2.2.2. Social approaches
The most important aspect of successful social engineering
attacks are social approaches. Hereby attackers rely on socio-
psychological techniques such as Cialdini
'
s principles of
persuasion to manipulate their victims. Examples of persua-
sion methods include the use of (purported) authority. One
common social vector that is not explicitly addressed by Cial-
dini is curiosity, which is, e.g., used in spear-phishing and
baiting attacks. In order to increase the chances of success of
such attacks, the perpetrators often try to develop a relation-
ship with their future victims. According to
Granger (2001)
, the
most prevalent type of social attacks is performed by phone.