0% found this document useful (0 votes)
18 views9 pages

Social Engineering Attack Framework Overview

This paper presents a social engineering attack framework that builds upon Kevin Mitnick's attack cycle, addressing its shortcomings and focusing on the entire process of social engineering attacks. The framework incorporates an ontological model to define the components of such attacks and allows for the mapping of historical attacks to standardized scenarios, aiding in awareness and countermeasure development. The authors emphasize the importance of understanding the human element in security and propose detailed steps for executing social engineering attacks, including information gathering and establishing trust with targets.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views9 pages

Social Engineering Attack Framework Overview

This paper presents a social engineering attack framework that builds upon Kevin Mitnick's attack cycle, addressing its shortcomings and focusing on the entire process of social engineering attacks. The framework incorporates an ontological model to define the components of such attacks and allows for the mapping of historical attacks to standardized scenarios, aiding in awareness and countermeasure development. The authors emphasize the importance of understanding the human element in security and propose detailed steps for executing social engineering attacks, including information gathering and establishing trust with targets.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Social Engineering Attack Framework

Francois Mouton∗ , Mercia M. Malan† , Louise Leenen∗ and H.S. Venter‡


∗ Defence Peace Safety & Security, Council for Industrial and Scientific Research
Pretoria, South Africa
E-mail: moutonf@[Link], lleenen@[Link]
† University of Pretoria, Information and Computer Security Architecture

Pretoria, South Africa


E-mail: malan747@[Link]
‡ University of Pretoria, Department of Computer Science

Pretoria, South Africa


E-mail: hventer@[Link]

Abstract—The field of information security is a fast growing which subsequently allow unauthorised individuals to access
discipline. Even though the effectiveness of security measures protected systems.
to protect sensitive information is increasing, people remain The ‘art’ of influencing people to divulge sensitive informa-
susceptible to manipulation and the human element is thus a
weak link. A social engineering attack targets this weakness by tion is known as social engineering and the process of doing
using various manipulation techniques in order to elicit sensitive so is known as a social engineering attack. There are various
information. The field of social engineering is still in its infancy definitions of social engineering and a number of different
stages with regards to formal definitions and attack frameworks. models of a social engineering attack [1]. The authors consid-
This paper proposes a social engineering attack framework ered a number of definitions of social engineering and social
based on Kevin Mitnick’s social engineering attack cycle. The
attack framework addresses shortcomings of Mitnick’s social
engineering attack taxonomies in a previous paper, Towards an
engineering attack cycle and focuses on every step of the social Ontological Model Defining the Social Engineering Domain
engineering attack from determining the goal of an attack up [1], and formulated a standardised, detailed definition. They
to the successful conclusion of the attack. The authors use a also proposed an ontological model for a social engineering
previously proposed social engineering attack ontological model attack. The authors define social engineering as “the science of
which provides a formal definition for a social engineering attack.
The ontological model contains all the components of a social
using social interaction as a means to persuade an individual
engineering attack and the social engineering attack framework or an organisation to comply with a specific request from an
presented in this paper is able to represent temporal data attacker where either the social interaction, the persuasion or
such as flow and time. Furthermore, this paper demonstrates the request involves a computer-related entity” [1].
how historical social engineering attacks can be mapped to The previously proposed ontological model includes compo-
the social engineering attack framework. By combining the
ontological model and the attack framework, one is able to
nents of a social engineering attack and divides the attack into
generate social engineering attack scenarios and to map historical different classes and subclasses. The two classes of a social
social engineering attacks to a standardised format. Scenario engineering attack are: Direct communication and indirect
generation and analysis of previous attacks are useful for the de- communication. The direct communication class is further
velopment of awareness, training purposes and the development divided into two subclasses: Bidirectional communication and
of countermeasures against social engineering attacks.
unidirectional communication. A social engineering attack is
Index Terms—Bidirectional Communication, Indirect Commu-
nication, Mitnick’s Attack Cycle, Ontological Model, Social En- then further explained to contain the following components:
gineering, Social Engineering Attack, Social Engineering Attack one Social Engineer; one Target; one or more Compliance
Framework, Unidirectional Communication. Principles; one or more Techniques; one Medium; and one
Goal [1].
I. I NTRODUCTION Although the ontological model contains all the components
of a social engineering attack, an ontological model struggles
The field of information security is a fast growing disci- to depict temporal data, such as flow and time [2]. One
pline. The protection of information is of vital importance to of the main features of an ontology is that it separates the
organisations and governments, and the development of coun- domain knowledge from the operational knowledge [2]. Due
termeasures against illegal access to information is an area that to this shortcoming, the ontological model is not sufficient
receives increasing attention. Organisations and governments to depict the process and the steps involved in executing
have a vested interest in securing sensitive information and a social engineering attack. The purpose of this paper is
thus securing the trust of clients and citizens. Technology on its to present a social engineering attack framework which, in
own is not a sufficient safeguard against information theft; staff conjunction with the ontological model, investigate the attack
is often the weak link in an information security system. Staff process in detail. The framework refers to the components
members can be influenced to divulge sensitive information in the ontological model, but focuses on the process flow

