers. The SE is employees have access to the sensitive information that the
able to obtain sensitive information from the help-desk staff attacker is trying to obtain. Also, assess all the gathered in-
by bypassing any checks that require authorisation to be formation about each employee and perform information
granted (Janczewski and Fu, 2010). gathering on each of the employees individually. This cyclic
• The SE uses the corporate language of the organisation to process is excluded from the template and it is assumed that
gain the trust of the other employees (Thornburgh, 2004). for the next phase all personal information about each em-
• The SE pretends to be a new employee and requests infor- ployee has been gathered and assessed.
mation from reception (Thornburgh, 2004).
• The SE pretends to be in distress, in a difficult situation or 3.4.3. Step 3: preparation
in a life-threatening emergency. The SE calls the targeted
department in an organisation and convinces the target that [Link]. Combination and analysis of gathered information.
in order to overcome the distress or emergency, his/her Determine the level of susceptibility of each employee, how
request needs to be fulfilled (Rao and Nayak, 2014). much access to information each employee has and what type
of personal information the attacker was able to gather and
This template illustrates an SEA where the attacker at- assess about him/her. Also, develop an information profile on
tempts to obtain sensitive information of an organisation to each employee to determine which employee would be the best
which only the employees of the organisation have access. The target from whom to request the sensitive information.
information is not available to members of the public. Once
the attacker has been provided with the sensitive informa- [Link]. Development of an attack vector. Develop an attack
tion, the SEA is deemed to have been successful. vector that contains the chosen employee whom the at-
The important features of the SEA are specified below: tacker will be targeting, the full personal profile of this employee
and what level of access this employee has. In addition, develop
Communication – The SEA is using bidirectional the planned e-mail communication with the employee to fit
communication. the specific personal profile of the employee.
Social Engineer – The SE is an individual.
Target – The target is an organisation. 3.4.4. Step 4: develop relationship
Medium – The communication medium is e-mail.
Goal – The goal of the attack is unauthorised information [Link]. Establishment of communication. The very first e-mail
disclosure from the target to the attacker. communication that the attacker has with the targeted em-
Compliance Principles – The compliance principles that are ployee of the organisation. This e-mail establishes the basis
used are friendship and liking. for all future communication between the attacker and
Techniques – The technique that is used is pretexting. employee.
The following text dissects and maps the template to the [Link]. Rapport building. This step will be a continuous process
SEAF. of back and forth e-mail communication between the at-
tacker and the employee. Several e-mails will be transferred
3.4.1. Step 1: attack formulation
in a bidirectional manner between the attacker and the em-
ployee in order to gain the trust of the employee. An example
[Link]. Goal identification. The goal of the attack is to get an
of trust building is where the attacker appears to be inter-
employee of the organisation to disclose to the attacker in-
ested in the hobbies and interests of the targeted employee.
formation that the attacker is not authorised to have.
The similarity between the attacker and the targeted employ-
ee’s preferences is used to build trust.
[Link]. Target identification. The target of the attack is the
organisation as a whole. This allows the attacker to target any
individual within the organisation who has the sought-after 3.4.5. Step 5: exploit relationship
capability of providing the attacker with the sensitive
[Link]. Priming the target. The exploitation of the relation-
information.
ship will occur within a single e-mail communication to the
3.4.2. Step 2: information gathering targeted employee. In the priming and elicitation e-mail, the
attacker will inform the employee of a scenario in which
[Link]. Identify potential sources. The information sources the attacker requires access to the sensitive information.
include the organisation’s website, any individuals in the An example of this could be that the attacker is requesting
computers & security 59 (2016) 186–209 195
sensitive information about the company policies because the are very popular social engineering attacks, are examples of
attacker, as part of the pretext, will be attending an interview this type of attack. Once the attacker has received the small
at the targeted employee’s organisation. deposit from the targeted individual, the SEA is deemed to have
been successful.
[Link]. Elicitation. The attacker will request the assistance of The important features of the SEA are specified below:
the targeted employee to retrieve the sensitive information and
due to the friendship and liking and the trust relationship that Communication – The SEA is using unidirectional
have been established, the targeted employee will feel obliged communication.
to comply with the request. Social Engineer – The SE is an individual.
Target – The target is a group of individuals.
3.4.6. Step 6: debrief Medium – The communication medium is e-mail.
Goal – The goal of the attack is financial gain, as the targets
[Link]. Maintenance. It is important that the attacker does not are requested to make a deposit into a bank account owned
abruptly end the communication between himself and the tar- by the attacker.
geted employee as this may cause suspicion and the Compliance Principles – The compliance principle that is
organisation may be alerted to a breach of information. The used is scarcity.
attacker is required to continue the e-mail communication until Techniques – The technique that is used is phishing.
such time as the request that was made is likely to have been
forgotten by the targeted employee and the topic of commu- The following text dissects and maps the template to the
nication has moved on away from the information request. The SEAF.
e-mail communication should thus continue until the sensi-
tive information has been utilised by the attacker and is no 3.5.1. Step 1: attack formulation
longer of use.
[Link]. Goal identification. The goal of the attack is to get an
[Link]. Transition. The attacker was able to successfully gain individual to deposit money into a bank account owned by the
unauthorised information disclosure from the targeted em- attacker and thus to provide financial gain to the attacker.
ployee and can thus proceed to the “goal satisfaction” step.
[Link]. Target identification. The target of the attack is any in-
[Link]. Goal satisfaction. The SE has attained his initial goal dividual of which the attacker has an e-mail address.
of unauthorised information disclosure.
3.5.2. Step 2: information gathering
3.5. Unidirectional communication – template 1
[Link]. Identify potential sources. The information sources
The detailed template of this attack is developed by using el- include any publicly available e-mail lists, websites selling e-mail
ements from the following examples in literature: lists and any other locations that are used to store e-mail
addresses.
• The SE deploys a fake website that sells tickets for a sport-
ing event. The SE also sends out phishing e-mails to inform [Link]. Gather information from sources. Gather from all the
people that they can buy discounted tickets (Janczewski and above-mentioned sources information that relates directly to
Fu, 2010). the individuals’ personal information and e-mail addresses.
• The SE sends out phishing e-mails that falsely originate from
the e-mail addresses of known contacts. Due to the tar- [Link]. Assess gathered information. Determine whether each
geted nature of the phishing attempts, the success ratio e-mail list that has been gathered contains all information about
increases significantly (Jagatic et al., 2007). each individual and whether each individual has an associ-
• The SE sends out an e-mail that directs the target to navi- ated e-mail address.
gate to a fraudulent website, which in turn collects
credentials such as identity document numbers and 3.5.3. Step 3: preparation
bank account numbers from the target (Abraham and
Chengalur-Smith, 2010). [Link]. Combination and analysis of gathered information.
• The SE sends out an e-mail about financial benefits that ex- Combine all the lists obtained into a single list that contains
ploited a zero-day vulnerability, upon clicking a link, and the personal details of each individual and his/her associ-
downloaded malicious code. The malware masked itself on ated e-mail address. After the lists have been combined, prune
systems and was designed to erase itself if it tried to com- all duplicates from the list to create a single list with only
promise a system and was unsuccessful (CERT Insider Threat unique e-mail addresses.
Team, 2014; Greitzer et al., 2014).
[Link]. Development of an attack vector. Develop an attack plan
This template illustrates an SEA where the attacker at- that details all the information that should be contained in each
tempts to obtain financial gain by sending out e-mails that e-mail, what personal information to use in each e-mail and
request a group of individuals to make a small deposit into a exactly how each section of the e-mail should be worded. It
bank account owned by the attacker. The “419 scams”, which is also important to determine the duration of the attack,
196 computers & security 59 (2016) 186–209
because the attacker will have to close the bank account after captures the user’s log-on credentials and provides them
a specified amount of time to ensure that individuals are not to the SE (Laribee, 2006).
able to reverse any funds transferred. • The SE sends the target a message by using a mobile device.
The message indicates that the user has to update the ap-
3.5.4. Step 4: develop relationship plication that is used to access the system or the product
to which the user has access. This can convince the user
[Link]. Establishment of communication. This involves the to visit the link and during the update process, the user is
physical action of sending out an e-mail to each of the e-mail asked to provide his/her log-on credentials (Salem et al.,
addresses on the list. 2010).
