Read up on the latest ideas and technologies from companies that sell hardware, software and services. Why Security SaaS Makes Sense Today
Email Archiving Implementation: Five Costly Mistakes to Avoid
Solve Exchange Mailbox Storage Issues Once and for All
Strategies for Eliminating .PST Files
Web Security SaaS: The Next Generation of Web Security
Delivering the Power of Choice with Microsoft Dynamics CRM
Best Practice in Building an Integrated Information Management Strategy
Taking On Demand CRM Integration to the Next Level
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Traditional e-mail phishing exploits are still growing in numbers, but they seem almost tame compared with newer, more virulent malware used by cybercrime rings that trade in financial account information.
These increasingly sophisticated and organized groups are using such tricks as keystroke loggers, browser redirectors and trojan horses to harvest, store and sell stolen information. And they're using automated, untraceable armies of botnets to help.
"Phishers have begun to specialize in malware, which we think is going to be a continued push. Some specialize in payload. Others specialize in delivery. This is a business for them, and they treat it as such. It's all become very sophisticated," says Brad Keller, e-commerce business risk manager at a bank.
"We're at the stage, technologically, where the criminals are ahead of us, and I don't see that gap closing anytime soon," adds George Rapp, senior vice president and director of IT for an online commercial and retail bank.
This bank has more than 50 percent voluntary adoption of multifactor authentication among its user base. Most have opted to use memory-phrase authentication (such as first pet's name, elementary school name or something else only they would know), with a small percentage of more technical users opting to pay $US25 a year for RSA Secure Tokens.
In the next few months, Rapp plans to require multifactor authentication for all users. Even then, he says, he's still worried about "man-in-the-middle" attacks that would let malware manipulators get at account data during the authenticated session.
His concern is well founded. In February, iDefense, a VeriSign-owned security intelligence company, began tracking a growing botnet called MetaFisher. By mid-March, when iDefense reported it to the public, MetaFisher had affected more than a million account holders, most of them European.
MetaFisher transfers bank account information during open connections, which raises concerns among security experts that phishers have already foiled the industry's best planned defences -- multifactor authentication and guest integrity checks on consumer PCs -- even before companies like the banks can deploy them.
The high cost of phishing
The stakes are high for both sides. Phishers make good money from traditional and automated techniques, which Gartner says conservatively cost consumers and businesses $US2.7 billion in the first half of 2005. As phishers haul in their illicit gain, businesses stand to lose their e-commerce communications and revenue channels altogether.
Of 5000 consumers surveyed, 42 percent say they've curbed their online shopping because of phishing fears, according to the Gartner study. Meanwhile, confidence in e-mail is at an all-time low, as 80 percent say they distrust e-mail claiming to be from brands they know.
At the very least, if trust is not restored, Gartner predicts phishing and similar crimes will slow Internet growth between 1 and 3 percent through to the end of 2008.
"What you've got here is the perfect storm: a global network worth trillions of dollars offering near-perfect anonymity, instant connectivity to millions of easy marks and countless ways to launder money," says Marcus Sachs, who directs the cybersecurity research centre at the US Homeland Security Department.
"Everything right now is working in favour of the criminals. There's not enough trained law enforcement. And the infrastructure itself is not reliable enough for the load we've put on it," Sachs adds.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
NetStar Networks Calls Brisbane Home 2008-10-13 12:01:00+10
New Verizon Business Managed Service Makes Collaboration Easier 2008-10-13 10:06:00+10
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
Enterprise Wireless WLAN Security
Learn more about the security challenges to be faced when defining and implementing security mechanisms within diverse wired and wireless network environments. Download this must-read guide to plan your wireless data protection strategy now.










