Learning Objective 1.1.A: Identify common indicators of social engineering tactics.
- 1.1.A.1 Social engineering attacks employ psychological tactics to manipulate users into revealing sensitive information (elicitation), downloading a malicious file, or clicking on a malicious link. Social engineering can be performed in person but is often done by email, by text message, or through social media messages.
- 1.1.A.2 Adversaries often use psychological tactics like intimidation and urgency to achieve their goals. Intimidation is when an adversary threatens a target with negative consequences if they don’t comply. Urgency is when an adversary creates reasons why a target should act quickly.
Learning Objective 1.1.B: Explain how social engineering tactics influence victims to perform a desired action.
- 1.1.B.1 Social engineering tactics rely on common psychological principles that influence human behavior.
- 1.1.B.2 Intimidation leverages a natural human aversion to negative consequences. By drawing attention to possible negative consequences, adversaries use fear to incite targets to act.
- 1.1.B.3 Urgency leverages a natural human response to react quickly to time-sensitive needs. When targets detect a sense of urgency in a message, they feel pressured to respond or act quickly, which can prevent them from taking the time to consider whether an action is reasonable or safe.
Learning Objective 1.1.C: Describe possible impacts for victims of social engineering attacks.
- 1.1.C.1 Victims may give an adversary personal information that could lead to impersonation, such as name, phone number, address, workplace, pets’ names, or birthdate. These types of information, and information like them, are often used on websites as challenge questions to verify a user’s identity.
- 1.1.C.2 Victims may give an adversary secure information like a one-time password (OTP) or authentication login code, which could allow an adversary to log in to a service as the victim.
- 1.1.C.3 Victims may download malware or click a link that installs malware on their device, steals information from their web browser, or directs them to a website where their login credentials can be captured by an adversary.
هدف التعلم 1.1.A: حدد المؤشرات الشائعة لتكتيكات الهندسة الاجتماعية.
- 1.1.A.1 تستند هجمات الهندسة الاجتماعية إلى تكتيكات نفسية للتلاعب بالمستخدمين بكشف معلومات حساسة (استخلاص)، أو تنزيل ملف ضار، أو النقر على رابط ضار. يمكن تنفيذ الهندسة الاجتماعية شخصيًا، لكنها غالبًا ما تتم عبر البريد الإلكتروني أو الرسائل النصية أو رسائل وسائل التواصل الاجتماعي.
- 1.1.A.2 يستخدم الخصوم غالبًا تكتيكات نفسية مثل التهديد والإلحاح لتحقيق أهدافهم. التهديد هو عندما يهدد الخصوم هدفًا بعواقب سلبية إذا لم يستجيبوا. الإلحاح هو عندما يخلق الخصم أسبابًا تجعل الهدف يتصرف بسرعة.
هدف التعلم 1.1.B: اشرح كيف تؤثر تكتيكات الهندسة الاجتماعية على الضحايا لأداء إجراء مطلوب.
- 1.1.B.1 تعتمد تكتيكات الهندسة الاجتماعية على مبادئ نفسية شائعة تؤثر على سلوك البشر.
- 1.1.B.2 يستغل التهديد الرفض الطبيعي للبشر للعواقب السلبية. ومن خلال لفت الانتباه إلى العواقب السلبية المحتملة، يستخدم الخصوم الخوف لتحفيز الأهداف على التصرف.
- 1.1.B.3 يستغل الإلحاح الاستجابة الطبيعية للبشر للتفاعل بسرعة مع الاحتياجات ذات الوقت المحدد. عندما يكتشف الأهداف شعورًا بالإلحاح في الرسالة، يشعرون بالضغط للرد أو التصرف بسرعة، مما قد يمنعهم من أخذ الوقت اللازم للتفكير فيما إذا كان الإجراء معقولًا أو آمنًا.
هدف التعلم 1.1.C: صف التأثيرات الممكنة على ضحايا هجمات الهندسة الاجتماعية.
- 1.1.C.1 قد يعطي الضحايا للخصوم معلومات شخصية قد تؤدي إلى انتحال الشخصية، مثل الاسم ورقم الهاتف والعنوان ومكان العمل وأسماء الحيوانات الأليفة أو تاريخ الميلاد. غالبًا ما تُستخدم هذه الأنواع من المعلومات وما شابهها في المواقع كأسئلة تحدي للتحقق من هوية المستخدم.
- 1.1.C.2 قد يعطي الضحايا للخصوم معلومات آمنة مثل كلمة مرور مرة واحدة (OTP) أو رمز تسجيل دخول للمصادقة، مما قد يسمح للخصوم بتسجيل الدخول إلى خدمة باسم الضحية.
- 1.1.C.3 قد ينزل الضحايا برمجيات خبيثة أو ينقرون على رابط يقوم بتثبيت برمجيات خبيثة على جهازهم، أو سرقة معلومات من متصفح الويب الخاص بهم، أو توجيههم إلى موقع ويب حيث يمكن للخصم التقاط بيانات تسجيل الدخول الخاصة بهم.




*عتاد شبكي حقيقي: جدار الحماية هو جهاز (أو برنامج) يقع حيث يلتقي هذه الكابلات بالعالم الخارجي