• The SE sent an innocent-looking e-mail to news service staff-
[Link]. Rapport building. Rapport building in an e-mail usually ers urging them to click on a link to an important article
occurs in the subject line and in the first few paragraphs of on another news organisation’s blog that, unknown to the
the e-mail. The reason behind this is that individuals scan only victims, would infect their computers with malware. The
the subject line and the first few paragraphs of an e-mail, and malware allowed the SE to capture passwords to the news
trust should be built so that the target is enticed to read the service’s Twitter account (CERT Insider Threat Team, 2014).
entire e-mail.
This template illustrates an SEA where the attacker at-
tempts to obtain log-on credentials from a group of individuals
3.5.5. Step 5: exploit relationship
who are all using a certain system or product provided by an
organisation. It is assumed that individuals are required to log-
[Link]. Priming the target. In this attack, priming is done by
on to this system or product using log-on credentials unique
using the scarcity principle. Priming usually occurs in the para-
to each individual. Individuals who are using the system are
graphs following the “rapport building” step. In these
not allowed to share their log-on credentials and thus the goal
paragraphs, the target is informed that he/she is a specially
of this attack is unauthorised information disclosure. The SE
selected individual and that there is only a limited time frame
can have a further goal to obtain unauthorised access to the
within which to claim the reward offered to him/her in this
system or product, but that is seen as a separate goal. Once
e-mail.
the attacker has obtained the log-on credentials from the in-
dividual, the SEA is deemed to be successful.
[Link]. Elicitation. In the next paragraph, the attacker re-
The important features of the SEA are specified below:
quests the individual to make a smaller deposit than the reward
offered, in order to be eligible to claim the full reward.
Communication – The SEA is using unidirectional
communication.
3.5.6. Step 6: debrief Social Engineer – The SE is an individual.
Target – The target is a group of individuals.
[Link]. Maintenance. The e-mail is ended off by thanking the Medium – The communication medium is a Short Message
target so as to make him/her feel at ease about making the Service (SMS).
payment and being selected for the specific reward. Goal – The goal of the attack is unauthorised information
disclosure from the target to the attacker.
[Link]. Transition. If the attacker is successful in his/her request Compliance Principles – The compliance principles that are
that the target makes a payment into the attacker’s bank used are scarcity, commitment and consistency.
account, the attacker can proceed to the “goal satisfaction” step. Techniques – The technique that is used is phishing.
[Link]. Goal satisfaction. The SE has attained his initial goal The following text dissects and maps the template to the
of financial gain. SEAF.
[Link]. Gather information from sources. Gather from all the 3.6.6. Step 6: debrief
above-mentioned sources information that relates directly to
the individuals’ personal information, cellphone numbers and [Link]. Maintenance. In this template, maintaining rapport is
any information regarding the product and the appearance of actually performed on the log-on screen and not in the SMS
the log-on screen for the product. itself. After the user has logged on to the fraudulent system,
a message appears thanking the individual for updating to the
[Link]. Assess gathered information. Determine whether each latest version and the individual is then redirected to the origi-
identified user has an associated cellphone number and that nal system.
the cellphone number is valid. Also, assess if enough infor-
mation has been gathered to correctly duplicate the log-on [Link]. Transition. The attacker was able to successfully gain
screen for the specific system. unauthorised information from the target and can thus proceed
to the “goal satisfaction” step.
3.6.3. Step 3: preparation
[Link]. Goal satisfaction. The SE has attained his initial goal
[Link]. Combination and analysis of gathered information. of unauthorised information disclosure.
Develop a single list that contains the names of all users of
the system and their associated cellphone numbers. In addi- 3.7. Unidirectional communication – template 3
tion, develop a mock-up of how the log-on screen should look,
so that this can be replicated to ensure that the screen is fa- The detailed template of this attack is developed by using el-
miliar to the targets during the attack. ements from the following examples in literature:
[Link]. Development of an attack vector. Develop an attack plan • The SE performs a pretext using postal letters. The SE pre-
that details all the information that should be contained in each tends to be various officials, internal employees, employees
SMS, what personal information to use in each SMS and exactly of trading partners, customers, utility companies or finan-
how each section of the SMS should be worded. For this tem- cial institutions and the SE solicits confidential information
plate, the attackers are required to develop a log-on screen that by using a wide range of persuasive techniques (Workman,
looks similar to the original screen and that is able to capture 2008).
the log-on credentials when individuals attempt to log-on. • The SE has the capability of spoofing the sender ID on
popular mobile messaging applications (Schrittwieser et al.,
3.6.4. Step 4: develop relationship 2012). This capability can further be used to perform an SEA
and to send messages to other users whilst impersonat-
[Link]. Establishment of communication. This is done by the ing friends of these users (Krombholz et al., 2013).
physical action of sending out all the SMSs to each of the cell- • Typical SE attacks, specifically phishing, used to occur via
phone numbers on the list. postal mail. The term “419 scams” refers to section 419 of
the Nigerian Criminal Code, which outlaws this type of scam.
[Link]. Rapport building. Rapport building in an SMS usually During the 1970s, postal mail was mostly used in these
occurs in the very first sentence of the SMS. The reasoning scams and during the 1980s, the medium of communica-
behind this is that SMSs are limited to 160 characters and thus tion changed to faxes. Both are examples of forms used by
you are required to keep the content brief. The first sentence the SE to initiate unidirectional communication (Dang, 2008).
of the SMS should build trust in the individual and entice him/
her to read the rest of the SMS. In this template, the SMS would This template illustrates an SEA in which the attacker at-
mention that it is an automated SMS from the organisation tempts to obtain financial gain by sending out paper mail. This
providing the system. letter requests a group of individuals to make a small deposit
into a bank account owned by the attacker. In this template,
3.6.5. Step 5: exploit relationship the attacker develops a phishing letter that masks the at-
tacker as a charity organisation requesting donations. Once the
[Link]. Priming the target. The second sentence of the SMS attacker has received the small deposit from the targeted in-
is used both to prime the target and to elicit action. The at- dividual, the SEA is deemed to be successful.
tacker will prime the target by using the scarcity principle, and The important features of the SEA are specified below:
by saying that a free update for the system will be available
for a limited period only. Communication – The SEA is using unidirectional
communication.
[Link]. Elicitation. The sentence continues by providing a short- Social Engineer – The SE is an individual.
ened hyperlink in the SMS on which the individual will be Target – The target is a group of individuals.
requested to click to obtain the free update to the system. The Medium – The communication medium is paper mail.
first screen that the individual would see after clicking on the Goal – The goal of the attack is financial gain because the
link would be a log-on screen similar to what he/she is used targets are requested to make a deposit into a bank account
to. Using the commitment and consistency principles, the user owned by the attacker.
will trust the familiar-looking site and enter his/her log-on Compliance Principles – The compliance principle that is
credentials. used is scarcity.
198 computers & security 59 (2016) 186–209
Techniques – The technique that is used is phishing. in the individual and to ensure that the individual will support
the charity and want to read the rest of the letter.
The following text dissects and maps the template to the
SEAF. 3.7.5. Step 5: exploit relationship
3.7.1. Step 1: attack formulation [Link]. Priming the target. The individual is primed by pro-
viding him/her with a list of the current donations that have
[Link]. Goal identification. The goal of the attack is to get an been received by the charity, what the charity needs to pur-
individual to make a deposit into a bank account owned by chase and specifically why these donations are needed. The
the attacker and thus allowing the attacker to achieve finan- received donations section will assure the individual that there
cial gain. are other people donating and that it is socially acceptable to
donate to the charity. The additional work the charity can
[Link]. Target identification. The target of the attack is any in- perform and why the donations are requested are included to
dividual for whom the attacker has a postal address. provoke an emotional response from the individual so that he/
she can relate to the charity.
3.7.2. Step 2: information gathering
[Link]. Elicitation. Using an empathetic tone of writing, the
[Link]. Identify potential sources. The information sources attacker requests the individual to make a small donation to
include any publicly available telephone records and address the specified charity. It is very important to provide several
lists. options on how the individual can donate to the charity and
the procedure to perform the donation should be as simple as
[Link]. Gather information from sources. Gather from all the possible.
above-mentioned sources information that relates directly to
the individuals’ personal information and postal address. 3.7.6. Step 6: debrief
[Link]. Assess gathered information. Determine whether each [Link]. Maintenance. The letter is finalised by thanking the in-
address list that has been obtained contains all information dividual for his potential generosity and to assure the individual
about each individual and whether each individual has an as- that any donation that is made will be spent wisely.
sociated postal address.
[Link]. Transition. If the attacker succeeds in persuading the
3.7.3. Step 3: preparation target to make a payment into the attacker’s bank account, the
attacker can proceed to the “goal satisfaction” step.
