Every
individual and organization with an internet presence needs some form of
protection against cyber-attacks and security threats. Hackers are constantly
trying to gain access to computer systems to steal, change or destroy
information. Information and system security help prevent valuable consumer and
company data from internal and external attacks.
An attacker can use the simple ping command to carry out
a cyber-attack. One form of this is called the Ping of Death, or PoD. A poD is
a denial of service attack, meaning its purpose is to shut down a machine or
network, making it inaccessible to its intended users. A PoD involves the
attacker sending malformed or oversized packets in fragments using the ping
command. When the target system attempts to reassemble the fragments, a memory
overflow could occur and lead to various problems, including a crash.
Social engineering is the art of manipulating people to
give up confidential information, typically passwords or bank information, or
to take control over your computer. Social engineering is prevalent because it
is easier for hackers to trick people into trusting them than to hack their
passwords. Most security professionals agree that the weakest link in the
security chain is the human who accepts a person or scenario at face value. By
using social engineering, hackers can bypass all established security protocols
with minimal effort. A social engineering attack could come in an email from a
friend or a Facebook message. If a Facebook account is hacked, the attacker can
send messages to everyone in the victim's contact list, spreading malware or
gathering personal information from them. One method to help prevent social
engineering is to delete any requests for financial information or passwords.
Organizations such as banks and online shopping sites will never ask for
personal information via email. If an individual receives a suspicious request
and is unsure what to do, they should contact the company by visiting the
organization’s website or calling them. Organizations should have security
policies in place to deal with all types of cyber-attacks. Companies should
update these policies regularly to protect against new threats. Requiring
regular password changes should also be necessary for the security policy.
Passwords should contain a combination of numbers, special characters, and
letters. Incident handling procedures are equally important when dealing with
social engineering attacks (Ghafir et al., 2016). Suppose a victim is trained
to identify an intruder and quickly implement security measures. In that case,
the attack can be stopped before any damage is done, resulting in the intruder
being located.
One of the most common forms of social engineering is
phishing. Phishing is when a hacker tries to bait an unsuspecting victim into
sharing sensitive information, such as bank account information, credit card
numbers, or other personal data. (Vahid, 2017). In a phishing attack, the
hacker often sends an email pretending to be from a legitimate organization,
such as the victim's bank, employer, or a known company like Amazon. The
attacker will ask the recipient to verify credit card information, secure
credentials or ask them to click on a malicious link. This can lead to a
malware installation, which allows the attacker to gain access to the victim's
computer or reveal sensitive information, leading to unauthorized purchases or
identity theft. If an organization becomes a victim of a phishing attack, the
losses can be devastating. Financial losses, declining market share, loss of
reputation, and consumer trust are all adverse effects of a business succumbing
to a phishing attack. One way to protect against phishing attacks is to train
employees on cyber-security procedures. Everyone should be made aware of how to
identify spam emails and know how to identify trusted sources. Organizations
should also test their employees by sending dummy phishing attacks and require
remedial training for those who fail. In the journal article Training to Mitigate Phishing Attacks Using
Mindfulness Techniques, three techniques are discussed for organizations to
prevent phishing attacks. These techniques are automated removal or quarantine
of phishing messages websites, automated warning mechanisms that notify an
individual when they encounter a suspicious message or website, and behavior
training where individuals are taught to identify and report attacks (Jensen et
al., 2017).
References
Ghafir,
I., Prenosil, V., Alhejailan, A., & Hammoudeh, M. (2016). Social
Engineering Attack Strategies and Defence Approaches. 2016 IEEE 4th
International Conference on Future Internet of Things and Cloud (FiCloud),
Future Internet of Things and Cloud (FiCloud), 2016 IEEE 4th International
Conference on, Ficloud, 145–149. https://doi-org.proxy-library.ashford.edu/10.1109/FiCloud.2016.28
Jensen,
M. L., Dinger, M., Wright, R. T., & Thatcher, J. B. (2017). Training to
Mitigate Phishing Attacks Using Mindfulness Techniques. Journal of
Management Information Systems, 34(2), 597–626. https://doi-org.proxy-library.ashford.edu/10.1080/07421222.2017.1334499
Vahid, F., & Lysecky, S. (2017). Computing technology for all. Retrieved from zybooks.zyante.com/