Social Engineering: Difference between revisions

From ICO wiki
Jump to navigationJump to search
 
(40 intermediate revisions by the same user not shown)
Line 1: Line 1:
== In Short ==
== In Short ==


* The third iteration of the current form of the course will be held during the first half of the Spring term 2025, from February 5 to March 27.
* The aim of this course is to provide students with basic knowledge of social engineering and human-based cyberattacks (see the [[ICS0018 Course Guide]] for details). The course is held by the [https://www.taltech.ee/en/itcollege IT College] of [https://www.ttu.ee/ Tallinn University of Technology] and is primarily meant for students of [https://www.taltech.ee/en/cyber-security-engineering Cyber Security Engineering], but other students interested in the human side of cybersecurity can also benefit from it.
* The aim of this course is to provide students with basic knowledge of social engineering and human-based cyberattacks (see the [[ICS0018 Course Guide]] for details). The course is held by the [https://www.taltech.ee/en/itcollege IT College] of [https://www.ttu.ee/ Tallinn University of Technology] and is primarily meant for students of [https://www.taltech.ee/en/cyber-security-engineering Cyber Security Engineering], but other students interested in the human side of cybersecurity can also benefit from it.
* The course can be held in contact or e-learning mode (and possibly some hybrid way as well). Due to large number of visiting students from [https://taltech.ee/en/euroteq/cooperation EuroTEQ], the Spring 2023 run is a full e-course (again see the guide for details). Note: this run is the first under the aegis of the university (it was run once in 2018 as part of the earlier IT College curriculum) - some irregularities can be expected!
* In principle, the course can be held in contact or e-learning mode (and possibly some hybrid way as well). Due to visiting students from [https://taltech.ee/en/euroteq/cooperation EuroTEQ], the Spring 2025 run is a full e-course (see the Course Guide below for details).
* Course code: ICS0018
* Course code: ICS0018
* Lecturers: Kaido Kikkas (lectures/discussions + overall coordination; [[User:Kaido.kikkas]], [https://www.etis.ee/CV/Kaido_Kikkas/eng/ ETIS]) and Kristjan Karmo (seminars/discussions and hands-on tasks; [[User:Krkarm]], [https://www.linkedin.com/in/kristjankarmo LinkedIn]).
* Lecturer: Kaido Kikkas ([[User:Kaido.kikkas]], [https://www.etis.ee/CV/Kaido_Kikkas/eng/ ETIS]). Note: Kristjan Karmo (usually in charge of hands-on seminars; [[User:Krkarm]], [https://www.linkedin.com/in/kristjankarmo LinkedIn]) is absent this time, but will hopefully return in the future runs of the course.
* Programme: [http://ois2.ttu.ee/uusois/aine/ICS0018 at the Study Information System] - unfortunately, it only shows the Estonian version, an updated English-language programme is [https://akadeemia.kakupesa.net/SocEng/programme2023.pdf available here].
* Programme: [http://ois2.ttu.ee/uusois/aine/ICS0018 at the Study Information System] - unfortunately, it only shows the Estonian version, an English-language programme is [https://akadeemia.kakupesa.net/SocEng/programme2023.pdf available here] (note: unchanged from the previous years).
* Volume: 3 ECTS credit points
* Volume: 3 ECTS credit points
* Grading: Pass/fail
* Grading: Pass/fail
Line 19: Line 20:
== Announcements ==
== Announcements ==


* The course kick-off (first lecture, including course intro) will take place on Wednesday, Feb 1 at 14.00 (2PM) Tallinn time (NB! 13.00 in Central Europe!) in the MS Teams environment of the university. The participation invitations will be delivered to all students whose Uni-ID is registered shortly before the event.
 
* The extra seminar will take place in MS Teams (Hands-on channel) on Thursday, March 27 at 16:00 Tallinn time. Attending the event is not mandatory - but it can be used to erase one miss in any class category (lecture, CotW, Hands-on) so it is advised for those who have missed one class too many.
* The course will start with the initial lecture in the University's MS Teams on Wednesday, February 5 at 10:00 Tallinn time.


== Topics, Materials and Notes ==
== Topics, Materials and Notes ==


As the course is new, we will keep tuning the materials - thus they will appear here either before or soon after every lecture session.  
Lecture materials will be published here either shortly before or after every lecture.
 