[Link]. Combination and analysis of gathered information.
Combine all the lists obtained into a single list that contains [Link]. Goal satisfaction. The SE is satisfied as he/she at-
the personal details of each individual and his/her associ- tained the initial goal of financial gain.
ated postal address. After the lists have been combined, prune
all duplicates from the list to create a single list with only 3.8. Indirect communication – template 1
unique postal addresses.
The detailed template of this attack is developed by using el-
[Link]. Development of an attack vector. Develop an attack plan ements from the following examples in literature:
that details all the information that should be contained in each
letter, what personal information to use in each letter and • The SE scatters USB drives in the parking lot, smoking areas
exactly how each section of the letter should be worded. It is and other areas that employees frequent. The employees
also important to determine the duration of the attack, as the plug in the USB drives the minute they get to their work-
attacker will have to close the bank account after a specified stations (Stasiukonis, 2006).
amount of time to ensure that individuals are not able to reverse • The SE attempts to gain unauthorised access to a work-
any funds transferred. station in an organisation by using a storage medium device
(Esmail, 2015; Jodeit and Johns, 2010). This attack is also de-
3.7.4. Step 4: develop relationship picted in a popular television series about penetration
testing, Mr. Robot (Esmail, 2015).
[Link]. Establishment of communication. This is done by the • Spreading malware through means of storage media or
physical action of sending out letters to each of the postal ad- storage devices is nothing new; this practice can be traced
dresses on the list. back to the use of floppy drives (Abraham and
Chengalur-Smith, 2010).
[Link]. Rapport building. Building rapport in postal mail is very
similar to building rapport in an e-mail and it should occur This template illustrates an SEA in which the attacker at-
in the first few paragraphs of the letter. In this template, the tempts to gain unauthorised access to a workstation within
first few paragraphs should introduce the charity requesting an organisation by using a storage device. Once the target has
the donation and what the charity has done so far with pre- plugged the storage device (in this case a USB flash drive) into
vious donations received. This information is used to build trust the targeted workstation, the SEA is deemed to be successful.
computers & security 59 (2016) 186–209 199
This is because the attacker is now able to install a backdoor [Link]. Development of an attack vector. Develop an attack plan
onto the workstation via the storage device. The SE can then that contains the exact time that the attacker will visit the
proceed to use this workstation as a pivot point for any further premises, which entrance the storage medium will be de-
attacks on the organisation. This type of an attack is viable due ployed at, how the storage medium will be marked to prompt
to an unintentional insider threat (CERT Insider Threat Team, the individual to return it to its owner and what data will be
2013; Greitzer et al., 2014). deployed onto the storage medium. The storage medium should
The important features of the SEA are specified below: contain a Trojan (malware) that will attempt to connect to the
attacker’s network infrastructure.
Communication – The SEA is using indirect communication.
Social Engineer – The SE is an individual. 3.8.4. Step 4: develop relationship
Target – The target is an organisation.
Medium – The communication medium is a storage device. [Link]. Establishment of communication. Communication is es-
In this case, the storage device to be used is a USB flash drive. tablished via the physical action of deploying the storage
Goal – The goal of the attack is to gain unauthorised access medium at an entrance and it lasts up to the time when an
to a workstation within the organisation. individual picks up the storage medium.
Compliance Principles – The compliance principle that is
used is social validation. [Link]. Rapport building. In this case, rapport is developed by
Techniques – The technique that is used is baiting. ensuring that the storage medium looks similar to those that
are typically used by the organisation and that are branded with
The following text dissects and maps the template to the the organisation’s logo.
SEAF.
3.8.5. Step 5: exploit relationship
3.8.1. Step 1: attack formulation
[Link]. Priming the target. Attach a label to the storage medium
[Link]. Goal identification. The goal of the attack is to gain that states that the information on the storage medium is very
unauthorised access to any workstation within the organisation. valuable and that, if lost, it should be returned to the owner.
The label or sticker to convey this message is normally only
[Link]. Target identification. The target of the attack is the a sticker saying “Important” or “Confidential”. The target is re-
organisation as a whole. This allows the attacker to target any quired to plug the storage medium into a workstation in order
individual within the organisation who has a workstation or to determine the owner.
who has access to a workstation.
[Link]. Elicitation. The “elicitation” step is almost implicit in
3.8.2. Step 2: information gathering this template. Most people will attempt to return lost valu-
ables or they could just be curious to find out what information
[Link]. Identify potential sources. The information sources is stored on the storage medium. Both of these situations will
include physical scouting of the premises, monitoring of the lead to a successful “elicitation” step.
movement of employees, and any schedules or appoint-
ments posted on the organisation’s website. 3.8.6. Step 6: debrief
[Link]. Gather information from sources. Gather from all the [Link]. Maintenance. Once the storage medium has been con-
above-mentioned sources information that relates directly to nected to a workstation, the Trojan will automatically execute
how and when employees are entering and leaving the office in a hidden fashion. In order to avoid suspicion, it is good prac-
building and specifically which entrances are being used. tice by the attacker to include either contact details to return
the storage medium or an encrypted document to indicate the
[Link]. Assess gathered information. Determine which of the importance of the information.
entrances are the most viable target, based on the time inter-
vals when individuals enter and exit the organisation at these [Link]. Transition. Once the attacker was able to success-
entrances. Also, determine the possible ways the attacker can fully gain unauthorised access to the workstation of the
approach these entrances without looking suspicious or individual, he/she can proceed to the “goal satisfaction” step.
showing suspicious behaviour.
[Link]. Goal satisfaction. The SE has attained his/her initial
3.8.3. Step 3: preparation goal of gaining unauthorised access.
[Link]. Combination and analysis of gathered information. 3.9. Indirect communication – template 2
Determine the best time slots during which the attacker can
attempt to deploy the storage medium at the entrance without The detailed template of this attack is developed by using el-
having to perform any suspicious behaviour. It is important to ements from the following examples in literature:
choose a time slot when most individuals are entering the build-
ing, because it is always possible that an individual exiting the • The SE studies the available attributes on public profiles
building may also pick up the storage medium. within specific social networks and determines how they
200 computers & security 59 (2016) 186–209
may be exploited. Context-aware e-mail spam is then gen- users of the social media website and the policies of the social
erated and sent to users of the network (Brown et al., 2008). media website.
This same attack can be repeated by posting the context-
aware spam within the social networks of the users. [Link]. Gather information from sources. Gather from all the
• Users of social networking websites exhibit a high degree above-mentioned sources information that relates directly to
of trust in both friend requests and messages from other the individuals’ personal information and any information re-
users. This research also covers reverse social engineering garding the log-on page of the social media website.
attacks where the victim initiates the conversation with the
attacker (Irani et al., 2011). [Link]. Assess gathered information. Determine whether all the
• The SE creates a fake profile that propagates click-bait posts required information to determine the likes and dislikes of each
that all use shortened forms of the Uniform Resource Locator individual have been gathered. Also, assess if enough infor-
(URL). This lets unsuspecting victims click on the links, which mation has been gathered to correctly duplicate the log-on
can lead them to websites containing malware (Ivaturi and screen for the social media website.
Janczewski, 2011).
• The SE crafted malware that was placed on a popular 3.9.3. Step 3: preparation
website for software developers. The malware was adver-
tised as a Java plug-in that could be installed on desktops [Link]. Combination and analysis of gathered information.
(CERT Insider Threat Team, 2014). Develop a combined personality profile based on all the in-
formation gathered from the individuals and determine what
This template illustrates an SEA where the attacker at- type of social media posts will be of interest to these indi-
tempts to obtain log-on credentials from a group of individuals viduals. Also, develop a mock-up of how the log-on screen
who are all using a certain social media website. It is assumed should look, so that the replicated log-on screen looks famil-
that individuals are required to log-on to this website using iar to the individuals when they are required to enter their log-
log-on credentials unique to each individual. Individuals who on credentials during the attack.
use the particular social media website are not allowed to share
their log-on credentials and thus the goal of this attack is [Link]. Development of an attack vector. Develop an attack plan
unauthorised information disclosure. The SE may have a further that details the formulation of a post on which most of the
goal, namely to obtain unauthorised access to the individu- individuals will click, based on their personality profile. In this
al’s social media account, but that is seen as a separate goal. template, the attacker is also required to develop a log-on screen
Once the attacker has obtained the log-on credentials from the that is similar to the original, and that is able to capture the
individual, the SEA is deemed to be successful. log-on credentials when individuals attempt to log-on. Once
The important features of the SEA are specified below: an individual has fallen prey to the attack, each target that has
been compromised by the malicious post will be forced – un-
Communication – The SEA is using indirect communication. beknown to the target – to automatically replicate the attacker’s
Social Engineer – The SE is an individual. social media post to that of the target’s friends.
