Social engineering is one of those topics that nobody really likes to talk about. Admittedly, we’ve all been vulnerable if not compromised by some sort of social engineering scheme. Problem is, we’re not aware of 50-60 % of social engineering attacks that occur on a daily basis. We often focus on the technical and physical aspects of security. These topics are much easier discuss since they relate to simply ‘physical’ or ‘logical’ systems or ideas. With social engineering, the problem expands to psychology, unified policy among all employees, and also includes many more variables. How does this relate to converged networks, you ask? In the first Securing the Line series, we discussed the layered security approach. When analyzing any environment, the security analysis usually includes inherent technical weaknesses, inadequate corporate or organizational policy, human error, physical security, and single point of failure vulnerabilities. What isn’t usually discussed or analyzed is what a true risk social engineering introduces into any technical environment. There is an article by Sarah Granger on the SecurityFocus website that was written back in 2001 about the dangerous pitfalls of social engineering. While it’s seven years old, the same fundamental ideas still apply. Sarah cites several examples that target telecommunications environments:
“Hackers are able to pretend they are calling from inside the corporation by playing tricks on the PBX or the company operator, so caller-ID is not always the best defense. Here’s a classic PBX trick, care of the Computer Security Institute: “’Hi, I’m your AT&T rep, I’m stuck on a pole. I need you to punch a bunch of buttons for me.’” ” (Granger) Why is telecommunications infrastructure such an easy target for social engineering? One of the major weaknesses of any organization’s telecom infrastructure is this: there are simply too many cooks in the kitchen. We have internal telecom / PBX / network staff, dialtone providers and carriers, and slew of external vendors and solution providers. How can social engineering attacks be mitigated? I’ve tried several different techniques personally for combating social engineering, and a few have been very successful. First, for every critical system or resources, such as “dialtone carriers” in our case, delegate one or two people as the “communication centers” for that environment. When I say one or two people, I really mean it. These people know the environment well, and are trained to respond to inquiries and potentially information-gathering attackers. They know exactly who needs what information at what time. Anybody within the organization that gets a suspicious request for information can immediately forward the request to the “communication center” delegate for further analysis. Even if a senior telecom engineer knows the answer to a question posed by an outside source, information release is controlled by the communications delegate. Conduct a “Social Engineering Day” Those who exploit social engineering attacks are smart, resourceful people. Every staff member, from the administrative assistant to the CEO needs to be aware of social engineering vulnerabilities. With even a little bit of training, the entire organization can be on the lookout for such attacks. Frequent training sessions containing real examples often benefit everyone, even part time staff. Vigilance It’s ultimately the vigilance that pays off in the long run. This is the accumulated vigilance that involves everyone, since an organization’s weakest link can compromise the entire environment.




