Social Engineering, Applied Educational Theory, and the Gap Between Them

No ratings

Presented at BSidesLisbon 2018 by

In this space, we glorify and revel in impressive and amusing social engineering hijinks. This is all fun and good, until the point where we need to get our colleagues to be better about security and the only "soft skills" that we have learned about related to security are based on deception and manipulation.While the framing of this talk is for changing security behaviours, the ideas are fairly broadly applicable for any situation where you are trying to support people making better, more informed choices.While social engineering can be powerful for getting people to do things for you, the effect is short acting and requires your constant intervention. Changing individual and organisational security practices requires a different approach to be effective, especially in the medium and long term. Effectively building awareness and competency on security behaviours is much more like other kinds of teaching and other kinds of behaviour change interventions, like public health. This talk will explore for basic ideas from these fields and how they can be applied. I will also cover the problems with using social engineering on your coworkers for effecting security behaviours and how and why it is counter-productive. Rogue One: A WiFi storyRicardo GoncalvesN/AN/AAn always on, all times and everywhere connected life is today's mantra. This in turn adds the need for an increasing number of available Wi-Fi Access Points (APs). These can be located almost everywhere: schools, coffee shops, shopping malls, airports, trains, buses, hotels... This proliferation raises the following questions:- Among all these APs how can a user be sure that (s)he is connecting to a trusted source?- In a small-medium sized company how do they guarantee their wireless security in a cost-effective way?In order to address these questions there is the need to effectively detect Rogue Access Points (RAPs). There are open source solutions described in the literature and others developed within enterprises for commercial purposes. Relative to the latter, it has become obvious that they are not accessible to everyone due to their high costs, and the former do not address all the types of RAPs.In this work, we research the solutions to detect RAPs and do a thorough survey study of the most commonly used and recent Wi-Fi type of attacks. Based on this knowledge we developed a solution to detect RAPs, Rogue AP Detector , which covers the most commonly known attacks. This proposed solution, is a modular framework composed of Scanners, Detectors and Actuators, which are responsible for scanning for available APs, apply a set of heuristics to detect them and apply a countermeasure mechanism.