Target – The target is a group of individuals.
Medium – The communication medium is via a website. In 3.9.4. Step 4: develop relationship
this specific case, it is a social media website.
Goal – The goal of the attack is unauthorised information [Link]. Establishment of communication. This involves the
disclosure from the target to the attacker. physical action of posting the first social media post on the
Compliance Principles – The compliance principles that are social media website.
used are social validation and friendship and liking.
Techniques – The technique that is used is baiting. [Link]. Rapport building. Posts on social media websites are
usually very short and often consist of one or two sentences
The following text dissects and maps the template to the only. The “rapport building” step is mostly performed as a con-
SEAF. tinuous process because individuals trust people with whom
they have been friends on social media for a long period. In
3.9.1. Step 1: attack formulation
this template, the first post by the attacker should be entic-
ing enough for any of the targets to click on it without having
[Link]. Goal identification. The goal of the attack is to get an
gained a lot of trust in the attacker. Once a single individual
individual to provide to the attacker information that the at-
has fallen prey to the attack, he/she will automatically, due to
tacker is not authorised to have.
the malicious post, propagate the post to his/her social media
friends, seeing that a trust relationship already exists between
[Link]. Target identification. The target of the attack is all in-
friends.
dividuals in the group who are using the specific social media
website.
3.9.5. Step 5: exploit relationship
3.9.2. Step 2: information gathering
[Link]. Priming the target. On social media websites, the target
[Link]. Identify potential sources. The information sources is almost already primed to be reading and clicking on posts.
include any information about the social media website, the Individuals usually tend to read social media to find interesting
computers & security 59 (2016) 186–209 201
activities that their friends are participating in or have posted. seek employment. The pamphlet advertises a job opportu-
In the post that the attacker provides, the image that accom- nity and provides a URL to a website where additional
panies the post and the short content description represent information can be found, or where the job seeker must
both the “priming the target” and the “elicitation” steps. apply.
[Link]. Elicitation. The post that is made available by the at- This template illustrates an SEA in which the attacker at-
tacker contains both an image and a short description based tempts to gain unauthorised access to any individual’s
on the personality profile of the group of individuals who are computer. In the current template, fliers appearing to be fines
being targeted. These individuals should be interested in the for traffic violations are placed on different individuals’ cars
subject matter that is posted and thus they would hardly hesi- in a parking lot. On these notices of supposed parking viola-
tate to click on the post and read more about it. Once the tions a website URL is provided where one could view pictures
individual has clicked on the post to read it, it will ask the in- associated with the so-called violation. When the individual
dividual for his/her log-on credentials for the particular social visits the website, a backdoor Trojan is installed onto the in-
media website as if he/she has been logged out. The indi- dividual’s workstation. Once the individual has accessed the
vidual is then prompted to log back in to the social media malicious website, the attacker successfully installs the backdoor
website, after which the post is propagated to all of the tar- Trojan and that SEA is deemed to be successful.
get’s social media friends. This template is now demonstrated through the use of the
SEAF.
3.9.6. Step 6: debrief The important features of the SEA are specified below:
[Link]. Maintenance. In this template, the maintenance of Communication – The SEA is using indirect communica-
rapport actually occurs on the log-on screen and not in the post tion through third-party media.
made on social media. After the targeted individual has logged Social Engineer – The SE is an individual.
on to the fraudulent log-on screen, the information that was Target – The target is an individual. In this instance, it is
discussed in the fraudulent post should be provided, after which any owner of a car parked in the parking lot.
the individual is navigated back to the real social media website. Medium – The communication medium is a flier.
This allows the targeted individual to think that he/she gained Goal – The goal of the attack is to gain unauthorised access
access to the post that he/she wanted to read and the target to an individual’s computer.
remains unaware that all his/her social media friends have also Compliance Principles – The compliance principles that are
been posted the fraudulent post. used are social compliance and authority.
Techniques – The technique that is used is phishing.
[Link]. Transition. The attacker was able to successfully gain
unauthorised information from the target and can thus proceed The following text dissects and maps the template to the
to the “goal satisfaction” step. SEAF.
• The SE creates fake traffic violation notices and places them 3.10.2. Step 2: information gathering
onto cars at a parking lot. The owner of the car returns to
his/her car, finds the notice and later navigates to the URL [Link]. Identify potential sources. Public websites that provide
provided on the traffic violation notice. In this way the owner the feature to view parking violation details and any insti-
of the car is tricked to visit a malicious website. This tem- tute with the authority to issue a parking violation.
plate is directly derived from the example quoted by Zeltser
(2009). [Link]. Gather information from sources. Collect sample
• The SE prints posters that contain a QR code. The poster parking violation notices that are placed on windshields of cars
is then placed close to a popular restaurant and mentions and on sample websites where one can view parking viola-
that scanning this QR code with your phone provides you tion information.
access to a voucher for the restaurant. Upon scanning the
code, the QR code directs the target to a malicious website [Link]. Assess gathered information. Determine which parking
or requests a signup to harvest usernames and passwords violations are relevant to the specific parking lot, perhaps on
(Kieseberg et al., 2010). location, region, etc. In this case, the violation should specifi-
• The SE creates a URL that points to malicious malware on cally conform to the standard parking violations that occur in
a cloud-based system (Gruschka and Jensen, 2010). This URL the target region. Also filter out the website that is consistent
is printed on a pamphlet and provided to job seekers who with the parking violation.
202 computers & security 59 (2016) 186–209
3.10.3. Step 3: preparation The next section briefly discusses the need for these social
engineering attack templates, after which, the usability of the
[Link]. Combination and analysis of gathered information. templates are shown by using them to verify a social engi-
Choose one parking violation and website pair and finalise the neering attack detection model.
structure of the parking violation notice, the style and working
of the website.
4. Application of the social engineering attack
[Link]. Development of an attack vector. Develop a parking templates
violation notice consistent with the finalised structure as well
as a phishing website that looks similar to the one chosen in The social engineering attack templates have been proposed
the previous step. On the parking violation notice, ensure that with the goal in mind to provide researchers with a set of social
there is a section stating that photos with information about engineering attack templates that can be used to verify or
the parking violation are on a certain website, with the URL compare other models, processes and frameworks within social
of the phishing website. engineering. Each template contained the full description of
every phase and associated steps of the social engineering
3.10.4. Step 4: develop relationship attack framework in such a way that each template will provide
repeatable results when used to verify or compare other models,
[Link]. Establishment of communication. This is done via the processes and frameworks. The templates are also kept as
physical action of placing the created fliers on the cars in the simple as possible so that they can be expanded upon to create
parking lot. more elaborate scenarios with exactly the same principal struc-
tures. The templates can also be used to verify or compare other
[Link]. Rapport building. The parking violation notices placed models, processes and frameworks without having to physi-
on the windshields of the cars should be consistent with cally perform the attack and potentially cause harm to innocent
parking violation notices handed out in that parking lot under targets (Mouton et al., 2015).
standard conditions. The owner of the car receiving the vio- In previous research, the authors proposed a social engi-
lation notice should not doubt whether it is official; it should neering attack detection model (SEADM), which was designed
look legitimate. When the target visits the website, the website to allow users of the model to be more vigilant against social
should also appear to be legitimate and may not raise doubt engineering attacks (Mouton et al., 2015). The model is de-
with the user. picted in Fig. 3. This model makes use of a decision tree and
breaks down the process into more manageable components
to aid decision making. The model is discussed in more detail
3.10.5. Step 5: exploit relationship in an article entitled “Social Engineering Attack Detection Model:
SEADMv2” and only a brief summary is provided here to assist
[Link]. Priming the target. The flier should be realistic so that the reader with how the social engineering attack templates
the owner of the car will take it seriously and not simply throw
are mapped to the social engineering attack detection model.
it away. While driving home, the target should ideally think
The model depicts the flow of action and how any type of
about the violation and prepare himself to go to the website
request should be handled by a “receiver”. Throughout this dis-
to view the parking violation, feeling pressured due to social
cussion this term is understood as the person dealing with the
compliance to do the right thing and resolve the violation.
request, while the term “requester” is defined as the person
or object who requests the specific action or information from
[Link]. Elicitation. The attacker provides a URL on the flier the receiver. The model should be used as a guideline to aid
of the phishing website to allow the target to take action. Upon
in decision making and it is an improvement on the initial
typing in the URL, a backdoor is installed on the target’s com-
SEADM due to its ability to cater for both typical requests and
puter, giving the SE the opportunity to gain unauthorised access
inherent requests. This generalisation allows the revised SEADM
to his/her computer.
to cater for the both the unidirectional communication and in-
direct communication categories of social engineering.
