【24h】

Advanced Persistent Threats Social Engineering

机译:高级持久威胁与社会工程

获取原文
获取外文期刊封面目录资料

摘要

Social Engineering has long been a very effective means of attacking information systems. The term knowledge worker has been coined by Peter Drucker more than 50 years ago and still describes very well the basic characteristics of many employees. Today, with current hypes such as BYOD (bring your own device) and public cloud services, young professionals expect to use the same technology both in their private life and while working. In global companies teams are no longer geographically co-located but staffed globally just-in-time. The decrease in personal interaction combined with the plethora of tools used (E-Mail, IM, Skype, Dropbox, Linked-In, Lync, etc.) create new opportunities for attackers. As recent attacks on companies such as the New York Times, RSA or Apple have shown, targeted spear-phishing attacks are an effective evolution of social engineering attacks. When combined with zero-day-exploits they become a dangerous weapon, often used by advanced persistent threats. In this talk we will explore some attack vectors and possible steps to mitigate the risk.
机译:社会工程长期以来一直是一种非常有效的攻击信息系统手段。第50多年前,彼得·德鲁克的术语知识工人已经创造出来,仍然介绍了许多员工的基本特征。今天,目前的山顶如BYOD(带上自己的设备)和公共云服务,年轻的专业人​​士希望在私人生活中使用相同的技术和工作。在全球公司中,队伍不再是地理位置的,而是在全球上立即使用。个人互动的减少与使用过多的工具(电子邮件,IM,Skype,Dropbox,Linked-In,Lync等)相结合为攻击者创造了新的机会。由于最近对纽约时报,RSA或Apple等公司的攻击表明,有针对性的矛网络钓鱼攻击是社会工程攻击的有效演变。当与零日漏洞结合时,它们成为一种危险的武器,经常被高级持续威胁使用。在这次谈话中,我们将探讨一些攻击向量和可能的步骤来减轻风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号