978-1-4799-3384-6/14/$31.00 ©2014 IEEE


Authorized licensed use limited to: UNIVERSIDADE DE BRASILIA. Downloaded on December 06,2024 at 19:26:49 UTC from IEEE Xplore. Restrictions apply.
starting at the point at which an attacker initially thinks about identity, citing those known to the victim, showing a need
gaining sensitive information from some target up to the point for assistance, or occupying an authoritative role.
of succeeding in the goal of gaining this information. When a target appears to trust an attacker, the attacker
The ontological model provides the basic structure of a Exploits the trust to elicit information from the target: this
social engineering attack whereas the social engineering attack can either take the form of a request for information, a request
framework adds both time and flow components. The combi- for a specified action from the victim or, alternatively, to
nation of the ontological model and the attack framework can manipulate the victim into asking the attacker for help [8].
be used to generate social engineering attack scenarios and This phase is where the previously established relationship is
to map historical social engineering attacks to a standardised abused to get the initially desired information or action.
format. These scenarios are useful to educate individuals Finally, the outcome of the previous phase is Utilised to
about social engineering and to gauge their awareness of reach the goal of the attack or to move on to further steps
social engineering. Scenario generation is also useful in the which may be required to reach the goal.
development of countermeasures against attacks. Having a A trivial example is when an attacker supposedly needs
standardised formulation of a social engineering attack as well to connect to an organisation’s network. As a result of his
as the flow and time events, allow researchers to compare research the attacker finds out that a help-desk staff member
different social engineering attacks. knows the password to the organisation’s wireless network.
Section II provides a background on social engineering In addition, the attacker found personal information regarding
attacks and further discusses the authors’ previous work. the staff member who has been identified as the target.
Section III discusses the proposed social engineering attack The attacker initiates a conversation with the target, using
framework and section IV provides some applications of the the acquired information to establish trust; in this case the
social engineering attack framework. Section V concludes the attacker misrepresents himself as an old school acquaintance
paper. of the target. The attacker subsequently exploits the established
II. D EFINING S OCIAL E NGINEERING trust by asking permission to use the company’s wireless
ATTACKS network facility to send an e-mail. The help-desk attendant is
willing to supply the required password to the attacker due
There are many models and taxonomies concerning social to the misrepresentation, and is able to gain access to the
engineering attacks which are explored and analysed in the organisation’s network and achieve his objective.
author’s previous paper [1] such as [3], [4], [5], [6], [7].
The authors’ ontological model defines that a social en-
The most commonly known model is Kevin Mitnick’s social
gineering attack “employs either direct communication or
engineering attack cycle as described in his book, The art
indirect communication, and has a social engineer, a target,
of deception: controlling the human element of security, [8].
a medium, a goal, one or more compliance principles and one
Mitnick’s attack model has four phases: research, developing
or more techniques” [1]. The attack can be split into more
rapport and trust, exploiting trust and utilising information.
than one attack phase, each phase handled as a new attack
These four phases are not explained in great detail in Mitnick’s
according to the model. The model is depicted in figure 2.
book.
The picture below is a representation of Mitnick’s attack
cycle created by the authors. Figure 1 depicts the four phases
and the flow between each of the phases. Each of these phases
are briefly discussed below as explained in Mitnick’s book.

Fig. 1. Kevin Mitnick’s Social Engineering Attack Cycle

Research is an information gathering process where infor- Fig. 2. An Ontological Model of a Social Engineering attack
mation about the target is retrieved. The attacker should know
as much as possible about the target before starting the attack. Direct communication, where two or more people commu-
The next phase is the Development of the rapport and nicating directly with each other, is sub-divided into “Bidirec-
trust with the target. A target is more likely to divulge tional communication” and “Unidirectional communication”.
requested information to an attacker if he trusts the attacker. Bidirectional communication occurs when both parties partic-
According to Mitnick [8], rapport and trust development can ipate in the conversation. For example, an e-mail is sent from
be done by using insider information, misrepresenting an the attacker to the target and the target replies to the attacker.

