Sony Employing "Social Engineering" Tactics For PSN Security
Last year's hack of the PlayStation Network was deemed a "wake-up call" by many experts.
Since that time, Sony has taken strides to make sure it doesn't happen again.
This is why they've brought on former McAfee Chief Security Officer Brett Wahlin to assist; in speaking to Secure Business Intelligence, he talked about the key points of interest for a new and improved PSN (or now, SEN). First and foremost, one must understand their enemy; i.e., social groups like Anonymous looking to make a statement:
"The types of attacks we see are by groups with social agendas. The methods they use aren't the same as the state-sponsored guys. At Sony, we are modifying our programs to deal less with state-sponsored [attacks] and more with socially-motivated hackers. It will be different."
So in other words, Sony security people have to act like social engineers, and that means constantly monitoring staff and users around the world. Basically, they see any Sony employee as a potential target as they all have different levels of access to the network and different levels of vulnerability. Wahlin says it's important to adapt and create strategies based more on general behavior and psychology.
"The strategy combines social engineering psychology with data analytics and user education, using Wahlin's counter-intelligence, FBI-inspired human behaviour profiling methods and advanced fraud detection systems.
We are looking to see if there are there key elements within a person's interaction with their environment. That could be interaction with badging systems, with telephones - when and who do they call- and with systems like browser habits and applications used. All these things allow us to set up a pattern for users, so when something different happens we can respond."
Security experts will tell you that for the most part, hackers are often one step ahead of security software. But at least Sony is doing what they can to insure their Network doesn't suffer a repeat failure and in truth, it's all anyone can really do, right?
Tags: psn, playstation network, psn hack, psn security
3/15/2012 10:03:29 AM Ben Dutka
Put this on your webpage or blog:
Email this to a friend
Follow PSX Extreme on Twitter
Comments (13 posts)
Highlander
Thursday, March 15, 2012 @ 12:10:41 PM
Reply
Online hacking is a fact of life. The PSN hack was most remarkable for the media coverage, not the data stolen, nor the consequences to individuals. To my knowledge not one consumer has had their money or identity stolen as a direct result of the PSN hack. Plenty of people have lost their money and identity due to numerous other hacks, including hacks of financial institutions. So like living in a tornado prone location, you know the risk you are taking and you take precautions against it. But you keep things in proportion.
saintaqua
Thursday, March 15, 2012 @ 12:35:59 PM
Sony was far from the only target last year and it was blown way out of proportion.
Meanwhile so many people have been losing money through Live and MS claims it is due to fishing scams.
Many of the people were not even on Live for months and MS still blames Fifa!
The media tends to ignore when the big bad MS screws up but jumps all over Sony.
Beamboom
Thursday, March 15, 2012 @ 1:49:52 PM
Highlander
Thursday, March 15, 2012 @ 2:07:33 PM
In fact I think that the most effective security strategy for service providers like Sony is very similar. Your perimeter defenses must be strong enough to rebuff casual attempts at attack, but also smart and sensitive enough to detect any level of penetration of the security. They must provide the warning that radar and sirens provide with tornadoes.
Then, like the storm shelter, the network must be designed in layers with sensitive data stored more securely and in such a way that it's possible to decouple the sensitive data from the rest of the system in the case of a successful intrusion. just as you would with a significant tornado, when the siren sounds you check the radar and get in your shelter. If the storm actually tracks over your area, you slam the door closed and hang on to those that are most valuable to you. With a network, you slam the door closed if an intruder is working on the layered security around the secure data. The storm may destroy the house, but the valuable things - lives - are safe.
In many ways Sony did this with the PSN hack. They took the rather drastic action of downing the entire network in order to severe the attackers from the data. They slammed the door closed. Of course their warning system could have been better, but what they did was effective. What Sony needs to do in the future is have better perimeter defense, and detection. Along with a layered approach so that they can detect and terminate intrusions quickly. They must maintain more than one layer of security around sensitive data. Only if that storm comes right over the house (in other words an intrusion breaches multiple layers of security) would they need to close the door on the shelter. Even if attackers tore up the rest of the network's security, maintaining the security of the data is paramount. Just as in a tornado, the storm can completely destroy a home, but maintaining the safety of the residents is the most important thing.
Beamboom
Thursday, March 15, 2012 @ 4:30:45 PM
Highlander
Thursday, March 15, 2012 @ 4:49:00 PM
You can build tornado resistant homes, but there's not a lot that can resist an EF5. Even a tornado resistant home is going to take damage to doors and windows, even if it remains structurally sound. The purpose of making them tornado resistant is to protect the occupants,not so much the home. It's been very educational living in a tornado prone area, I can tell you.
BTW, Norway and the UK do get tornadoes, they are just typically weaker, and often coastal. Usually they'll be termed water spouts because they occur over water. Sometimes tthey do happen on land, but it's far rarer than in places like Illinois, Arkansa, Missouri, Kentucky, Tennessee or Indiana.
Hypntick
Thursday, March 15, 2012 @ 12:32:51 PM
Reply
Highlander
Thursday, March 15, 2012 @ 12:50:30 PM
Beamboom
Thursday, March 15, 2012 @ 1:52:19 PM
WorldEndsWithMe
Thursday, March 15, 2012 @ 2:53:47 PM
Reply
Underdog15
Friday, March 16, 2012 @ 11:10:57 AM
GGCAN
Thursday, March 15, 2012 @ 3:18:58 PM
Reply
They said to get a card that only has a small amount on it.
I've done this for the PSN (SEN) as I just started using Music Unlimited in Canada and there isn't an option when you first sign up to use PSN cards(which I've been doing for some time now).
With a low limit card, if it does ever happen, not much is available to the person stealing the identity.
Most companies now a days check usage and if it's out of the norm, they'll contact you, or send you another card (this happened to me last year when I used a Japanese website to order....I received another card from my bank, stating the site had been previously compromised and just to be safe another card was issued to me).

See Full Image









Temjin001
Reply
Thursday, March 15, 2012 @ 10:56:32 AM
But anyway, a good many did seem to be scared to put their CC information into PSN due to the hacker thing that happened last year. So hopefully SOny's efforts to regain consumer internet security trust succeeds. Anyway, it's good to know that in some public communities it's pro PS3 all the way =)
Last edited by Temjin001 on 3/15/2012 11:00:12 AM