CAPEC-421: Influence Perception of Authority

Attack Pattern ID: 421
Abstraction: Detailed
Status: Stable
+ Description
An adversary uses a social engineering technique to convey a sense of authority that motivates the target to reveal specific information or take specific action. There are various techniques for producing a sense of authority during ordinary modes of communication. One common method is impersonation. By impersonating someone with a position of power within an organization, an adversary may motivate the target individual to reveal some piece of sensitive information or perform an action that benefits the adversary.
+ Relationships

+ Relevant to the view "Mechanisms of Attack" (CAPEC-1000)
ChildOfStandard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern.417Influence Perception
+ Prerequisites
The adversary must have the means and knowledge of how to communicate with the target in some manner.
+ Skills Required
[Level: Low]
The adversary requires strong inter-personal and communication skills.
+ Resources Required
None: No specialized resources are required to execute this type of attack.
+ Consequences

+ Mitigations
An organization should provide regular, robust cybersecurity training to its employees to prevent social engineering attacks.
+ Example Instances
The adversary calls the target and announces that he is the head of IT at the target's company. The adversary goes on to say that there has been a technical issue and he/she needs the target's login credentials for their account. By convincing the target of his/her authority, the adversary hopes the target will reveal the sensitive information.