3.10.6. Step 6: debrief An example of a typical request is where the requester, in
this case a person, requests the receiver to perform a task/
[Link]. Maintenance. The flier and website should be created favour for him/her. This request can range from the requester
in such a way that the target does not feel threatened. The requesting information about an organisation to the re-
website should be similar to the real violations website so that quester requesting that the receiver performs a password reset
the victim is confident that he/she is performing the correct for an individual’s Internet banking logon.
procedure to resolve the violation. An example of an inherent request is where the receiver
receives a request, in this case an object that contains either
[Link]. Transition. The SE can use the backdoor to gain a request or a process that needs to be completed by the re-
unauthorised access to the computer and can thus proceed to ceiver. This type of request can range from a parking ticket
the “goal satisfaction” step. detailing how to pay the ticket on the pamphlet to a receiver
finding a storage medium device and wanting to return the
[Link]. Goal satisfaction. The SE has attained his initial goal device to its rightful owner. In the case of the parking ticket,
of gaining unauthorised access. the receiver is inherently requested to pay the ticket using the
computers & security 59 (2016) 186–209 203
information on the pamphlet. In the case of the storage device tion about the requester can be verified. The third party states,
the situation is a little bit more complicated. The receiver, upon indicated in red, directly depict the involvement of a third party
finding the device, is inherently requested to return it to its in the model and whether the information about the re-
rightful owner. quester can be externally verified.
The model provides for four different types of states – the The social engineering attack templates, as proposed in this
request, receiver, requester and third party – that provide a brief paper, are used to verify this model and to show the need for
idea of what can be expected to be performed in each state. these proposed social engineering attack templates. Social en-
The request states, indicated in yellow, directly deals with in- gineering is divided into three distinct categories based on the
formation about the request itself. The receiver states, indicated type of communication utilised (see Section 2). The three cat-
in blue, directly deals with the person handling the request and egories are respectively bidirectional communication,
whether this person (the receiver) understands and is allowed unidirectional communication and indirect communication. A
to perform the request. The requester states, indicated in green, template from each of these categories is used to verify that
directly deals with the requester and whether any informa- the model can be used to detect social engineering attacks.
204 computers & security 59 (2016) 186–209
In the first scenario, from the bidirectional communica- the management floor. If the request is successful, access has
tion templates (template in Section 3.1), the social engineer been gained to the management floor, and a key logger is de-
pretends to be someone who works on the management floor ployed onto a workstation. This attack is performed using
and has to convince a cleaner that he is indeed an employee. bidirectional communication because the social engineer com-
He requests the cleaner to give him access to the manage- municates with the cleaner and convinces him that the social
ment floor. In the second scenario, from the unidirectional engineer is allowed to have access to the management floor
communication templates (template in Section 3.7), the social and the workstations.
engineer attempts to obtain financial gain by sending out paper
mail in which the letter requests a group of individuals to make
4.1.1. Do you understand what is requested?
a small deposit into a bank account owned by the attacker. In
The request from the social engineer should clearly state that
the third scenario, from the indirect communication tem-
access needs to be gained to the management floor. The social
plates (template in Section 3.8), the social engineer attempts
engineer can also justify to the receiver why access is re-
to gain unauthorised access to a workstation in an organisation
quired to further allow the receiver to understand the request.
by using a storage medium device.
When the receiver understands the request, the “yes” option
In each scenario the reader is provided with a generic de-
is selected.
scription of the attack as taken from social engineering attack
templates. This generic description is then populated with el-
ements, both subjects and objects, from real-world examples 4.1.2. Do you understand how to perform the request?
of social engineering attacks, as provided in the discussion of The social engineer would have made certain that the tar-
the specific social engineering attack template. Using the generic geted employee fully understands the request, is capable of
description, the elements from the real-world examples and performing the request and has the authority to perform the
the fully detailed flow of the attack as provided in each phase request. This will allow the current step, and the following two
and step of the social engineering attack framework, one is able steps to take the “yes” option.
to devise a social engineering attack scenario. This scenario
is then reflective of a real-world example of which every phase 4.1.3. Are you capable of performing or providing the
and step is fully documented as per the social engineering request?
attack framework. Using the proposed social engineering attack As indicated earlier, the “yes” option is chosen.
templates, one is able to formulate a social engineering attack
scenario that always follows the same process, with regards
4.1.4. Do you have the authority to perform the request?
to phases and steps, whilst the social engineering attack is still
In this scenario, the receiver does not specifically have the au-
representative of a real-world scenario.
thority to grant access to the management floor; however, the
The remainder of this section is dedicated to mapping the
receiver has the authority to deny access. Typically, at this ques-
social engineering attack templates to the social engineering
tion the “no” option should be followed; however, in the scenario
attack detection model and verifying whether the social en-
it is mentioned that the receiver was not trained to be able to
gineering attack detection model can assist in detecting social
handle unusual requests so the receiver assumes that he or
engineering attacks.
she has access to grant the request. Due to the assumption,
the “yes” option is taken.
4.1. Bidirectional communication scenario
The generic description for this scenario (template in Section 4.1.5. Is the requested action or information available to the
3.1) reads as follows: “This template illustrates a SEA where public?
the attacker attempts to gain physical access to a computer- In the scenario only management and cleaners should have
ised terminal at the premises of an organisation. The access to the management floor and thus the “no” option is
assumption is that when the attacker has once gained access chosen.
to the computerised terminal, he/she is deemed to have been
successful. The attacker is now able to install a backdoor onto 4.1.6. Is this a preapproved request that can be performed to
the computerised terminal for future and further access avoid a life-threatening emergency?
from the outside.” This scenario is populated with elements This is not a life-threatening request and thus the “no” option
from the real-world example where the social engineer pre- is selected.
tends to be someone who works on the management floor and
convinces a cleaner of his supposed role. The cleaner grants
4.1.7. Are any of these conditions for refusal true?
the social engineer access to the building. This allows the social
Seeing that the requested access is an unusual request, as dis-
engineer to gain physical access to the computerised termi-
cussed in the description, the “yes” option is selected.
nals on the management floor (Dimkov et al., 2010; Janczewski
and Fu, 2010).
In this scenario a social engineer has to convince the cleaner, 4.1.8. Is the requester’s identity verifiable?
the receiver, to believe that he is indeed a staff member. In this In this case, bidirectional communication is utilised; thus it
scenario, the cleaners have full access to the building, yet, their allows for the receiver to communicate back via face to face
security awareness is very low. They are not trained to respond communication and ask more questions to verify the re-
to unusual requests such as giving other employees access to quester. Hence the “yes” option is taken.
computers & security 59 (2016) 186–209 205
4.1.9. How many verification requirements hold? 4.2.1. Do you understand what is requested?
In this case, the authority principle is utilised and the social The letter from the social engineer should clearly state that
engineer mimics an authoritative figure whom should have a receiver is requested to make a donation to the specific charity.
access to the management floor. The pretext utilised during The letter will include all the required details because this re-
this attack is that the social engineer is part of management ceiver cannot communicate with the social engineer. The “yes”
and that he or she should have access to the management floor. option is taken.
The receiver is only able to verify the authority level, even if
it is false information, from the social engineer in this sce- 4.2.2. Do you understand how to perform the request?
nario. Since only a single verification requirement is met, the The social engineer would have ensured that the targeted in-
“one to two” option is selected. dividual fully understands the request, is capable of performing
the request and has the authority to perform the request. This
4.1.10. Can you verify the requester through a third party will cause the receiver to select the “yes” option in this step,
source? as well as in the following two steps.
The receiver will now have the ability to verify the informa-
tion from another employee on the management floor. In the
4.2.3. Are you capable of performing or providing the
case that there are no other employees on the management
request?
floor, the “no” option will be taken and the social engineering
As indicated before, the “yes” option is taken.
attack will be thwarted. It is assumed that there are other people
on the management floor who can be contacted to verify the
information and thus the “yes” option is taken. 4.2.4. Do you have the authority to perform the request?
As was the case earlier, the “yes” option is chosen.
4.1.11. Does the verification process reflect the same
information as the verification requirements? 4.2.5. Is the requested action or information available to the
It is at this step that the receiver will be able to ask the other public?
employee whether the authority level of the social engineer The requested action is to make a deposit into the bank account
is indeed true. The other employee will deny this and thus the of the requester. This request is directed at the receiver and
verification process will show that the information provided not at the public. The action of the specific receiver making a
is not the same as the verification requirements. Conse- deposit is only available to the specific receiver, thus the “no”
quently, the “no” option will be taken and the social engineering option is taken.
attack will be thwarted.
4.2.6. Is this a preapproved request that can be performed to
4.2. Unidirectional communication scenario avoid a life-threatening emergency?
This is not a life-threatening request and thus the “no” option
The generic description for this scenario (template in Section is selected.
3.7) reads as follows: “This template illustrates an SEA in which
the attacker attempts to obtain financial gain by sending out
4.2.7. Are any of these conditions for refusal true?
paper mail. This letter requests a group of individuals to make
This request can be seen as either unusual or new as the re-
a small deposit into a bank account owned by the attacker. In
quester would not usually receive this specific type of letter
this template, the attacker develops a phishing letter that masks
from the charity. It can also be the case that the requester feels
the attacker as a charity organisation requesting donations.
uneasy about the request and his or her uneasiness about the
Once the attacker has received the small deposit from the tar-
request can be seen as a reason to refuse at this point. The “yes”
geted individual, the SEA is deemed to be successful.” This
option is selected because there is sufficient reason to refuse
scenario is populated with elements from the real-world
the request without even verifying the identity of the requester.
example where the social engineer performs a pretext using
postal letters. The social engineer pretends to be various of-
ficials, internal employees, employees of trading partners, 4.2.8. Is the requester’s identity verifiable?
customers, utility companies or financial institutions and the Since unidirectional communication is utilised in this case, the
social engineer solicits confidential information by using a wide receiver can only verify the identity using the information as
range of persuasive techniques (Workman, 2008). provided in the letter. At this point one can defer or refer the
In this scenario, a social engineer attempts to obtain fi- request if it does not contain additional information such as
nancial gain by sending out paper mail. In the letter, a group the requester’s contact details. In the current scenario, the letter
of individuals are requested to make a small deposit into a bank actually contains the contact details of the charity organisation
account owned by the attacker. In this scenario, the attacker and thus the “yes” option is chosen.
will develop a phishing letter that masks the attacker as a
charity organisation requesting donations. The phishing letter 4.2.9. How many verification requirements hold?
contains the contact details, the logo and the purpose of the The requirement that the receiver should be aware of the ex-
charity to improve the authenticity of the letter. This attack istence of the requester will definitely hold, because the social
uses unidirectional communication and thus the receiver is engineer would have chosen a well-known charity. One can also
not able to communicate with the attacker. The rest of this argue that receiver may have had a previous interaction with
section maps the scenario to the model. the charity; however, from the letter alone, the authority and
206 computers & security 59 (2016) 186–209
credibility of the requester cannot be verified. In this case the inherent request that the receiver should return the device, the
“one to two” option is selected. request is easily understandable and the “yes” option is selected.
information is continuously improved, the one weak point trolled experiment can be performed comparing the
remains the human being who is susceptible to manipula- performance of individuals who had access to the awareness
tion techniques. The current paper explored social engineering material versus individuals who did not have access. Also, the
as a domain and social engineering attacks as a process inside authors will use these templates to expand on existing re-
this domain. Two previous papers by the authors, Towards an search on social engineering attack detection models and to
Ontological Model Defining the Social Engineering Domain (Mouton propose specific attack detection models for each type of
et al., 2014) and Social Engineering Attack Framework (Mouton et al., communication.
2014), are revisited. Both the ontological model and the social
engineering attack framework are explored in order to further
expand the social engineering domain. REFERENCES
The authors found that reports and news articles on social
engineering do not provide all the information on social en-
gineering attacks. There is usually no information available on Abraham S, Chengalur-Smith I. An overview of social
either the “attack formulation” phase or the “information gath- engineering malware: trends, tactics, and implications.
ering” phase. There is also very little information on the “exploit Technol Soc 2010;32(3):183–96. <[Link]
[Link].2010.07.001>, <[Link]
relationship” phase, because reports or news articles tend to
science/article/pii/S0160791X10000497>.
mention only the technique that was used and that it was suc-
Åhlfeldt R-M, Backlund P, Wangler B, Söderström E. Security
cessful. In order to do comparative studies of social engineering issues in health care process integration? A research-in-
models, processes and frameworks, it is essential to have a set progress report, in: EMOI-INTEROP, 2005, pp. 1–4.
of fully detailed social engineering attack templates. Bader G, Anjomshoaa A, Tjoa A. Privacy aspects of mashup
This paper proposed ten templates that provide fully de- architecture, in: Social Computing (SocialCom), 2010 IEEE
tailed steps and phases throughout a social engineering Second International Conference on, 2010, pp. 1141–6.
doi:10.1109/SocialCom.2010.169.
attack. These templates were designed to be diverse and
Brainard J, Juels A, Rivest RL, Szydlo M, Yung M. Fourth-factor
unique so that there is little overlap between each of them. authentication: somebody you know, in: Proceedings of the
The templates were also categorised based on the type of com- 13th ACM Conference on Computer and Communications
munication that was utilised. The authors proposed four Security, CCS ’06, ACM, New York, NY, USA, 2006, pp. 168–78.
templates in which bidirectional communication was used, doi:10.1145/1180405.1180427. [Link]
three for unidirectional communication and three for indi- 1180405.1180427.
rect communication. Brody RG, Brizzee WB, Cano L. Flying under the radar: social
engineering. Int J Account Inf Manage 2012;20(4):335–47.
This paper also demonstrated the need for the social en-
doi:10.1108/18347641211272731.
gineering attack templates and how they can be used to verify Brown G, Howe T, Ihbe M, Prakash A, Borders K. Social networks
or compare other models, processes and frameworks within and context-aware spam, in: Proceedings of the 2008 ACM
social engineering. The social engineering attack templates were Conference on Computer Supported Cooperative Work, CSCW
used to create social engineering attack scenarios that were ’08, ACM, New York, NY, USA, 2008, pp. 403–12. doi:10.1145/
used to verify the social engineering attack detection model. 1460563.1460628. [Link]
CERT Insider Threat Team, Unintentional insider threats: a
Having the social engineering attack templates, the research-
foundational study, Tech. Rep. CMU/SEI-2013-TN-022,
ers were able to verify whether the social engineering attack
Software Engineering Institute, Carnegie Mellon University,
detection model was able to assist users of the model to be Pittsburgh, PA; 2013. [Link]
more vigilant against social engineering attacks. [Link]?AssetID=58744.
The proposed social engineering attack templates can now CERT Insider Threat Team, Unintentional insider threats: social
be used as a resource by researchers to expand on, use for com- engineering, Tech. Rep. CMU/SEI-2013-TN-024, Software
parative measures, create additional template or evaluate Engineering Institute, Carnegie Mellon University, Pittsburgh,
PA; 2014. [Link]
models for completeness. Having the social engineering attack
[Link]?AssetID=77455.
templates, researchers are able to verify their models, pro- Culpepper AM. Effectiveness of using red teams to identify
cesses and frameworks and compare their performances against maritime security vulnerabilities to terrorist attack [Master’s
other models, processes and frameworks. The templates provide thesis]. Naval Postgraduate School, Monterey, California;
a repeatable instance of a social engineering attack that can 2004.
be stepped through a model, process or framework without the Dang H. The origins of social engineering. McAfee Secur J
need to perform the attack and potentially harming individuals. 2008;1(1):4–9.
Dimkov T, van Cleeff A, Pieters W, Hartel P. Two methodologies
Additionally, the proposed social engineering attack tem-
for physical penetration testing using social engineering, in:
plates can also be used to develop social engineering awareness Proceedings of the 26th Annual Computer Security
material. The templates can be used to develop social engi- Applications Conference, ACSAC ’10, ACM, New York, NY, USA,
neering attack scenarios that are populated with subjects and 2010, pp. 399–408. doi:10.1145/1920261.1920319. http://
objects of an organisation in order to demonstrate scenarios [Link]/10.1145/1920261.1920319.
that are applicable to a specific environment. These scenarios Dittes JE, Kelley HH. Effects of different conditions of acceptance
upon conformity to group norms. J Abnorm Soc Psychol
can then be discussed with the individuals from the
1956;53(1):100–7. doi:10.1037/h0047855.
organisation in a way that enhances the individual’s security
Esmail S. eps1.5_br4ve-[Link] , mr. Robot: Season 1. Episode
awareness to be more vigilant against such a type of an attack. 2015;6:URL: <[Link]
In future work, the social engineering attack templates can -guide/season-1-episode-6-eps15br4ve-trave1erasf>; [cited
be utilised as social engineering awareness material. A con- 2015.08.19].
208 computers & security 59 (2016) 186–209
Gerard HB, Wilhelmy RA, Conolley ES. Conformity and group European Conference on, 2010, pp. 46–52. doi:10.1109/
size. J Pers Soc Psychol 1968;8(1p1):79–82. doi:10.1037/ EC2ND.2010.16.
h0025325. Kieseberg P, Leithner M, Mulazzani M, Munroe L, Schrittwieser S,
Granger S. Social engineering fundamentals, part i: Hacker Sinha M, et al., QR code security, in: Proceedings of the 8th
tactics (December 2001) URL: <[Link] International Conference on Advances in Mobile Computing
connect/articles/social-engineering-fundamentals-part-i and Multimedia, MoMM ’10, ACM, New York, NY, USA, 2010,
-hacker-tactics>; [cited 2013.11.11]. pp. 430–5. doi:10.1145/1971519.1971593. [Link]
Greitzer FL, Strozer JR, Cohen S, Moore AP, Mundie D, Cowley J. 10.1145/1971519.1971593.
Analysis of unintentional insider threats deriving from social Kingsley Ezechi A. Detecting and combating malware [Master’s
engineering exploits, in: IEEE Security and Privacy Workshops thesis]. University of Debrecen, Hungary; 2011. http://
(SPW 2014), San Jose, California, USA, 2014, pp. 236–50. [Link]/2437/105305.
doi:10.1109/SPW.2014.39. Krombholz K, Hobel H, Huber M, Weippl E. Social engineering
Greitzer FL, Strozer J, Cohen S, Bergey J, Cowley J, Moore A, et al., attacks on the knowledge worker, in: Proceedings of the 6th
Unintentional insider threat: contributing factors, International Conference on Security of Information and
observables, and mitigation strategies, in: 47th Hawaii Networks, SIN ’13, ACM, New York, NY, USA, 2013, pp. 28–35.
International Conference on Systems Sciences (HICSS-47), Big doi:10.1145/2523514.2523596. [Link]
Island, Hawaii, 2014, pp. 2025–34. doi:10.1109/HICSS.2014.256. 2523514.2523596.
Gruschka N, Jensen M. Attack surfaces: a taxonomy for attacks Laribee L. Development of methodical social engineering
on cloud services, in: Cloud Computing (CLOUD), 2010 IEEE taxonomy project, Msc, Naval Postgraduate School, Monterey,
3rd International Conference on, IEEE Computer Society, Los California; 2006.
Alamitos, CA, USA, 2010, pp. 276–9. [Link] Lenkart JJ. The vulnerability of social networking media and the
.[Link]/10.1109/CLOUD.2010.23. insider threat new eyes for bad guys [Master’s thesis]. Naval
Hadnagy C. Social engineering: the art of human hacking. Wiley Postgraduate School, Monterey, California; 2011. http://
Publishing, Inc.; 2010. [Link]/public/handle/10945/5562.
Hamill JT, Deckro RF, Kloeber JM Jr. Evaluating information Long J. No tech hacking: a guide to social engineering, dumpster
assurance strategies. Decis Support Syst 2005;39(3):463–84. diving, and shoulder surfing. Syngress; 2011.
<[Link] <[Link] Lott AJ, Lott BE. Group cohesiveness, communication level, and
.[Link]/science/article/pii/S0167923604000284>. conformity. J Abnorm Soc Psychol 1961;62(2):408–12.
Harley D. Re-floating the titanic: dealing with social engineering doi:10.1037/h0041109.
attacks, in: European Institute for Computer Antivirus Major SDA. Social engineering: hacking the wetware! Inf Secur J
Research, 1998, pp. 4–29. Global Persp 2009;18(1):40–6. doi:10.1080/19393550802623214.
Hill D. Peer group conformity in adolescent smoking and its Mitnick KD, Simon WL. The art of deception: controlling the
relationship to affiliation and autonomy needs. Aust J Psychol human element of security. Indianapolis: Wiley Publishing;
1971;23(2):189–99. doi:10.1080/00049537108254613. <http:// 2002.
[Link]/doi/pdf/10.1080/00049537108254613>, Mohd Foozy F, Ahmad R, Abdollah M, Yusof R, Mas’ud M. Generic
<[Link] taxonomy of social engineering attack, in: Malaysian
00049537108254613>. Technical Universities International Conference on
Insko CA, Smith RH, Alicke MD, Wade J, Taylor S. Conformity and Engineering & Technology, Batu Pahat, Johor, 2011, pp. 1–7.
group size the concern with being right and the concern with Mouton F, Malan M, Venter H. Development of cognitive
being liked. Pers Soc Psychol Bull 1985;11(1):41–50. functioning psychological measures for the SEADM, in:
doi:10.1177/0146167285111004. Human Aspects of Information Security & Assurance, Crete,
Irani D, Balduzzi M, Balzarotti D, Kirda E, Pu C. Reverse social Greece, 2012, pp. 40–51.
engineering attacks in online social networks. In: Holz T, Bos Mouton F, Malan MM, Venter HS. Social engineering from a
H, editors. Detection of intrusions and malware, and normative ethics perspective, in: Information Security for
vulnerability assessment, vol. 6739 of lecture notes in South Africa, Johannesburg, South Africa, 2013, pp. 1–8.
computer science. Springer Berlin Heidelberg; 2011. doi:10.1109/ISSA.2013.6641064.
p. 55–74. Mouton F, Leenen L, Malan MM, Venter H. Towards an ontological
Ivaturi K, Janczewski L. A taxonomy for social engineering model defining the social engineering domain. In: Kimppa K,
attacks, in: G. Grant (Ed.), International Conference on Whitehouse D, Kuusela T, Phahlamohlaka J, editors. ICT and
Information Resources Management, Centre for Information society, vol. 431 of IFIP advances in information and
Technology, Organizations, and People, 2011, pp. 1–12. communication technology. Springer Berlin Heidelberg; 2014.
Jagatic TN, Johnson NA, Jakobsson M, Menczer F. Social phishing. p. 266–79.
Commun ACM 2007;50(10):94–100. doi:10.1145/1290958 Mouton F, Malan MM, Leenen L, Venter H. Social engineering
.1290968. <[Link] attack framework, in: Information Security for South Africa,
Jahankhani H. The behaviour and perceptions of on-line Johannesburg, South Africa, 2014, pp. 1–9. doi:10.1109/
consumers: risk, risk perception and trust. Int J Inf Sci ISSA.2014.6950510.
Manage 2012;7(1):79–90. Mouton F, Leenen L, Venter HS. Social engineering attack
Janczewski L, Fu L. Social engineering-based attacks: model and detection model: SEADMv2, in: International Conference on
New Zealand perspective, in: Computer Science and Cyberworlds (CW), Visby, Sweden, 2015, pp. 216–23.
Information Technology (IMCSIT), Proceedings of the 2010 doi:10.1109/CW.2015.52.
International Multiconference on, 2010, pp. 847–53. Mouton F, Malan MM, Kimppa KK, Venter H. Necessity for ethics
doi:10.1109/IMCSIT.2010.5680026. in social engineering research. Comput Secur 2015;55:
Jetten J, Hornsey MJ, Adarves-Yorno I. When group members 114–27. <[Link] <http://
admit to being conformist: the role of relative intragroup www
status in conformity self-reports. Pers Soc Psychol Bull .[Link]/science/article/pii/S0167404815001224>.
2006;32(2):162–73. doi:10.1177/0146167205279904. Nohlberg M. Securing information assets: understanding,
Jodeit M, Johns M. USB device drivers: a stepping stone into your measuring and protecting against social engineering attacks
kernel, in: Computer Network Defense (EC2ND), 2010 [Ph.D. thesis]. Stockholm University; 2008.
computers & security 59 (2016) 186–209 209
Noy NF, McGuinness DL. Ontology development 101: a guide to USA, 2004, pp. 133–5. doi:10.1145/1059524.1059554. http://
creating your first ontology, Technical report ksl-01-05, [Link]/10.1145/1059524.1059554.
