Social Engineering.. Dangerous Hackers!!
By: Prof. Dr. Gabriel bin Hassan Al-Arishi
Although social engineering is a branch of social sciences, which involves using mechanisms to study social trends and influence them to face negative social behaviors, it has become commonly used to express attacks that rely on deceiving employees working in institutions, or exploiting their kindness or innocence, in order to seize data, or access sensitive information stored in the computer systems of their institutions. It is strange that such an act is not described as meanness, theft, or fraud, as if Stockholm syndrome is what makes us call the one who performs this despicable act a "social engineer," as if we are showing our admiration for what he does.
The danger of this type of attack that exploits human nature is that hackers get the information they want using simple methods of deception, without exerting effort in hacking computer systems via malicious programs. They get their aim by simply making a phone call with one of their friends among the institution's employees, or by passing in front of empty offices to snatch passwords. Institutions only discover the failed ones; the skilled are safe from discovery. Tactical deceptions used by social engineers vary. Some exploit the employee's desire to be helpful out of concern for customer satisfaction. Some exploit employees who look forward to building work relationships based on respect and mutual trust, by building a friendship and gaining their trust, so they voluntarily disclose information.
Moreover, the negligent nature of some employees helps attackers. Some employees write passwords above or next to the computer screen. Institutions' websites usually reveal much information that can be used. Figures show that new employees are most vulnerable to this danger. Email is the most used means, followed by social media. Men are more vulnerable than women, especially if the social engineers are female. An experiment on 135 employees from 17 major companies like ogle, Microsoft and Cisco showed that only five refused to give information, and they were women. Male response rates rose from 53% for male senders to 68% for female senders. Providing employees with knowledge and following a firm information security policy is the first line of defense.
* Professor of Information Science - King Saud University - Member of the Shura Council