978-1-4799-3384-6/14/$31.00 ©2014 IEEE


Authorized licensed use limited to: UNIVERSIDADE DE BRASILIA. Downloaded on December 06,2024 at 19:26:49 UTC from IEEE Xplore. Restrictions apply.
Unidirectional communication occurs when the conversation
is one-way only: from the attacker to the target. For example,
if the attacker sends a message through paper mail without a
return address, the target cannot reply to the message. Phishing
attacks are also a popular type of attack in this category.
Indirect communication is when there is no actual interac-
tion between the target and the attacker; communication occurs
through some third party medium. An example of this type of
communication is when the attacker infects a flash drive and
leaves it somewhere to be found by some target. The target is
curious to find out what is on the flash drive for personal gain
or, motivated by ethical consideration, to attempt to find the
owner of the flash drive. The target inserts the flash drive into
their computer, and the infection on the flash drive is activated.
The ontological model further contains several components
as mentioned in the introduction. The goal can be financial
gain, unauthorised access or service disruption. The medium is
a way of communication such as e-mail, face to face, telephone Fig. 3. Social Engineering Attack Framework
etc. The social engineer can be either an individual or a group
of individuals. The target can either be an individual or an
organisation. In Mitnick’s first phase, the research phase, he states that
Compliance principles refer to the reasons why a target when executing a social engineering attack one needs to get
complies with the attacker’s request, and techniques include the most possible information about the target. Even though
those used to perform social engineering attacks. Examples of this is true, this is a very broad statement and it also assumes
techniques include phishing, pretexting, baiting and quid pro that the target is already known and that the goal is already
quo [1]. Examples of compliance principles include: set. The authors propose an additional step before gathering
• Friendship or liking: People are more willing to comply
the information which is meant for determining what the goal
with requests from friends or people they like. of the attack is and the best possible target to assist with
• Commitment or consistency: Once committed to some-
reaching the goal. Once the goal and target is known, the actual
thing, people are more willing to comply with requests information gathering can start. This process is also described
consistent with this position. in more detail than Mitnick’s model as one needs to identify
• Scarcity: People are more willing to comply to requests
sources of information before anything can be gathered and it
that are scarce or decreasing in availability. is beneficial to assess the gathered information to ensure that
• Reciprocity: People are more willing to comply with a
there is sufficient information to execute the attack. Mitnick’s
request if the requester has treated them favourably in attack cycle does not contain a preparation phase which is
the past. also needed during the social engineering attack. The authors
• Social Validation: People are more willing to comply to
propose a preparation phase which is used to prepare the
a request if it is seen as the socially correct thing to do. gathered information and to develop the attack vector that will
• Authority: People comply easily to requests given by
be used during the social engineering attack.
people with more authority than they have. Mitnick’s next phase, development of rapport and trust, is
Once the compliance principles, techniques and medium very similar in the proposed framework but the starting point is
have been selected, the attack vector can be set-up and the modelled as a separate step. Establishment of communication
social engineer can continue to the actual attacking phase. is a requirement for any relationship to be built with the
The next section introduces the proposed social engineering target. The gathered information is used to assist in estab-
attack framework. lishing communication. Once the attacker and the target are
communicating, the rapport and trust building can commence.
III. S OCIAL ENGINEERING ATTACK The third phase, according to Mitnick, is the exploitation
FRAMEWORK phase. This phase also requires more detail than that given
In this section the authors propose an extension of Kevin in Mitnick’s attack cycle. Exploiting a relationship is done
Mitnick’s original social engineering attack cycle [8]. Mit- with different manipulation techniques and in order for these
nick’s attack cycle is explained very briefly in his book and techniques to work the target has to be in an emotional state
does not contain a lot of detail. Mitnick’s attack cycle is where the exploitation is possible. This differs between all
very broad and is open to interpretation in some aspects. human beings and it is thus necessary to first determine what
Figure 3 depicts the new proposed social engineering attack that emotional state is of the target and then get the target
framework. This framework clarifies Mitnick’s phases and is into the desired emotional state. Once the target is in the right
more detailed. emotional state, the information can be elicited. The other

