Social engineering · 사회 공학(Social engineering)
Hacking the human
- The weakest part of any system is often people, not computers.
- Social engineering means tricking a person into giving away secrets or access. No malware needed.
인간을 해킹하는 것
- 시스템의 가장 약한 점은往往是 컴퓨터가 아니라 사람입니다.
- 사회 공학(Social engineering) 은 사람을 속여 비밀이나 접근 권한을 내게 만드는 것입니다. 말웨어가 필요 없습니다.
Phishing and pharming
- Phishing — a fake email or message that looks real, asking you to "log in" on a fake site that steals your password.
- Pharming — redirecting you to a fake website even when you typed the correct address.
- Both aim to steal your login details by pretending to be a site you trust.
피싱과 파밍
- 피싱(Phishing) — 실제처럼 보이는 가짜 이메일이나 메시지로, 사용자를 속여 가짜 사이트에서 "로그인"하게 만들어 비밀번호를 도난합니다.
- 파밍(Pharming) — 올바른 주소를 입력했음에도 가짜 웹사이트로 재지향합니다.
- 둘 다 신뢰할 수 있는 사이트인 척하여 로그인 정보를 도난하는 것을 목표로 합니다.
Spotting a phishing message
- Check the sender's address and the link — hover to see where it really goes.
- Watch for urgency ("act now or your account closes!") and spelling mistakes.
- A real bank will never ask for your password by email.
피싱 메시지 식별하기
- 보낸이의 주소와 링크를 확인하세요. 마우스를 올릴 때 실제로 어디로 가는지 확인합니다.
- 급박함("지금 action하지 않으면 계정이 폐쇄됩니다!")과 오타를 주의하십시오.
- 실제 은행은 이메일로 비밀번호를 요청하지 않습니다.
Other tricks
- Shoulder surfing — simply watching you type your PIN.
- Baiting — leaving an infected USB stick for a curious person to plug in.
- The defence is awareness: slow down and check before you click or type.
Covers: IGCSE 5.3 (phishing, pharming, social engineering), AP CSP Big Idea 5.
기타 술기
- 숄더 서핑(Shoulder surfing) — 단순히 사용자가 PIN을 입력하는 것을 바라보는 것.
- 바이팅(Baiting) — 호기심 많은 사람이 꽂도록 감염된 USB 스틱을 남겨두는 것.
- 방어책은 인식(Awareness) 입니다: 클릭하거나 입력하기 전에 멈추고 확인하십시오.
적용: IGCSE 5.3 (피싱, 파밍, 소셜 엔지니어링), AP CSP Big Idea 5.
Now you try
- First build a tiny phishing filter: check the sender's address and where the link really points.
- Then match three more tricks to their names — exactly what the exam asks you to do.
이제 직접 해보기
- 먼저 작은 피싱 필터를 구축하십시오: 보낸이 주소와 링크가 실제로 어디로 향하는지 확인합니다.
- 그런 다음 나머지 세 가지 술기를 이름과 매칭하십시오 —这正是 시험에서 요구하는 내용입니다.
Common mistakes
- The weakest link is often people, not software.
- Phishing tricks you into giving up secrets — check the sender and the link first.
흔한 실수
- 가장 약한 고리는往往是 소프트웨어가 아니라 사람입니다.
- 피싱은 사용자를 속여 비밀을交出하게 만듭니다. 먼저 보낸이와 링크를 확인하십시오.
Build a tiny phishing filter. The real bank writes from addresses ending @mybank.com and its links start with https://mybank.com. Print phishing if either check fails, otherwise ok. · 작은 피싱 필터를 구축하십시오. 실제 은행은 @mybank.com로 끝나는 주소에서 발송하고 링크는 https://mybank.com로 시작합니다. EITHER 검사에 실패하면 phishing을 출력하고, 그렇지 않으면 ok을 출력하십시오.
Click Run to see the output here. · 출력을 보려면 '실행'을 클릭하세요.
Name the trick. Set each variable to shoulder surfing, baiting or pharming. · 술책의 이름을 적으십시오. 각 변수를 shoulder surfing, baiting 또는 pharming로 설정하십시오.
Click Run to see the output here. · 출력을 보려면 '실행'을 클릭하세요.