Catch me, Yes we can! - Pwning Social Engineers @HackersOnBoard
Catch me, Yes we can! - Pwning Social Engineers  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 15 hours ago
Social engineering is a big problem but very little progress has been made in stopping it, aside from the detection of email phishing. Social engineering attacks are launched via many vectors in addition to email, including phone, in-person, and via messaging. Detecting these non-email attacks requires a content-based approach that analyzes the meaning of the attack message.

We observe that any social engineering attack must either ask a question whose answer is private, or command the victim to perform a forbidden action. Our approach uses natural language processing (NLP) techniques to detect questions and commands in the messages and determine whether or not they are malicious.

Question answering approaches, a hot topic in information extraction, attempt to provide answers to factoid questions. Although the current state-of-the-art in question answering is imperfect, we have found that even approximate answers are sufficient to determine the privacy of an answer. Commands are evaluated by summarizing their meaning as a combination of the main verb and its direct object in the sentence. The verb-object pairs are compared against a blacklist to see if they are malicious.

We have tested this approach with over 187,000 phishing and non-phishing emails. We discuss the false positives and false negatives and why this is not an issue in a system deployed for detecting non-email attacks. In the talk, demos will be shown and tools will be released so that attendees can explore our approach for themselves.


Black Hat USA 2018
Catch me, Yes we can! - Pwning Social EngineersBlack Hat USA 2018 - InfoSec Philosophies for the Corrupt EconomyBlack Hat USA 2018 - ZEROing Trust Do Zero Trust Approaches Deliver Real SecurityARTist - An Instrumentation Framework for Reversing and Analyzing Android Apps and the Middleware.Black Hat USA 2018 - Legal Liability for IOT Cybersecurity VulnerabilitiesBlack Hat USA 2018 - SDL That Wont Break the BankDay Zero A Road Map to #BHUSA 2018Black Hat USA 2018 - The Air Gap JumpersBlack Hat USA 2018 - AI & ML in Cyber Security - Why Algorithms are DangerousBlack Hat USA 2018 - Stealth Mango and the Prevalence of Mobile SurveillancewareBlack Hat USA 2018 - No Royal Road … Notes on Dangerous GameBlack Hat USA 2018 - Deep Neural Networks for Hackers Methods, Applications, and Open Source Tools
HackersOnBoard |

Catch me, Yes we can! - Pwning Social Engineers

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER