The Art of Deception

Submitted by: Submitted by

Views: 214

Words: 939

Pages: 4

Category: Science and Technology

Date Submitted: 03/29/2013 08:50 AM

Report This Essay

The Art of Deception is a book by Kevin Mitnick that covers the art of social engineering. Part of the book is composed of real stories, and examples of how social engineering can be combined with hacking.

All, or nearly all, of the examples are fictional, but quite plausible. Many are frightening or at least unsettling because they expose the ease with which a skilled social engineer can subvert many rules most people take for granted. A few examples:

 A person gets out of a speeding ticket by fooling the police into revealing a time when the arresting officer will be out of town, and then requesting a court date coinciding with that time.

 A person gains access to a company's internal computer system, guarded by a password that changes daily, by waiting for a snowstorm and then calling the network center posing as a snowed-in employee who wants to work from home, tricking the operator into revealing today's password.

 A person gains lots of proprietary information about a start-up company by waiting until the CEO is out of town, and then showing up at the company headquarters pretending to be a close friend and business associate of the CEO.

 A person gains access to a restricted area by approaching the door carrying a large box of books, and relying on people's propensity to hold the door open for others in that situation.

This book also, after giving an example, will tell what tricked/conned the victims of the scam, and how to prevent it in real life or business. The Art of Deception ends with Mitnick's strategy and business plans to prevent most if not all of the scams in the book.

What is a social engineering attack?

To launch a social engineering attack, an attacker uses human interaction (social skills) to obtain or compromise information about an organization or its computer systems. An attacker may seem unassuming and respectable, possibly claiming to be a new employee, repair person, or researcher and even offering credentials to...