Anyone aware or involved in information security in this day and
age, would be quick to agree that the threats linked with using the
Internet have drastically changed since the early-, to
mid-90’s, when the use of this media explosively impacted
culture and commerce. Compared with today’s Internet traffic,
early threats had little way of spreading, the magnitude of users
was tiny and the biggest worry was viruses wreaking havoc on
peoples’ personal computers.
Online threats have come a long way and can now be held
accountable for a growing list of misdeeds and crimes. From the
pettier financially-driven theft – which actually yields the
least of collateral damage – to theft of priceless
intellectual property, facilitating business espionage, involvement
in disrupting critical infrastructures and penetration of secure
systems that can translate into cyber war; the demons of the
digital world impact our finances, our identities and the world as
we know it today.
Although more diverse and more advanced than ever, it appears
that almost all threats still have that one, rather benign looking
gateway. Surprisingly, that gateway is phishing! How do most
threats connect with phishing? And why is this older and well-known
threat still so prevalent today?
The art of deception and persuasion
Looking at the short historical timeline of online threats,
phishing can be considered an ‘old threat’. The term
phishing has been discussed as early as 1996; a quick calculation
shows that phishing is 16 years old now, and yet, the world has not
been able to rid itself from this phenomenon. Phishing is still one
of the top threats on the Internet today; its direct and indirect
costs tax the global economy with billions of dollars in fraud
damages every year.
RSA reports, released early this year, show that worldwide
losses from phishing attacks alone amounted to over USD 520 million
during H1 2011; a 43 percent increase in attack numbers translated
into USD 755 million through H2 2011. The total number of monetary
losses was Rs 5,760 crore (or USD 1.28 billion globally) with India
ranking in the top 5 most targeted countries for phishing attacks,
having been robbed of a USD 38 million portion of that pie.
What makes phishing such a successful threat? In one word:
Evolution. They say “The Strongest Survive” and in that
sense it appears that phishing has what it takes—a good DNA
and the ability to evolve over time.
At the core of this threat lays a powerful magnet – human
emotion. Although phishing is a 21st century crime, manipulation,
deceit and persuasion are not. What makes phishing successful is
the use of social engineering which drives most schemes used by
cyber criminals today to manipulate online users into disclosing
crucial information. The concept of social engineering is deeply
rooted in many fundamental social psychology principles and thus
its perpetual success.
There are several aspects of psychology we can draw-on in
understanding how social engineering works, specifically the
psychology of persuasion. In social psychology, there are two
alternative routes of persuasion that can be employed when
attempting to elicit a response from another:
- A central route to persuasion, which involves the
recipient thinking about the message. - And a peripheral route to persuasion , relying on superficial
clues within a message to get a person to purposefully not
think – but rather react emotionally and react
immediately. - Again, neither is new. That peripheral route to persuasion has
been and still is, vastly used in confidence scams and in
telemarketing fraud.
Because persuasion is such a pervasive component of our lives,
it is easy to overlook the external influences affecting us.
When it comes to phishing, cyber criminals rely on those peripheral
routes to persuasion in order to be successful in getting a victim
to respond via an emotional reaction to anxiety or excitement.
Every phishing attack, of all types (broad spectrum spam, spear
phishing/whaling) begins with a ploy with built-in emotional
triggers. Regardless of the method of delivery of the phishing URL,
the intended user has to be convinced that he needs to visit the
URL for a reason. That reason needs to be valid enough to cause the
user to impart with access credentials and/or personally
identifying information.
The better ploys add these common human motivators and emotions
to the mix:
- Rightful Reward: Tax refunds
- Greed: Unwarranted lottery winnings and 419-scam deals
- False accusation: Tax Fraud report from the authorities
- Curiosity: ‘Look who has been searching for
you’ - Right the wrong: Fake order confirmations from known online
merchants or shopping sites - Trust: Fake e-mails from banks, service providers, investment
houses, social networking friends or professional network
colleagues/ business associates.
In terms of numbers and effectiveness of attack ploys, it
appears that the most successful campaigns rely on trust. This
explains a current and prominent trend of phishing via social
networks or purporting to be a known source, which infallibly
yields more victims. Creating that rush of strong emotion within a
potential victim repeatedly enables cyber criminals to elicit an
immediate response as the victim’s ability to think logically
will likely be hindered. Phishing using social networking as a lure
has risen considerably. In January 2010, this tactic was only used
in 8.3 percent of all phishing attacks but by the end of 2011 the
figure stood at 84.5 percent, according to the 2011 Microsoft
Security Intelligence Report.
