- 1
- 2
- 3
- 4
- < previous
Enterprise tools
Ideally, enterprises should also look for tools that scan in combination with authentication so that logon credentials are not allowed until the integrity check is completed.
Toolsets like these would go a long way towards quelling concerns among financial services companies that man-in-the-middle attacks can bypass stronger authentication by taking over accounts during authenticated sessions, Rapp says. But he's not convinced they can totally block man-in-the-middle attacks.
"These phishing packages contain rootkits, which can turn off the security and make it look to a scanner like it's all up to snuff when really it's infected with malware," he says.
The final authentication piece needed, says Sally Steward, vice president of strategy for TriCipher, is a way to follow up on authentication by working with the financial institutions' fraud-detection systems. That way, should a criminal somehow slip past all these front-end defences, open new accounts and transfer funds in a way that's suspect, the system could follow up by logging the event and alerting investigators.
As with every other information security problem to arise since the beginning of IP networking, protecting online commerce from the phishing blight calls for education and layered security. But we also need to look forward to new standards, technologies and frameworks to deal with increasingly sophisticated problems, Sachs and others say.
"The bad guys are ahead of our best defences at this moment in time," Rapp adds. The gap isn't going to be as easy to close as it has been in the past. But I urge everyone doing financial business on the Internet to at least start out with multifactor authentication to make it that much more difficult for the criminals to get at our consumers' financial data."
Fighting back
While automated phishing attacks are on the rise, phishes that still use e-mail and instant message lures and fake logon sites still abound. Below is an update about how companies are responding and what users should be aware of.
Closed e-mail: Two years ago, eBay started sending restricted e-mail to its customers. Last year, financial services began following suit. For example, Wachovia Bank now uses a closed, authenticated e-mail system as its only way to message customers. And eBay uses its internal "my messages" mail to educate consumers by putting security messages around the frames, an eBay spokeswoman says.
Education: In addition to "practicing safe computing" by not clicking links and staying away from questionable Web sites, users should now update their security tools everyday. And they shouldn't trust the little closed SSL locks anymore. NetCraft researchers found forged SSL certificates in 450 separate phish sites last year. Users need to also be wary of any solicitations, not just from eBay and financial services. Last year, phishers forged brands from the the Internet Crime Complaint Centre, numerous security vendors and several authoritative, nonfinancial companies.
Enforcement: Microsoft, spearheading Digital PhishNet, took down 4744 phishing sites in 2005 and filed 117 lawsuits against phishers. In February, Microsoft announced the Global Phishing Enforcement Initiative, which will coordinate efforts in monitoring for domain offences, phish takedowns, partnerships with law enforcement and worldwide investigations. In March, Castlecops and Sunbelt Software announced the Phishing Incident Reporting and Termination Squad to focus solely on terminating phish sites.
Identity services: Some organizations are taking the unusual step of buying proactive identity-protection services for their employees, says Todd Davis, CEO of LifeLock. "Fifty-one percent of identity theft occurs in the workplace. It takes an employee on average 177 hours to reclaim an identity," Davis says. "For $70 per year per employee, businesses realize this is a good investment to keep their employees productive."
Spam: Service providers have made improvements at filtering spam and authenticating e-mail through adoption of the Sender Policy Framework and Sender ID. Symantec reported a 13 percent reduction in spam mail last year, from 63 percent of all traffic in 2004 to 50 percent in 2005.
Toolbars: Microsoft announced Phishing Filter and SmartScreen e-mail scanner and browser toolbar that scan URLs against blacklists in Microsoft browsers and e-mail services and programs. They also look for basic indicators of a phish, such as addresses that don't resolve correctly.
- 1
- 2
- 3
- 4
- < previous
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Delivering the Power of Choice with Microsoft Dynamics CRM
Email Archiving Implementation: Five Costly Mistakes to Avoid
Discover the advantages of an open architecture multi-vendor network solution
Email Archiving 101—Customer Case Study
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Data grids and service-oriented architecture
CRM your salespeople will love
Making the Business Case for IT Consolidation
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure: Growth In Internet Crime Calls For Growth In Punishment 2008-12-05 13:00:00+11
International researchers gather in Sydney to preview the clever web 2008-12-05 09:48:00+11
Borderless corporate networks to shift focus to secure content management in Australia in 2009 2008-12-04 16:06:00+11
IDC Says Asia/Pacific Excluding Japan IT Market Will Remain The Bright Spot... 2008-12-04 15:04:00+11
MySpot SOS "Panic Button" Smartphone Application could save lone worker lives 2008-12-04 13:34:00+11
Taking On Demand CRM Integration to the Next Level
Discover the current integration challenges facing businesses attempting to deploy on demand CRM systems. Learn how to create comprehensive integration of your data, user interface and business process levels and transform a portfolio of disparate applications into a unified, virtual application suite.