978-1-4799-3384-6/14/$31.00 ©2014 IEEE


Authorized licensed use limited to: UNIVERSIDADE DE BRASILIA. Downloaded on December 06,2024 at 19:26:49 UTC from IEEE Xplore. Restrictions apply.
important step not mentioned in Mitnick’s attack cycle is the B. Information Gathering
debriefing step. The target has to be brought back to a normal
Information gathering is a very important part of the social
emotional state to avoid further consequences. The idea is
engineering attack because the probability of developing a
to have the target feel good about giving out unauthorised
trusting relationship with a target is increased by the quality
information instead of feeling guilty about it.
of the information regarding the target. A target is more likely
Finally Mitnick has a fourth phase, utilising the information,
to share information with the attacker if a relationship exists
which the authors argue to be not part of the actual social
between the two.
engineering attack. The social engineering attack focuses on
Information is gathered about the target and everything
attacking the human aspect with the intention to achieve a
related to the attack. As depicted in Figure 5, the first step
specified goal, in this case to gain privileged information. This
of gathering information is to ‘identify the possible sources’
information can be used to perform a different action, but this
from which information can be obtained. The sources can be
is no longer part of the social engineering attack. For instance
anything or anyone with access to the information required for
if the information is a password to the system, gaining the
the attack. These sources can be any publicly available sources
password from a person is a social engineering attack whereas
such as company websites, social networking sites or personal
using the password to break into the system has no human
blogs and forums, or private information that is not publicly
element to it and is thus not a social engineering attack.
available. Techniques such as dumpster diving can be used
The framework is completed by having a transition phase
where discarded items are scanned for private information,
after debriefing to either go back and gather more information
such as an address on a bank statement. Dumpster diving is
if it is found that more information is needed to be able to
the technique of sifting through trash such as medical records
complete the attack, or go to the goal satisfaction. Mitnick
or bank statements to find anything that can be useful to the
also states that previous steps can be repeated if the goal is
dumpster diver [9].
not satisfied, though this is not described in much detail. The
proposed framework provides a more precise transition phase
specifying the exact phase to return to and repeat if necessary.
The following subsections describe each of these phases in
more detail.
A. Attack Formulation
The first step of a social engineering attack is to address
the question “What does the social engineer want?”. This goal
of the social engineer is the purpose of the entire attack and
should be very clear. Once the goal is identified, the target
should be selected, as depicted by Figure 4. The target can be
an individual or a group of individuals.
The target may belong to an organisation that is under
attack as part of the goal. For example, the goal may be to
infiltrate an organisation and the target is a security guard who
possesses information required to accomplish the goal. Both
the organisation and the selected target are important in the
information gathering phase.

Fig. 5. Social Engineering Attack : Information Gathering

After gathering information, the information is assessed


to be relevant or not. If the social engineer still does not
have enough information, he can go back to identifying more
sources and restart the information process.
The ‘information gathering’ phase is repeated until the
social engineer is satisfied that sufficient information has been
obtained, such that he can start his preparation for the attack.

C. Preparation
During preparation the social engineer ensures that every-
Fig. 4. Social Engineering Attack : Attack Formulation thing is ready before starting the actual attack. As depicted
by Figure 6, the first step of this phase is to combine

978-1-4799-3384-6/14/$31.00 ©2014 IEEE


Authorized licensed use limited to: UNIVERSIDADE DE BRASILIA. Downloaded on December 06,2024 at 19:26:49 UTC from IEEE Xplore. Restrictions apply.
all information gathered to form a bigger picture about the
planned attack.

Fig. 6. Social Engineering Attack : Preparation

This combined view of the scenario can be used for pre-


texting where a scenario is devised to lure the target into Fig. 7. Social Engineering Attack : Develop Relationship
a required action. An effective pretext should be believable
and withstand scrutiny from the target. It often relies on the
quality of the information gathered on the target’s personality.
An attack vector is now developed; it should contain all the
elements of a social engineering attack [1]. The attack vector
is the attack plan which leads to the satisfaction of the goal. It
has a goal, a target and a social engineer. In addition, the plan
must identify a medium, compliance principles and techniques.
D. Develop a Relationship
As mentioned previously, developing a good relationship
with the target is an essential part of the social engineering
attack. If trust cannot be established, the required information
Fig. 8. Social Engineering Attack : Exploit Relationship
is unlikely to be elicited from the target. Figure 7 depicts the
first step involved in building a relationship with the target,
namely the ‘establishment of communication’ step. This step is
phase the social engineer should have obtained the required
executed by using the medium identified during the preparation
information from the target. This may be a password which is
phase. If a pretext has been included in the plan, it is used
needed for the eventual satisfaction of the goal of the social
along with the initial communication.
engineering attack. After the exploitation phase, it is important
The next step in developing a relationship is the ‘rapport
to debrief the target.
building’. This entails the actual building of the relationship
and establishment of trust using the devised plan. Various
F. Debrief
techniques can be employed to establish trust. This step is not
trivial and can be time consuming. A good pretext simplifies Debriefing the target involves returning the target to a
this step. Once the social engineer has built a good relationship desired emotional state of mind, as shown in the ‘maintenance’
with the target, the relationship can be exploited to obtain the step in figure 9. It is important for the target not to feel
information the social engineer requires from the target. that he was under attack; if he is in a normal state of mind,
he will probably not reflect too much on the activities that
E. Exploit the Relationship occurred. For example, if the target had been manipulated
As depicted in Figure 8, exploiting the relationship consists into a sad emotional state and the attacker then elicited a
of two parts: ‘priming the target’ and ‘elicitation’. The first password from him, the target may feel inadequate because he
part is for the attacker to use manipulation tactics and his has released sensitive information. This feeling of inadequacy
preparation to get the target in a desired emotional state suited may consequently lead to emotional states such as depression.
to the plan, such as feeling sad or happy. For example, relating It may even lead to suicide by the target as evidenced
to a sad story can evoke the target into remembering a sad in an incident in 2012 involving the solicitation of private
incident, and subsequently to feel sad. information concerning the British Royal family [10], [11].
Once the target is in the desired emotional state, the During the confinement of Princess Catherine, an Australian
elicitation process can start. At the conclusion of the elicitation radio talk show host socially engineered a staff member of the

