The Psychology behind Social Engineering
You have probably heard the term social engineering before, either in the news (as part of a big scam) or even in your job as part of the annual security awareness program.
But what is social engineering? Well, to make it simple, we can just say that social engineering is the art of manipulating people to perform an action that will provide a benefit for the attacker. That action could be in the form of disclosing information, executing an action (such as executing a command), or even disabling or bypassing a security measure.
In other words, social engineering is focused on “hacking” the users, not the systems.
Now, to better understand social engineering, it is imperative to understand the psychology, principles, and tactics behind those attacks. Attackers will leverage a set of psychological concepts, principles, and tactics to successfully manipulate the victim. They will then use the art of manipulation to influence the victim to either reveal sensitive information (passwords, users, etc.) or even perform a given action (such as disabling the antivirus).
Understanding those tactics will help you to identify when you are a target and avoid falling into these elaborate attack vectors. For this reason, in this chapter, we will cover the following main topics:
- The art of manipulation
- Tactics and principles used to influence the victims
- Developing rapport
- The weakness behind the empathy
- Leveraging influence tactics for defensive security