Towards Automating Social Engineering Using Social Networking Sites (Preprint)

Posted: July 6th, 2009 | Author: | Filed under: ASE, PASSAT-09, research, security | Tags: , , , , , , , , , , , , , , , , , , | No Comments »

I made the preprint version of my publication on “Towards Automating Social Engineering Using Social Networking Sites” available online. You can fetch the pdf from here: http://asebot.nysos.net. As I said before I will present this work at this year’s PASSAT in Vancouver.

Abstract—A growing number of people use social networking sites to foster social relationships among each other. While the advantages of the provided services are obvious, drawbacks on a users’ privacy and arising implications are often neglected. In this paper we introduce a novel attack called automated social engineering which illustrates how social networking sites can be used for social engineering. Our approach takes classical social engineering one step further by automating tasks which formerly were very time-intensive. In order to evaluate our proposed attack cycle and our prototypical implementation (ASE bot), we conducted two experiments. Within the first experiment we examine the information gathering capabilities of our bot. The second evaluation of our prototype performs a Turing test. The promising results of the evaluation highlight the possibility to efficiently and effectively perform social engineering attacks by applying automated social engineering bots.


Automated Social Engineering Bot – PASSAT 2009

Posted: June 13th, 2009 | Author: | Filed under: ASE, random, security | Tags: , , , , , , , , , , , , , , , , , , | No Comments »

I got a paper on my Automated Social Engineering Bot accepted at the PASSAT 2009 conference. I’ll post the camery-ready version soon. 🙂


Automated Social Engineering PoC is out

Posted: March 23rd, 2009 | Author: | Filed under: ASE, security | Tags: , , , , , , , , , , , | No Comments »

I finished my thesis on automated social engineering via Facebook two weeks ago. More information and the thesis is available online: http://asebot.nysos.net .

I will present my work in Stockholm tomorrow and then leave to Madrid for some vacations.


An end is in sight …

Posted: February 27th, 2009 | Author: | Filed under: ASE, random, security | Tags: , , , , , , , , , , , , | No Comments »

I’m writing the last pages of my master’s thesis on Automated Social Engineering and should present my work soon. Once it’s done I’m also planning to post a digitial version online on my blog.