978-1-4799-3384-6/14/$31.00 ©2014 IEEE


Authorized licensed use limited to: UNIVERSIDADE DE BRASILIA. Downloaded on December 06,2024 at 19:26:49 UTC from IEEE Xplore. Restrictions apply.
maternity ward where the princess was a patient, to release hosted on a popular file sharing service. A few min-
information regarding the Princess’ condition. utes later, the same administrative assistant received
a phone call from another vice president within the
company, instructing her to examine and process the
invoice. The vice president spoke with authority and
used perfect French. However, the invoice was a
fake and the vice president who called her was an
attacker.
The supposed invoice was actually a remote
access Trojan (RAT) that was configured to contact
a command and control (CC) server located in
Ukraine. Using the RAT, the attacker immediately
took control of the administrative assistant’s infected
computer. They logged keystrokes, viewed the desk-
top, and browsed and ex-filtrated files.
These tactics, using an e-mail followed up by a
phone call using perfect French, are highly unusual
and are a sign of aggressive social engineering. In
May 2013, Symantec Security Response published
details on the first attacks of this type targeting
Fig. 9. Social Engineering Attack : Debrief
organisations in Europe. Further investigations have
Figure 9 depicts the next step in the debriefing phase, revealed additional details of the attack strategy,
namely ‘transition’. This is where the social engineer either attacks that are financially motivated and continue
decides that the goal has been satisfied or that more infor- to this day.”
mation is needed and the engineer returns to the information This example is now mapped to the Social Engineering
gathering phase. Attack Framework. It consists of two different phases and also
The next section discusses the applications of the framework demonstrates how the Social Engineering Attack Framework
on two examples. can handle two different Social Engineering Attacks.
1) First Attack Phase:
IV. F RAMEWORK A PPLICATION
The important features of the social engineering attack are
This section discusses two examples of well-known social specified below:
engineering attacks which have also been documented in news
Communication — The Social Engineering Attack
articles. Each of the examples are individually mapped to the
is using direct communication with the subclass of
proposed Social Engineering Attack Framework. This exercise
unidirectional communication.
shows that the Social Engineering Attack Framework can
Social Engineer — The Social Engineer is an individ-
be utilised to convert historical social engineering attacks to
ual.
a standardised format. Having historical social engineering
Target — The Target is an individual. In this instance
attacks in a standardised format allows one to perform compar-
the target is an administrative assistant to the vice-
isons between two different social engineering attacks. These
president at a French-based multinational company.
standardised social engineering attack scenarios can also be
Medium — The medium is e-mail.
used for social engineering training and awareness testing.
Goal — The goal of the attack is to gain unauthorised
The next subsections analyse each of the examples ac-
access to the organisation.
cording to the attack framework. Important features of each
Compliance Principles — The compliance principles
social engineering attack are mapped to the components in
that are used are consistency and authority.
the definition of a social engineering attack. The different
Technique — The technique that is used is phishing.
components of a social engineering attack are: the type of
communication, the social engineer, the target, a medium, a The next part steps through this example by means of the
goal, one or more compliance principles and one or more attack framework.
techniques. Step 1: Attack Formulation
Goal identification: The goal of the attack is to gain
A. Example 1 Analysis unauthorised access to the organisation’s systems and
The first example happened in 2013 and is described in the thus to the organisation’s information.
following excerpt [12]: Target identification: The target of the attack is the ad-
“In April 2013, the administrative assistant to ministrative assistant to the vice-president at a French-
a vice-president at a French-based multinational based multinational company.
company received an e-mail referencing an invoice Step 2: Information Gathering

