Module 2: Pervasive Attack Surfaces and Controls

Module Overview

  • Module 2: Pervasive Attack Surfaces and Controls
  • Module Objectives: after completing this module you should be able to:
    • Define social engineering and list types of attacks
    • List different types of physical defenses
    • Describe controls for protecting data
  • Trending Cyber note: social engineering is among the most effective attack types, involving deception to elicit actions or information from users. History shows deceptive schemes exist long before cyberspace, ranging from simple to highly complex operations.
  • Real-world example (1970s): a small group aimed to steal classified FBI documents by studying building access, door locks, and timing around a national event; their approach leveraged social cues and environmental factors rather than technical exploits. The FBI countered by changing the door lock just before they attempted entry, shifting their plan to a backdoor with a deadbolt, a heavy filing cabinet, and ultimately a carpeted room allowing access. This case illustrates how social engineering and human factors can enable or thwart physical intrusions.
  • Pervasive definition: existing in or spreading through every part of something. The three topics in this module (social engineering, physical security, data controls) are pervasive because they apply universally across IT security and information protection.

Social Engineering: Definition and Historical Context

  • Social engineering definition: a means of eliciting information or convincing a user to take an action that weakens security, typically through deception and manipulation of human psychology.
  • Core idea: threat actors exploit human factors as the attack surface (human vectors).
  • Why it matters: most cyberattacks today begin with social engineering and unlock subsequent technological or procedural breaches. Estimate: cybercriminals use social engineering in about 98%98\% of their attacks.
  • Historical context: deception used for gain spans thousands of years; modern examples leverage digital trust, impersonation, and social cues to bypass technical controls.

Expanded Case Background: Pervasive Security Context

  • Pervasive topics across IT security: social engineering, physical security, and data controls.
  • Purpose: establish fundamentals for securing information across environments, not just networks or devices.

Threat Surfaces and Social Engineering: Core Concepts

  • Attacks often start with social engineering rather than a direct exploit of a technology weakness; attackers manipulate people first to gain access or information.
  • Human vectors: attackers exploit psychology and social dynamics to influence actions.
  • Table reference (conceptual): Table 2-1 lists social engineering principles used to manipulate targets.

Human Manipulation Principles (Table 2-1: Conceptual Overview)

  • Authority: acting as or citing an authority figure (e.g., "I’m the CEO calling").
  • Intimidation: coercion through threats (e.g., "If you don’t reset my password, I’ll escalate").
  • Consensus: leveraging what others have done (e.g., "I called last week and your colleague reset my password").
  • Scarcity: pressuring with limited availability (e.g., "I can’t waste time here").
  • Urgency: demanding immediate action (e.g., "My board meeting starts in 5 minutes").
  • Familiarity: leveraging recognition or prior interaction (e.g., references to familiar evaluations).
  • Trust: building confidence in the impersonated individual or entity.

Prepended Technique in Social Engineering

  • Prepending: influencing the subject before the event occurs by presenting a favorable framing (e.g., "The best film you will see this year").
  • In attacks, prepending is combined with urgency (e.g., "Reset my password immediately because my meeting starts soon").

Personal Techniques Used in Attacks (Person-to-Person Contact)

  • Provide a reason: add rationale with words like "because" to justify the request (e.g., director’s office manager is out sick).
  • Project confidence: walk through restricted areas calmly to reduce suspicion.
  • Use evasion and diversion: provide vague or irrelevant answers to questions until trust is established.
  • Make them laugh: humor to reduce guard and build trust.

Types of Social Engineering Attacks

  • Phishing
  • Impersonation
  • Redirection
  • Misinformation and Disinformation
  • Watering Hole Attacks
  • Data Reconnaissance

Phishing: Overview and Variants

  • Phishing definition: sending emails or web content that falsely claims to be from a legitimate source to trick users into taking actions or revealing information.
  • Etymology: phishing is a "fishing" metaphor where bait is cast hoping some victims bite.
  • Typical phishing flow: user responds to email or visits a compromised website to enter sensitive information (passwords, SSNs, credit card numbers, etc.).
  • Phishing variations:
    • Spear phishing: targeted messages tailored to a specific individual or organization.
    • Whaling: spear phishing aimed at high-value targets (e.g., executives).
    • Vishing: voice phishing via phone calls.
    • Smishing: SMS/text phishing.
    • BEC (Business Email Compromise): fund transfer requests impersonating legitimate business communications.
  • Impersonation in phishing context: attackers may impersonate CEOs, help desks, or other trusted roles to gain trust.
  • Caution factors: phishing sites often visually mimic legitimate sites; modern phishing uses sophisticated branding; many browsers block known phishing sites but rapid domain proliferation makes blocking hard.
  • Financial impact example for phishing/spam economics: a spam email sent to 6 million users with $50 product and $5 cost to make; even with a 0.001\% response rate, profit can exceed 270,000270{,}000.
  • Note: phishing is distinct from spam, though both involve mass emailing; phishing focuses on deception to steal or access data.
  • Notable BEC attacks (Table 2-2):
    • Bogus Invoice: pretend supplier, fake invoice demanding payment.
    • Executive Fraud: impersonate executive to request urgent fund transfer.
    • Account Compromise: compromised finance email to request payment.
  • Phishing statistics (Q3 2022): over 1.2 million1.2\text{ million} phishing attacks; financial sector accounted for 23%23\% of phishing attacks; BEC attacks rose 59%59\%.
  • Phishing challenges: modern emails and fake websites are hard to distinguish; visual cues (logos, color schemes) are often convincing; browsers block known phishing sites, but rapid domain creation complicates protection.
  • Note 4 and Note 5 references highlight phishing education and risk awareness aspects.

