Cybersecurity Books: The human attack vector
Social engineering, phishing, and the psychology of influence: why perimeter spending is bypassed with a single phone call.
Cybersecurity Books: The human attack vector
Part seven of nine. Social engineering, phishing, and the psychology of influence.
The reason this block is worth reading even for people who work on the technical side: money spent on the perimeter is bypassed with a single phone call.
Kevin Mitnick, William Simon. The Art of Deception (2002)
A collection of scenarios from practice: dozens of stories in which nobody broke anything, they just called and asked. Each story is followed by a breakdown of which procedure should have caught it.
Topics: pretexting, exploiting the org chart, gathering information in pieces, working on the help desk and on assistants, building policies and training staff.
Kevin Mitnick, William Simon. The Art of Intrusion (2005)
The sequel, assembled from the accounts of other people involved. There is noticeably more technical substance here.
Topics: combining social and technical techniques, attacks on casinos and banks, industrial espionage, misconfiguration as the way in, each case examined from the defender's side.
Christopher Hadnagy, Michele Fincher. Phishing Dark Waters (2015)
A narrow book about a single vector, but the most widespread one.
Topics: the anatomy of a phishing email, spear phishing and how it is prepared, internal training campaigns and the right metrics for them, technical protection of email, the response to a successful attack.
Robert Cialdini. Influence (1984)
Not a security book, yet every social attack is built on exactly these mechanisms. Both Mitnick and Hadnagy cite it.
Topics: reciprocity, commitment and consistency, social proof, liking, authority, scarcity.
Kevin Mitnick, Robert Vamosi. The Art of Invisibility (2017)
A practical guide to personal privacy from a man who spent a long time hiding professionally.
Topics: passwords and two-factor authentication, metadata in files and photographs, tracking in the browser, the security of email and messengers, public Wi-Fi, buying things and moving around without a digital trail.
Daniel Kahneman. Thinking, Fast and Slow (2011)
The background for the whole block: why people fail predictably, and why those failures are reproducible and therefore exploitable.
Topics: the two systems of thinking, heuristics and cognitive biases, judging probabilities, behaviour under time pressure, mistakes in assessing risk.
Next part: nonfiction investigations.
The whole series:
Christopher Hadnagy. Social Engineering: The Science of Human Hacking (2nd edition, 2018)
A systematisation of what Mitnick presents as stories: methodology instead of anecdotes.
Topics: gathering information from open sources, building a cover story, non-verbal signals and micro-expressions, techniques for establishing trust, tooling for professional engagements, a training programme for staff.