Analysis of a social engineering threat to information security exacerbated by vulnerabilities exposed through the inherent nature of social networking websites
David Mills · 2009
Social engineering is defined as "a process in which an attacker attempts to acquire information about your network and system by social means." Social networking websites are those where one person creates a message and presents it to an audience, either known or unknown, (a process referred to as "posting") to be read at a later time. While there are certainly thousands of social networking websites worldwide, this paper references the three most globally visited social networking websites These are, according to Alexa.com on September 1, 2009, Facebook.com, visited by 23.17% of all Internet users; Blogger.com, visited by 9.25% of all Internet users; and MySpace.com, visited by 4.45% of all Internet users. In addition, we can include Twitter, a fourth such website, on the Internet today. Social networking websites present a new aspect of identity and information protection because personal information that is provided on these websites can be used as a means of social engineering against not only that person but any organization's information security with which this individual is affiliated. Account "hijacking" occurs when a perpetrator compromises established security measures to gain unauthorized access to the account owner's respective console; a process that can referred to as "hacking." An account can be "spoofed" by a perpetrator creating a credible online identity for the purposes of impersonation. Personnel who are discovered to have authorization within an organization may have their active social networking account hijacked or hacked; or their online identity spoofed, which then leaves their respective organization(s) vulnerable to some level of threat exposure. Because of the threat social networking websites can create, organizations must create and implement security policy which helps to prevent disclosure of any information about the organizations network, infrastructure, or Information Security through content written into a social networking website.