What is social engineering? (Social Engineering)
Social engineering was proposed by the hacker Mitnick in the art of deception after repentance, it is a harmful means to the psychological traps of the victims, such as deception and injury, through psychological weakness, instinct reaction, curiosity, trust, and greed.
So what is social engineering?
In the chain of information security, human factors are the weakest link. Social engineering is an attack method that intrude into computer systems by means of deception by exploiting the weak points of people. The Organization may take comprehensive technical security control measures, such as identity authentication system, firewall, intrusion detection, and encryption system, however, because employees do not intend to disclose confidential information (such as system passwords and IP addresses) by phone or email, or the Organization's confidential information is cheated by illegal personnel, this may cause serious damage to the Organization's information security.
Social engineering typically uses conversations, spoofing, counterfeiting, or speaking to conceal the secrets of a user's system from legal users. Skilled social engineers are good at collecting information. Many seemingly useless information will be exploited by these people for penetration. For example, a phone number, a person's name, or a work ID number may be used by social engineers.
This means that if the "person" factor is not put into the enterprise's security management policy, it will constitute a great security "crack ".