978-1-4799-3384-6/14/$31.00 ©2014 IEEE


Authorized licensed use limited to: UNIVERSIDADE DE BRASILIA. Downloaded on December 06,2024 at 19:26:49 UTC from IEEE Xplore. Restrictions apply.
Identify potential sources: Public records of the he is an administrative assistant to the vice-president at
company and e-mail communication samples from the a French-based multinational company.
organisation. Medium — The medium is the telephone.
Gather information from sources: Collect and find Goal — The goal of the attack is to gain unauthorised
the public records of the company and collect samples access to the organisation.
of e-mail communication. Compliance Principles — The compliance principles
Assess gathered information: Determine the organisa- that are used are consistency and authority.
tional hierarchy and assess the e-mail format of internal Technique — The technique that is used is phishing.
organisational e-mail communication.
The next part steps through this example by means of the
Step 3: Preparation
attack framework.
Combination and analysis of gathered information:
Identify where the target fits into the organisational Step 1: Attack Formulation
hierarchy and identify the superiors of the target. Iden- Nothing here as it is a transition to the ‘development
tify the e-mail structure of internal e-mails sent in the of an attack vector’ step.
organisation and the type of information that should be Step 2: Information Gathering
sent to the target. Nothing here as it is a transition to the ‘development
Development of an attack vector: Write an e-mail of an attack vector’ step.
which is similar to other e-mails exchanged within the Step 3: Preparation
organisation but also contains the malicious Remote Combination and analysis of gathered information:
Access Trojan (RAT). More specifically, the e-mail’s Nothing here as it is a transition to the ‘development
format should be similar to the format used in typical of an attack vector’ step.
e-mail invoices the administrative assistant receives. Development of an attack vector: The target already
Step 4: Develop Relationship has an e-mail in his inbox containing a malicious
Establishment of communication: The physical action invoice, and during phase 1 this e-mail was not deleted.
of sending the e-mail that was developed during the This attack vector is aimed at getting the target to open
‘development of an attack vector’ step is the initial the malicious invoice so that the social engineer can
establishment of communication. gain unauthorised access. In this phase one is required
Rapport building: The e-mail contents should be to develop a transcript to be followed which will use
similar to a typical e-mail the administrative assistant both authority and consistency principles to get the
can expect. target to comply with the request to open the malicious
Step 5: Exploit Relationship invoice.
Priming the target: The e-mail should be of such Step 4: Develop Relationship
a nature that the administrative assistant would not Establishment of communication: The physical action
immediately delete or discard the e-mail. of making the phone call of which the transcript has
Elicitation: In the ‘priming the target’ step, the goal is been developed during the ‘development of an attack
for the target to not delete the e-mail immediately. The vector’ step is the initial establishment of communica-
elicitation will be deemed successful if the target does tion.
not delete the e-mail. Rapport building: The telephonic conversation should
Step 6: Debrief start off by the attacker introducing himself as the sec-
Maintenance: The e-mail should be worded in such a ond vice-president of the organisation (This information
manner that the target is not perturbed by the e-mail. was gathered from the organisational hierarchy).
Transition: The e-mail should note that there will Step 5: Exploit Relationship
be some follow-up communication. The target is then Priming the target: The target should be aware that
prepared for follow-up communication and thus a tran- the caller requesting him to process the invoice is a
sition is made to the ‘development of an attack vector’ person in an authoritative position. It must also be
step and not to the ‘goal satisfaction’ step. consistent with requests that the target would normally
be required to process as well as consistent with the
2) Second Attack Phase:
e-mail containing the invoice.
The important features of the social engineering attack are
Elicitation: Since the target has been primed to comply
specified below:
with the requests by means of authority and consis-
Communication — The Social Engineering Attack tency, the social engineer can now request the target to
is using direct communication with the subclass of process the malicious invoice.
bidirectional communication. Step 6: Debrief
Social Engineer — The Social Engineer is an individ- Maintenance: The malicious invoice should be similar
ual. to one that the target would normally receive. The
Target — The Target is an individual. In this instance target should be unaware that he has provided the