Impersonation and Pretexting

  • Impersonation: threat actors masquerade as real or fictitious individuals and play roles to obtain information or access.
  • Pretexting: designed to obtain private information through a fabricated scenario.
  • Common impersonations: repairperson, IT support, manager, trusted third party; authoritative figures often exploited to reduce resistance.
  • Brand impersonation: emulate a well-known brand to leverage recognition and trust (e.g., a familiar bank name) to prompt risky actions.

Redirection and Typo Squatting (URL-based Attacks)

  • Redirection: using misspelled URLs or look-alike sites to trick users into visiting malicious or ad-filled pages; attackers purchase domains that mimic legitimate sites.
  • Typo squatting: domains that are misspelled variants of legitimate sites (e.g., goggle.com for google.com).
  • Note 6 and Note 7: typo-squatting targets high-traffic brands; common targets include PayPal, Apple, Amazon, etc.
  • Domain name strategy changes: modern attackers use more generic TLDs; there are over 1,239 generic TLDs (gTLDs) including .museum, .office, .global, .school, etc., increasing the need to pre-register close spellings.
  • Note 8: cybersquatting definition and anti-cybersquatting laws (e.g., Anti-Cybersquatting Consumer Protection Act of 1999).
  • Bitsquatting: domain names that differ by a single bit due to RAM memory flip (e.g., aeazon.com for amazon.com, microsmft for microsoft.com); in a sample, about 20%20\% of attacker domains showed bitsquatting.
  • Pharming: malware or DNS manipulation redirects users to fake sites even when the correct URL is entered.
  • Note 9: Bitsquatting prevalence; Note 9: Bitsquatting concept illustrated with bit flip example.

Misinformation vs Disinformation

  • Misinformation: false or inaccurate information regardless of intent.
  • Disinformation: false information spread with malicious intent.
  • Cyber disinformation examples: hoaxes or false warnings sent via email warning of a virus; these are designed to prompt actions that compromise systems or provide attackers with access.
  • Note 10: Hacktivists and nation-state actors may spread disinformation not tied to a cyberattack.

Watering Hole Attacks and Data Reconnaissance

  • Watering hole attack: target a specific group by compromising a website commonly visited by that group (e.g., executives visiting a supplier site) to deliver malware to their devices.
  • Data reconnaissance: gathering information about a target without direct interaction. Methods include:
    • Dumpster diving: digging through trash for sensitive information (calendars, memos, org charts, phone directories, policies).
    • Purchasing used equipment: residual data on devices.
    • Google dorking: using advanced search techniques to uncover sensitive data posted online.
    • Shoulder surfing: watching someone enter a code or password; can be aided by hidden cameras.
  • Note 11: Google dorking terminology origin; Note 12: caution about student-targeted phishing and similar offers.
  • Caution about college-targeted social engineering: students are especially vulnerable to free scholarships, jobs, cheap loans, and credit offers.

Physical Security Controls: Core Concepts

  • Security controls overview: countermeasures to limit asset exposure to danger; four broad categories are managerial, operational, technical, and physical; physical controls are often overlooked but crucial.
  • Physical security controls examples: perimeter defenses, preventing data leakage, and computer hardware security.
  • Perimeter defenses aim to restrict access and include barriers, guards, sensors, buffers, and locks.

Perimeter Defenses and Barriers

  • Passive barriers restrict entry: fencing, signage, lighting; chain-link fencing offers limited security.
  • Enhanced perimeter security (Table 2-3 concepts):
    • Anticlimb paint: gel-based, non-hardening coating that makes surfaces hard to climb.
    • Anticlimb collar: spiked collar extending from pole to deter climbing.
    • Roller barrier: rotating cups on top of fences to prevent gripping.
    • Rotating spikes: high-security deterrent on walls/fences; color-matched to environment.
    • Barricades: direct traffic control; not always tall enough to deter determined intruders.
    • Bollards: short, sturdy vertical posts to prevent vehicle ramming.
  • Active barriers: security guards (active defense) and video surveillance (CCTV) with monitoring by guards.
  • Drones (UAVs) increasingly used for monitoring.

