Spotting social engineers: An eye on body language

By
Follow google news

Facial expressions don't match speech a giveaway.

Body language, gestures, and facial expressions can be analysed to identify attackers entering a premise to instal malicious hardware or software.

Spotting social engineers: An eye on body language

Social engineering experts Chris Hadnagy and Paul Kelly said malicious social engineers who attempt to compromise an organisation by physical intrusion may display discomfort such as crossing their arms, and show facial expressions that aren't in line with what they say.  

But Kelly, who formerly served as a special agent in the US Secret Service for more than twenty years, explained that when verbal and nonverbal communication are contradictory it was dangerous to jump to the conclusion that someone is lying.

"Do not make a rush to judgement,” Kelly told delegates at the SC Congress. "Do not make a decision unless you have all the input."

He said “misattribution of emotion" was a "vulnerability in judgement”.

In order to mitigate socially engineered attacks, Hadnagy suggested that companies implement security awareness training and actionable policies at work, meaning enforcing rules that employees can realistically follow.

He also said that management should carry out regular tests that mimic real-life attack scenarios and response plans.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

National photo licence recognition system set to go live in 2025

National photo licence recognition system set to go live in 2025

Hackers using F5 devices to target US gov networks

Hackers using F5 devices to target US gov networks

Qantas says customer data released by cyber criminals

Qantas says customer data released by cyber criminals

Austrade to replace its data centre core network

Austrade to replace its data centre core network

Log In

  |  Forgot your password?