978-1-4799-3384-6/14/$31.00 ©2014 IEEE


Authorized licensed use limited to: UNIVERSIDADE DE BRASILIA. Downloaded on December 06,2024 at 19:26:49 UTC from IEEE Xplore. Restrictions apply.
social engineer with unauthorised access by opening 1) The Attack Phase:
the malicious invoice. Whilst on the phone, the social The important features of the social engineering attack are
engineer should be friendly and reassuring towards the specified below:
target. The target must always feel good about helping Communication — The Social Engineering Attack
the social engineer in order to avoid suspicion. is using indirect communication through third party
Transition: The Social Engineer has now obtained mediums.
his unauthorised access and can proceed to the goal Social Engineer — The Social Engineer is an individ-
satisfaction state. ual.
Goal Satisfaction: The Social Engineer has obtained Target — The Target is an individual. In this instance,
his initial goal of obtaining unauthorised access. it is any owner of a car parked in the parking lot.
Medium — The medium is fliers.
B. Example 2 Analysis Goal — The goal of the attack is to gain unauthorised
access to an individuals computer.
The second example happened in 2009 when fliers appear-
Compliance Principles — The compliance principles
ing to be traffic violations were placed on cars in a parking
that are used are social compliance and authority.
lot. On these supposed parking violations a website link was
Technique — The technique that is used is phishing.
included where one could view pictures associated with the
so-called violation. The website extracted a Dynamic Link The next part steps through this example by means of the
Library (DLL) into the system32 directory on the computer attack framework.
used to access the website. The DLL installs as an internet Step 1: Attack Formulation
explorer browser helper object once the system is rebooted. Goal identification: The goal of the attack is to gain
Next a pop-up would appear, informing the user that his unauthorised access to an unspecified individuals’ com-
computer contains signs of viruses and Antivirus 360 needs puter.
to perform a scan. If the user agrees to let the anti-virus Target identification: The target of the attack is any
application install itself, (it was later found that the anti-virus person who owns a car and is parked in the parking lot
application was a virus dropper) it in turn installed a virus. at the time of spreading the fliers.
The attacker did not continue with the attack, however if he Step 2: Information Gathering
had continued he could have taken full control of the computer Identify potential sources: Public websites with the
since it was already infected with his software [13]. ability to view parking violations and any institute with
An excerpt of this article reads as follows [13]: authority to reach out a parking violation.
“I had the opportunity to examine malware Gather information from sources: Collect sample
whose initial infection vector was a car windshield parking violations which are placed on windshields of
flier with a website address. The malicious programs cars and sample websites where one can view parking
were run-of-the-mill; however, the use of fliers was violations.
an innovative way of social engineering potential Assess gathered information: Determine which park-
victims into visiting a malicious website. ing violations are relevant to the specific parking lot,
perhaps on location, region etc. The violation, in this
Several days ago, yellow fliers were placed on
case, should specifically conform to the standard park-
the cards in Grand Forks, ND. They stated:
ing violations reached out in Grand Forks, ND. Also
PARKING VIOLATION This vehicle is in vi-
filter out the website that is consistent with the parking
olation of standard parking regulations. To view
violation.
pictures with information about your parking pref-
Step 3: Preparation
erences, go to website-redacted.
Combination and analysis of gathered information:
The website showed several photos of cars on Choose one final parking violation / website pair and
parking lots in that specific town. EXIF data in the finalise the structure of the parking violation, the style
JPG files show that they were edited using Paint and working of the website.
Shop Pro Photo 12 to remove license plate details Development of an attack vector: Develop a parking
of the cars and that the photos were taken using violation consistent to the finalised structure as well
a Sony DSC-P32 camera. Installing PictureSearch- as a phishing website which looks similar to the one
[Link] led to DNS queries for [Link], a chosen in the previous step. On the parking violation,
domain with a bad reputation according to Syman- ensure that there is a section stating that pictures with
tec, McAfee, etc. Even without the Internet connec- information about the parking violation are on a certain
tion, the program installed (extracted) a DLL into website, with a link to the phishing website.
C:/WINDOWS/system32.” Step 4: Develop Relationship
This example is now demonstrated through the use of the Establishment of communication: The physical action
Social Engineering Attack Framework. of putting the created fliers on the cars in the parking

