Cyber warfare is emerging significantly over the years with technological advancements and innovative tactics on the daily basis. One aspect has grown constantly with the development of cyber warfare which is human factor. Social engineering and psychological operations are vital components of cyber warfare which place integral part in exploiting human venerability to achieve strategic goals. This article describe these core issues of cyber warfare by exploring their applications, case studies, and defensive measures.
If we oversee social engineering, then we come to know that it has a major part in manipulating human vulnerability. Basically, social engineering manipulates individual’s sensitive information or performing specific actions which facilitate cyber attacks. Such type of attacks can be done through various tactics. Let’s began with a tactic named as phishing. Phishing is defined as an attempt to steal sensitive information or data. It is usually done by using wrong usernames, passwords, credit card numbers or bank account information to utilize or sell stolen information. For example, a Swedish Bank Nordea lost 7 million kronor due to this phishing attack in 2007. After this, second tactic is pretexting. In this tactic, attacker uses false scenario for story to gain trust and then obtain sensitive information. Its example can be Hewlett-Packard pretexting scandal in 2006. Baiting is third tactic which is defined as wrongdoers lure victims with rewards or interesting offers. This tactic tricks the victim into unintentional downloading of malware into their system and revealing confidential personal or organizational information. For example, free music or movie downloads contain malicious software that lead to disruption of personal data.
Fourth is Quid pro quo. Basically, it is a Latin term which is defined as “something for something”. It means that it is based on interest or exchange of services between two parties. Fifth is whaling which is defined as target on high level executives officials. Last is Vishing which means using different voices on calls to trick victims into revealing sensitive information. Vishing can be done through artificial intelligence, Robocall, VoIP, Caller ID Spoofing, Dumpster Diving, Tech Support Call, Voice mail scam and Client Call. Social engineering attacks depend on psychological disturbance like curiosity, fear or greed and these attacks can be very effective as they can surpass technical defenses.
Let’s discuss psychological operations which aim to influence the thoughts and actions of individuals or groups. It has very various purposes. Let’s discuss them one by one. First is propaganda which means to disseminate information to shape public opinion or to lower enemy morale. Two famous examples of propaganda include the Uncle Sam army recruitment posters and the Rosie the Riveter poster from both world wars. Propaganda possesses political religious or societal purposes. Second is deception which is defined as disseminating false information to confuse or mislead adversaries. Third is denial and deception which means to conceal or distort information to Hinder enemy decision making.
Social engineering and psychological operations play a very significant role in cyber warfare and enable attackers to gain initial access, escalate privileges, spread propaganda, conduct espionage and disrupt operations. United States Presidential elections in 2016 witnessed social engineering and psychological operation efforts with Russian actors using social media and propaganda to influence public opinion. In 2013 Yahoo breach exploited a social engineering vulnerability which allowed attackers to steel sensitive user data. In 2019, Facebook bridge exposed millions of user data. A long time ago, data from NADRA was steeled. These are few case studies of social engineering and psychological operations under the umbrella of cyber warfare.
To defend against social engineering and psychological operations, multilayer approach is required.
Awareness and education can help uses about social engineering tactics and psychological operation techniques. Building security policies and access controls can be helpful for it. As far as technical defence is considered, utilization of anti-phishing software, Intrusion Detection System and encryption is necessary to protect online users. Incident response can be very helpful for countering these attacks as it establish procedures for responding to social engineering and psychological operation incidents. Software and system up gradation can prevent exploitation of known vulnerabilities. Employee screening is necessary response these attacks. For employee screening, it is necessary to conduct background checks which will help to prevent insider threats.
By understanding the human factor in cyber warfare, we can prepare ourselves from the evolving threads. To counter these challenges in this digital landscape, it is important to follow preventive measures as mention above. Mitigating the risks associated with social engineering and psychological operations is crucial in this digital era. The only way, to protect our digital assets and prevent cyber attacks, is to follow preventive measures.
Author can be reached at naeemunnisa913@gmail.com
Related