* Lecture 1: Course intro + main concepts of SE (February 5). [https://akadeemia.kakupesa.net/SocEng/lecture1.odp ODP], [https://akadeemia.kakupesa.net/SocEng/lecture1.pdf PDF].
* Week 1 (Feb 1) lecture: Course introduction + Introduction to Social Engineering (lecture slides: [https://akadeemia.kakupesa.net/SocEng/lecture1.odp OpenDocument], [https://akadeemia.kakupesa.net/SocEng/lecture1.pdf PDF])
* Lecture 2: Information gathering (February 12). [https://akadeemia.kakupesa.net/SocEng/lecture2.odp ODP], [https://akadeemia.kakupesa.net/SocEng/lecture2.pdf PDF].
* Week 2 (Feb 8) lecture: Information gathering (lecture slides: [https://akadeemia.kakupesa.net/SocEng/lecture2.odp OpenDocument], [https://akadeemia.kakupesa.net/SocEng/lecture2.pdf PDF])
* Lecture 3: Elicitation (February 19). [https://akadeemia.kakupesa.net/SocEng/lecture3.odp ODP], [https://akadeemia.kakupesa.net/SocEng/lecture3.pdf PDF].
* Week 3 (Feb 15) lecture: Elicitation (lecture slides: [https://akadeemia.kakupesa.net/SocEng/lecture3.odp OpenDocument], [https://akadeemia.kakupesa.net/SocEng/lecture3.pdf PDF])
* Lecture 4: Pretexting (February 26). [https://akadeemia.kakupesa.net/SocEng/lecture4.odp ODP], [https://akadeemia.kakupesa.net/SocEng/lecture4.pdf PDF].
* Week 4 (Feb 22) lecture: Pretexting
* Lecture 5: Some psychological aspects (March 5). [https://akadeemia.kakupesa.net/SocEng/lecture5.odp ODP], [https://akadeemia.kakupesa.net/SocEng/lecture5.pdf PDF].
* Week 5 (Mar 1) lecture: Psychology in social engineering
* Lecture 6: Influence and persuasion (March 12). [https://akadeemia.kakupesa.net/SocEng/lecture6.odp ODP], [https://akadeemia.kakupesa.net/SocEng/lecture6.pdf PDF].
* Week 6 (Mar 8) lecture: Influence and persuasion
* Lecture 7: The Way of the Ninja (March 19). [https://akadeemia.kakupesa.net/SocEng/lecture7.odp ODP], [https://akadeemia.kakupesa.net/SocEng/lecture7.pdf PDF].
* Week 7 (Mar 15) lecture: The Way of the Ninja
* Lecture 8: Prevention and mitigation (March 26). [https://akadeemia.kakupesa.net/SocEng/lecture8.odp ODP], [https://akadeemia.kakupesa.net/SocEng/lecture8.pdf PDF].
* Week 8 (Mar 22) lecture: Prevention, mitigation and counters


== Frequently Asked Questions ==
== Frequently Asked Questions ==

Latest revision as of 10:31, 26 March 2025

In Short

  • The third iteration of the current form of the course will be held during the first half of the Spring term 2025, from February 5 to March 27.
  • The aim of this course is to provide students with basic knowledge of social engineering and human-based cyberattacks (see the ICS0018 Course Guide for details). The course is held by the IT College of Tallinn University of Technology and is primarily meant for students of Cyber Security Engineering, but other students interested in the human side of cybersecurity can also benefit from it.
  • In principle, the course can be held in contact or e-learning mode (and possibly some hybrid way as well). Due to visiting students from EuroTEQ, the Spring 2025 run is a full e-course (see the Course Guide below for details).
  • Course code: ICS0018
  • Lecturer: Kaido Kikkas (User:Kaido.kikkas, ETIS). Note: Kristjan Karmo (usually in charge of hands-on seminars; User:Krkarm, LinkedIn) is absent this time, but will hopefully return in the future runs of the course.
  • Programme: at the Study Information System - unfortunately, it only shows the Estonian version, an English-language programme is available here (note: unchanged from the previous years).
  • Volume: 3 ECTS credit points
  • Grading: Pass/fail

Course Information

Announcements

  • The extra seminar will take place in MS Teams (Hands-on channel) on Thursday, March 27 at 16:00 Tallinn time. Attending the event is not mandatory - but it can be used to erase one miss in any class category (lecture, CotW, Hands-on) so it is advised for those who have missed one class too many.
  • The course will start with the initial lecture in the University's MS Teams on Wednesday, February 5 at 10:00 Tallinn time.

Topics, Materials and Notes

Lecture materials will be published here either shortly before or after every lecture.

  • Lecture 1: Course intro + main concepts of SE (February 5). ODP, PDF.
  • Lecture 2: Information gathering (February 12). ODP, PDF.
  • Lecture 3: Elicitation (February 19). ODP, PDF.
  • Lecture 4: Pretexting (February 26). ODP, PDF.
  • Lecture 5: Some psychological aspects (March 5). ODP, PDF.
  • Lecture 6: Influence and persuasion (March 12). ODP, PDF.
  • Lecture 7: The Way of the Ninja (March 19). ODP, PDF.
  • Lecture 8: Prevention and mitigation (March 26). ODP, PDF.

Frequently Asked Questions

  • Q: Where can I find information about the course (tasks, grading etc)?
  • A: from the Course Guide
  • ...