978-1-4799-3384-6/14/$31.00 ©2014 IEEE


Authorized licensed use limited to: UNIVERSIDADE DE BRASILIA. Downloaded on December 06,2024 at 19:26:49 UTC from IEEE Xplore. Restrictions apply.
lot. The authors found that Mitnick’s attack cycle is a good base
Rapport building: The parking violation placed on for social engineering attacks, but lacks significant detail. It is
the windshield of the cars should be consistent with a very broad explanation of an attack and assumes that certain
parking violations handed out in that parking lot under components of the attack are already known, such as the goal
standard conditions. The owner of the car receiving of the attack and the target. The attack framework provides
the violation should not doubt whether it is official; specific steps to identify these component and detailed steps
it should look legitimate. When the target visits the for all other aspects of an attack.
website, the website should also look legitimate, not This paper provides an in depth social engineering attack
raising doubt with the user. framework as an extension to the previously proposed on-
Step 5: Exploit Relationship tological model. The framework adds temporal data such as
Priming the target: The flier should be realistic so that flow and time whereas the ontological model contains all the
the owner of the car would take it seriously and not just components of a social engineering attack. The framework
throw it away. While driving home the target should and the ontological model can be used to generate social
ideally think about the violation and prepare himself to engineering attack scenarios as well as to map historical social
go to the website to view the parking violation, feeling engineering attacks to a standardised format. This is important
pressured due to social compliance to do the right thing as these scenarios can be used for education and awareness
and pay the fine. purposes and enables anyone to analyse and compare different
Elicitation: Provide a link on the flier which links social engineering attacks. Future work includes the actual
to the phishing website. Upon clicking on the link, a creation of such scenarios.
backdoor is installed on the person’s computer, giving
R EFERENCES
the social engineer the opportunity to gain unauthorised
access to the computer. [1] F. Mouton, L. Leenen, M. M. Malan, and H. S. Venter, “Towards an
ontological model defining the social engineering domain,” in 11th Hu-
Step 6: Debrief man Choice and Computers International Conference, Turku, Finland,
Maintenance: The flier and website should be created July 2014, pp. 266–279.
in such a way that the target does not feel threatened. [2] N. F. Noy and D. L. McGuinness, “Ontology development 101: A
guide to creating your first ontology,” Stanford Knowledge Systems
The website should be similar to the real violations Laboratory, Technical Report KSL-01-05, March 2001.
website so that the victim is confident that he should [3] D. Harley, “Re-floating the titanic: Dealing with social engineering
take the steps required to pay the violation. attacks,” in European Institute for Computer Antivirus Research, 1998.
[4] L. Laribee, “Development of methodical social engineering taxonomy
Transition: The social engineer can use the backdoor project,” MSc, Naval Postgraduate School, Monterey, California, June
to gain unauthorised access to the computer and can 2006.
thus proceed to the ‘goal satisfaction’ step. [5] K. Ivaturi and L. Janczewski, “A taxonomy for social engineering
attacks,” in International Conference on Information Resources Manage-
Goal Satisfaction: The Social Engineer has obtained ment, G. Grant, Ed. Centre for Information Technology, Organizations,
his initial goal of unauthorised access. and People, June 2011.
[6] F. Mohd Foozy, R. Ahmad, M. Abdollah, R. Yusof, and M. Mas’ud,
“Generic taxonomy of social engineering attack,” in Malaysian Technical
V. C ONCLUSION Universities International Conference on Engineering & Technology,
Batu Pahat, Johor, November 2011.
The protection of information is extremely important in a [7] P. Tetri and J. Vuorinen, “Dissecting social engineering,” Behaviour &
Information Technology, vol. 32, no. 10, pp. 1014–1023, 2013.
modern society and even though the security around informa- [8] K. D. Mitnick and W. L. Simon, The art of deception: controlling the
tion is continuously improving, the one weak point is still the human element of security, W. Publishing., Ed. Indianapolis: Wiley
human being who is susceptible to manipulation techniques. Publishing, 2002.
[9] J. Long, No tech hacking: A guide to social engineering, dumpster
This paper explored social engineering as a domain and diving, and shoulder surfing, S. Pinzon, Ed. Syngress, 2011.
social engineering attacks as a process inside this domain. A [10] F. Mouton, M. M. Malan, and H. S. Venter, “Social engineering from a
previous paper by the authors, Towards an Ontological Model normative ethics perspective,” in Information Security for South Africa,
Johannesburg, South Africa, August 2013, pp. 1–8.
Defining the Social Engineering Domain [1], is revisited and [11] [Link]. (2012, December) One royal pwning. Social-
the ontological model proposed in the paper is explored in [Link]. [Online]. Available: [Link]
order to further define the social engineering domain. engineering/one-royal-pwning/
[12] Symantec Security Response. (2014, January) Francophoned
Kevin Mitnick’s social engineering attack cycle [8] is anal- a sophisticated social engineering attack. Symantec. [On-
ysed and discussed in detail. The authors propose a social line]. Available: [Link]
engineering attack framework based on Mitnick’s attack cycle. sophisticated-social-engineering-attack
[13] L. Zeltser. (2009, February) Malware infection that began with
The shortcomings in Mitnick’s attack cycle are explored and windshield fliers. Internet Storm Center. [Online]. Available:
improvements of these short-comings are reflected in the [Link]
proposed attack framework. Each phase in the proposed social
engineering attack framework is discussed in detail and two
life scenarios are explored as an application of the combi-
nation of the attack framework and the previously proposed
ontological model.

978-1-4799-3384-6/14/$31.00 ©2014 IEEE


Authorized licensed use limited to: UNIVERSIDADE DE BRASILIA. Downloaded on December 06,2024 at 19:26:49 UTC from IEEE Xplore. Restrictions apply.

You might also like