Security Guards and Video Surveillance

  • Guards provide active security and can distinguish intruders from legitimate visitors; two-person integrity (2-person control) reduces insider compromise risk.
  • CCTV considerations: fixed versus dome cameras; live monitoring vs. recording for later analysis; AI-enabled live-object detection can trigger alerts and lockdowns.
  • Importance of active monitoring versus passive recording.

Sensors in Physical Security

  • Infrared (IR) sensors: detect IR radiation; two types:
    • Active IR: emits IR and detects reflections; proximity sensing.
    • Passive IR: detects IR emitted by objects (e.g., warm bodies); effective for motion-based detection.
  • Passive IR note: a passive IR sensor can detect objects with temperatures above ~5 K5\text{ K} (−450450^{\circ}F).
  • Microwave sensors: use high-frequency radio waves; cover large areas; can sense daylight levels to adjust lighting; effective for warehouses.
  • Ultrasonic sensors: use ultrasonic waves; distance calculation: Distance=Time3432Distance = \frac{Time \cdot 343}{2} in meters, where 343 m/s is the speed of sound in air.
  • Note 15–Note 17 cover IR basics and microwave advantages.
  • Pressure sensors: measure force per unit area (Pascal is 1 Pa=1 N/m21\ \text{Pa} = 1\ \text{N/m}^2, US uses psi\text{psi}; underground pressure sensors detect entry and direction of travel for pedestrians/vehicles.

Data Leakage Prevention and Protection of Transmission

  • Faraday Cage: metallic enclosure that blocks electromagnetic fields; used for shielding devices and in crime scenes (Faraday bags).
  • Faraday bags: portable shielding for phones/tablets/laptops to prevent remote wiping of evidence.
  • Protected Distribution System (PDS): conduits carrying data cabling between secure areas; standard DoD practice.
  • Hardened carrier PDS: conduit is metal tubing with welded/sealed connections; underground burial requires concrete encasement and locked access.
  • Alarmed carrier PDS: sensing ability to detect intrusions via acoustic/vibration sensors; benefits include continuous monitoring and concealment.
  • Computer hardware security: laptop security slots and cable locks; safes or locked cabinets for storage; pre-wired locking cabinets for charging and updates.

Data Security: Classification, Types, and Sovereignty

  • Data classifications: organize data by sensitivity and handling requirements; common framework includes:
    • Confidential: Highest level; access restricted to preapproved users.
    • Private: Restricted data with a need-to-know basis.
    • Sensitive: Could cause significant harm if disclosed (riskier data).
    • Restricted: Access limited to employees with business need and approval.
    • Critical: Data critical to mission or availability; requires rigorous protection.
  • Data handling guidance (Table 2-4): for each type, appropriate handling steps align with confidentiality, integrity, and availability needs.
  • Data types (examples):
    • Regulated data (e.g., PHI under HIPAA).
    • Intellectual property (IP): patents, trademarks, copyrights, trade secrets.
    • Trade secrets: three elements—independent economic value, not generally known, reasonable secrecy efforts.
    • Legal information: neutral legal facts.
    • Financial information: monetary transactions and scores.
    • Human-readable vs non-human-readable data: human-readable (e.g., plain text) vs non-human-readable (machine-readable, e.g., JSON, XML).
  • Data states: three states of data
    • Data in use (data in processing)
    • Data in transit (data in motion)
    • Data at rest (data stored on electronic media)
  • Data sovereignty: country-specific requirements for data storage and processing; data may need to remain within borders; GDPR and other laws affect penalties and compliance.
  • Geolocation vs GeoIP:
    • Geolocation provides precise longitude/latitude coordinates.
    • GeoIP uses IP address to infer location, often with city/state data via ISPs.
  • Practical implications: cross-border data flows, regulatory penalties, and the need to align technical controls with regulatory requirements.

Data Security Methods and Data Minimization

  • Data minimization: collect only data necessary for a task; periodically review data collection practices.
  • Data masking: replace sensitive elements with obfuscated equivalents; must be non-reversible to restore original data.
  • Tokenization: replace sensitive data with tokens; original data stored in a token vault; can be reversible through a vault, enabling pseudo-anonymization if reversible.
  • Restrictions: permission restrictions limit access to those with legitimate business needs; geographic restrictions limit access by location.
  • Segmentation: classify data, tag elements with their classification, and separate the most sensitive data as the protect surface; apply extra controls around critical surfaces.
  • Data sanitization concepts: masking and tokenization are forms of data sanitization.

