CAPEC-416: Manipulate Human Behavior

Meta Stable 严重程度: Medium 攻击可能性: Medium

CAPEC版本: 3.9

更新日期: 2023-01-24

攻击模式描述

An adversary exploits inherent human psychological predisposition to influence a targeted individual or group to solicit information or manipulate the target into performing an action that serves the adversary's interests. Many interpersonal social engineering techniques do not involve outright deception, although they can; many are subtle ways of manipulating a target to remove barriers, make the target feel comfortable, and produce an exchange in which the target is either more likely to share information directly, or let key information slip out unintentionally. A skilled adversary uses these techniques when appropriate to produce the desired outcome. Manipulation techniques vary from the overt, such as pretending to be a supervisor to a help desk, to the subtle, such as making the target feel comfortable with the adversary's speech and thought patterns.

前提条件

  • The adversary must have the means and knowledge of how to communicate with the target in some manner.

后果影响

影响范围: Confidentiality Integrity Availability

技术影响: Other

说明: Attack patterns that manipulate human behavior can result in a wide variety of consequences and potentially affect the confidentiality, availability, and/or integrity of an application or system.

缓解措施

An organization should provide regular, robust cybersecurity training to its employees to prevent successful social engineering attacks.

关键信息

CAPEC ID: CAPEC-416

抽象级别: Meta

状态: Stable

典型严重程度: Medium

攻击可能性: Medium