Stanford Knowledge Systems Laboratory; 2001. Workman M. A test of interventions for security threats from
Peltier TR. Social engineering: concepts and solutions. Inf Syst social engineering. Inf Manage Comput Secur 2008;16(5):463–
Secur 2006;15(5):13–21. doi:10.1201/1086.1065898X/46353 83.
.15.4.20060901/95427.3. <[Link] Zeltser L. Malware infection that began with windshield fliers
10.1201/1086.1065898X/46353.15.4.20060901/95427.3>, <http:// (February 2009) URL: <[Link] [cited
[Link]/doi/abs/10.1201/1086.1065898X/46353 2014.02.24].
.15.4.20060901/95427.3>.
Rao U, Nayak U. Social engineering. In: The InfoSec handbook. Francois Mouton is a senior information warfare researcher at the
Apress; 2014. p. 307–23. Council for Scientific and Industrial Research (CSIR) with exper-
Salem O, Hossain A, Kamala M. Awareness program and AI based tise in the fields of social engineering, mobile security and digital
tool to reduce risk of phishing attacks, in: Computer and forensics. Francois graduated with an [Link]. Computer Science, in
Information Technology (CIT), 2010 IEEE 10th International the field of digital forensics, from the University of Pretoria in 2012.
Conference on, 2010, pp. 1418–23. doi:10.1109/CIT.2010.254. During his [Link]. degree he also completed all the undergraduate
Schrittwieser S, Frühwirt P, Kieseberg P, Leithner M, Mulazzani BA Psychology modules due to his passion in the field of social en-
M, Huber M, et al., Guess who’s texting you? Evaluating the gineering. He is currently pursuing his PhD Computer Science, with
security of smartphone messaging applications, in: Network a main focus on social engineering, at the University of Pretoria.
and Distributed System Security Symposium, 2012, pp. 1–9. He has (co)authored several international publications, mainly on
Simon HA. Models of man; social and rational. Oxford, England: topics of digital forensics readiness and social engineering. Fran-
Wiley; 1957. cois is currently leading the development on mobile security related
Stasiukonis S. Social engineering, the usb way (June 2006) URL: projects within the CSIR.
<[Link]
-[Link]>; [cited 2015.08.13]. Dr Louise Leenen is a Senior Researcher in the Cyber Defence re-
Symantec Security Response, Francophoned? a sophisticated search Group at the Council for Scientific and Industrial Research
social engineering attack (January 2014) URL: <http:// (CSIR), South Africa. She holds a PhD Computer Science (in Con-
[Link]/connect/blogs/francophoned straint Programming) from the University of Wollongong in Australia.
-sophisticated-social-engineering-attack>; [cited 2014.02.24]. Her research focus is on artificial intelligence applications in the
Tam L, Glassman M, Vandenwauver M. The psychology of defence environment, cyber defence and ontology development. She
password management: a tradeoff between security and is the Chair of the IFIP Working Group 9.10 on ICT in War and Peace.
convenience. Behav Inf Technol 2010;29(3):233–44. doi:10.1080/
01449290903121386. <[Link] Prof H.S Venter has established an international research reputa-
01449290903121386>, <[Link] tion in digital forensics, information privacy, computer-based trust
01449290903121386>. and information security management. Over the past 8 years, Prof
Tetri P, Vuorinen J. Dissecting social engineering. Behav Inf Venter has been focusing mainly on digital forensic research. Prof
Technol 2013;32(10):1014–23. Venter is the research group leader for the Information and Com-
Thornburgh T. Social engineering: the “dark art”, in: Proceedings puter Security Architectures (ICSA) research group at the University
of the 1st annual conference on Information security of Pretoria, where he supervises more than 30 honours, masters
curriculum development, InfoSecCD ‘04, ACM, New York, NY, and doctoral students.
To protect against pretexting, organizations can implement multi-layered security strategies including rigorous identity verification processes and employee training programs designed to recognize social engineering tactics. Training should emphasize skepticism of unsolicited requests, even if they appear to come from authoritative figures . Additionally, establishing strict protocols for sharing information and requiring higher-level approval for sensitive actions can deter employees from inadvertently assisting attackers. Regular security audits and simulated social engineering attempts can test and strengthen organizational defenses .
Urgency is a potent psychological tool in social engineering as it triggers the target's instinct to act quickly without thoroughly considering the consequences. Attackers create a false sense of emergency to pressure targets into bypassing standard security procedures – for instance, insisting on the immediate need for access to retrieve crucial documents or resolve critical issues . The tactic exploits the target's desire to assist in what seems like a crisis, reducing their likelihood of questioning the requester's legitimacy. Studies on human behavior and decision-making under stress reveal that individuals are more likely to comply with urgent requests, especially when perceived authority figures are involved .
To mitigate the risk of social engineers exploiting face-to-face interactions, organizations can enforce strict access control measures such as employee ID verification at entry points, use of biometric systems, and visitor management protocols including pre-registration and escorting visitors at all times . Additionally, organizations should cultivate a security-first culture among employees, encouraging vigilance and reporting of suspicious behavior, and conduct regular security training sessions that include recognizing and responding to social engineering scenarios. Surveillance systems and physical barriers such as turnstiles or secure doors can further prevent unauthorized access .
Preventing social engineering attacks that employ indirect communication channels, such as phishing emails or fake social media profiles, presents significant challenges for organizations. These attacks often exploit widely known communication methods and trusted networks, making them harder to detect using conventional security measures . Additionally, the scalability and anonymity offered by digital channels allow attackers to target large numbers of individuals simultaneously, increasing the likelihood of successful breaches. Organizations face the difficulty of educating users to recognize subtle phishing signs and must implement comprehensive, behavior-based detection systems to mitigate these threats effectively. Proactive monitoring of digital platforms and rigorous employee training are essential to counteract these tactics but require substantial investment and ongoing effort .
Reverse social engineering in online social networks involves presenting oneself as a knowledgeable or authoritative figure, prompting the victim to initiate contact. This can be achieved by creating credible profiles or posts indicating expertise or insights into subjects that interest the target . Once the victim reaches out for advice or assistance, the social engineer can subtly guide the conversation to extract sensitive information, manipulate the target into downloading malicious software, or otherwise compromise their security by capitalizing on the trust established through the initial contact .
Baiting exploits the natural curiosity and greed of individuals by offering enticing content or incentives to lure victims into performing actions that compromise their security. On social networking platforms, baiting might involve sharing links to sensational stories, downloadable content, or fictional materials that require entering credentials or downloading malware to access . Because users on social media platforms often overlook potential risks when faced with compelling bait, they are more likely to engage with and believe these traps, leading to unauthorized data disclosure or malware infections .
Knowledge of an organization's language and culture significantly enhances the effectiveness of social engineering attacks by increasing the attacker's credibility and reducing suspicion. When a social engineer uses industry-specific jargon and mimics organizational protocols, they are seen as insiders, which can lead help-desk staff or employees to lower their guard . This familiarity facilitates gaining trust and bypassing security checks that depend on the assumption that only legitimate members possess such knowledge . The ability to convincingly navigate these cultural and linguistic aspects makes it easier for attackers to solicit sensitive information or persuade targets to comply with harmful requests .
Indirect communication in social engineering attacks leverages platforms like social media to extract information by exploiting user behaviors and trust. Attackers may create context-aware spam or phishing emails that are sent to users. Social engineers also craft fake profiles with click-bait content that lures users into revealing personal information . Additionally, exploiting the high level of trust users place in friend requests and messages on social networking sites, attackers can design scenarios where victims are prompted to disclose information or take actions that result in unauthorized information disclosure .
Social engineering attacks on social media often involve compliance principles such as social validation and friendship and liking. Social validation leverages the target's inclination to conform to perceived social norms, making them more likely to accept fake profiles or click on malicious links that appear popular or endorsed by their network . Friendship and liking involve building rapport or establishing false connections with the victim, which can result in victims willingly sharing sensitive information like log-on credentials because they perceive the attacker as trustworthy or similar to themselves . These psychological principles are effective in manipulating users by bypassing logical defenses in favor of emotional responses. .
Social engineers exploit compliance principles by assuming positions or personas that carry authority, such as pretending to be maintenance or management staff. By doing so, they leverage authority to gain the trust of targets, such as cleaners or security staff . For example, a social engineer might masquerade as a high-ranking employee to manipulate others into granting physical access to secure areas or computer terminals. The principles of commitment and consistency are similarly exploited, as individuals who have begun to assist the social engineer might continue to do so to remain consistent with their initial actions .