Data Breach Consequences and Legal Context

  • Consequences of data breaches include:
    • Reputation damage and loss of customers; regulatory letters to affected users.
    • IP theft of enterprise or customer data.
    • Financial penalties under laws such as HIPAA, Sarbanes-Oxley, GLBA, PCI DSS, and state laws.
    • GDPR penalties for EU-based entities: Tier 1 up to 10,000,000€10{,}000{,}000 or 2% of worldwide revenue, Tier 2 up to 20,000,000€20{,}000{,}000 or 4% of worldwide revenue, whichever is higher.
  • HIPAA Breach Notification Rule: breaches of 500+ records must be reported to DHHS within 60 days; breaches under 500 must be reported by the end of the calendar year in which the breach occurred (or earlier if required by local laws).
  • Data breach impact examples: reputational harm, regulatory scrutiny, financial penalties, and potential impacts to stock price.

Data Governance and Practical Considerations

  • General data considerations before controls:
    • Data state (in use, in transit, at rest) and where data is located (geographic considerations).
    • Data sovereignty and country-specific regulations.
    • The balance of confidentiality, integrity, and availability when labeling data.
  • Data types vs data classifications: data types describe the kind of data (regulated, IP, trade secret, etc.); classifications describe the sensitivity and protection requirements.
  • JSON and XML as non-human-readable data concepts: JSON is a lightweight data-interchange format derived from JavaScript; XML is another non-human-readable format used for data transport; both can be interpreted by machines, and with training, by humans as well.

Case Projects and Hands-On Labs (Overview)

  • Case and hands-on projects emphasize practical application:
    • Case Project 2-1: #TrendingCyber – identify three physical and three operational security procedures to prevent the described break-ins.
    • Case Project 2-2: Phishing Simulators – research simulators, compare features, assess training value.
    • Case Project 2-3 to 2-6: various labs on CCTV technologies, sensors, and tokenization.
  • Virtual labs and MindTap resources accompany these modules for practical exercises.

Review Questions and Key Concepts (Sample)

  • What is the attack surface of social engineering?
    • Answer: Human vectors; manipulation of people; deception.
  • Which principle of human manipulation did an attacker attempt on Bjorn in a phone call claim incident? Options include Authority, Fright/Intimidation, Urgency.
  • Which of the following is NOT a personal technique used by social engineering attackers? Options:
    • Provide a reason, Project confidence, Demand compliance, Use evasion and diversion, Make them laugh.
  • What type of phishing attack involves targeting a specific individual or role (e.g., a senior executive)? Answer: Spear phishing; Whaling is a variant targeting executives.
  • Tobias received an SMS claiming bank overdrawn; this is an example of which attack? Answer: Smishing (SMS phishing).
  • Which attack is masquerading as a real or fictitious character and acting in that role? Answer: Impersonation.
  • What is typo squatting? Answer: Registering domains with close spellings to mislead users who mistype a URL.
  • What is bitsquatting? Answer: Registering domains that differ by a single bit flip from legitimate domains; a known tactic.
  • Define misinformation vs disinformation.
    • Misinformation: false information without malicious intent.
    • Disinformation: false information spread with malicious intent.
  • What are the four general categories of controls? Answer: managerial, operational, technical, physical.
  • Name four sensor types used in physical security and a key property of each: IR (active vs passive; motion detection), Microwave (large-area monitoring and daylight sensing), Ultrasonic (distance measurement with Distance = ( Time \cdot 343 / 2 )), Pressure (per-area force measurement and direction detection).
  • What are Faraday cages used for in security contexts? Answer: Prevent entry/exit of electromagnetic fields; protect devices and preserve evidence (Faraday bags).
  • What is a Protected Distribution System (PDS)? Answer: A system of cable conduits used to protect classified data between secure areas; can be hardened or alarmed.
  • What data state describes data while being processed or used by devices? Answer: Data in use (data in processing).
  • What governs data locality and data residency across borders? Answer: Data sovereignty; GDPR and national privacy laws.

Key Terms (glossary highlights)

  • Access badge, Access control vestibule, Bollard, Brand impersonation, Business Email Compromise (BEC), Confiential, Critical, Data in transit, Data in use, Data at rest, Data sovereignty, Data minimization, Data masking, Tokenization, Restrictions, Segmentation, Encryption (implicit through data protection concepts), Faraday cage, Protected Distribution System (PDS), Geolocation, GeoIP, Typo squatting, Bitsquatting, Phishing, Spear phishing, Whaling, Vishing, Smishing, Watering hole, Impersonation, Pretexting, Redirection, Misinformation, Disinformation, Shoulder surfing, Ultrasonic, Infrared (IR) sensors, Microwave sensors, Pressure sensors, CCTV, AI in surveillance