Академический Документы
Профессиональный Документы
Культура Документы
1
Social Media is the single most effective
resource when developing targeted attacks
There is no firewall, no anti-virus program fo
wet ware (human brain).
Little or no capability to monitor and protect
against in service content and the aggregat
PII.
How can you tell the different between a
legitimate program collecting information to
drive content vs. malware? (or Infoware)
Malicious content in ads or apps.
Reconnaissance and Social Engineering.
CovCom and Command and Control.
Find a real event, especially one that has a
#tag. Create a persona and inject yourself
into the event. By proxy you will be accepte
as being there.
Can then develop social relationships based
on the perception or illusion of a connection
based on time and space.
Jackeey Wallpaper - Android Wallpaper App
Stole User data, sent to China to imnet.us
(developer iceskysl@1sters).
47 percent of Android apps and 23 percent
Phone apps collect some sort of user
nformation.
Spear Fishing
Attacks on SNS increased 70% from 2008 t
2009.
C&C Resources
Aurora good example of effectiveness of us
SNS for Reconnaissance and execution.
Sophos conducted an experiment in late 20
and started friending random people.
• 46% accepted
• 89% divulged their full birthdates
• 50% town of residence
LikeJacking
Block it
DLP
Training
Protect you PII
• Use platforms specifically.
• Be suspicious of content, even from friend
Persona Management
Backstopping
No information is information. Real vs. Alt.
Government needs to think commercially
Limited use of SNS for government purpose
CovCom
Gather personal
information and
information
about
immediate
family
Do SNS
searches for
family
members.
LinkedIn
provides one of
the best
resources for
identifying
specific targets
Linkedin
provides
detailed
professional
information as
well as
associates.
Facebook
Privacy defaults
to off.
Most peoples
friends lists are
exposed.
Location
information on
Gray including
spots he
frequents most
and friends.
Information on
Location, who
frequents, tips,
events.
Real-time
location based
messages using
Google Buzz.
Gowalla is
currently the
most
informative
LBS.
See Everyone
that has
checked in at
Apple HQ.
Mondays are
Indoc days at
Apple.
Berry is excited
to be starting
with Apple
today.
And look he has
a twitter
account too.
Twitter provides
lots of good
background
information
Service
Integration
Eric Arthur Blaire
Martin Place
Age: 44
Sydney Australia
Occupation: Author
Suzanna Hamilton Opened in 1891
Profile
Age: 35 History
History
Occupation: Trainer Events
Profile Recent Visitors
History
Topics