Using XML to Support Robust Information Sharing: An IODEF Automated Approach
Patrick Cain · Journal of Digital Forensic Practice · 2006
A disturbing trend on the Internet is the capture of electronic banking information and login credentials through social engineering attacks using electronic mail or instant messaging. Such “phishing” attacks use spoofing techniques, fraudulent domain names, etc., to trick consumers into believing they are dealing with a legitimate website. Although newly emerging attacks can be blocked, attackers defeat this blocking approach by slightly modifying each attack. As a result, network operators must continually add attack variations to a block list. This article describes an automated approach to updating the block lists using an XML IODEF document. Such information sharing in a structured and automatic way reduces the time delay from phishing attack to blocking efforts and provides a rapid-response forensic research tool to track attack vectors. Using an IETF-defined XML reporting format provides live data for ongoing investigations. This article introduces results of a prototyping activity and explores areas for further enhancements.