Security 2.0: Not Just a New Kettle of Phish

Bill Orr · ABA banking journal · 2008

Just when bankers are getting a feet for the benefits of Web 2.0 now comes Security 2.0, a radical new approach to foiling malware, malicious software whose target is the nitty gritty transaction details of online banking. Much of the security software now used in banking is designed to protect users against identity theft and other frauds typically perpetrated via e-mail and generically known as phishing, like security in any arena, phishing quickly turned into an arms race between offense and defense. White e-malt messages promising financial or physical enrichment were once staples for enticing users to give out their passwords or credit card numbers, that approach is losing its potency. So the arms race escalated. Fraudsters devised cleverer come-on messages that e-mail users couldn't see through and sent them out in such profusion that fraud fighters couldn't keep up with them. The classic of this kind was Storm Worm, a spam e-mail attachment that broke out in January '07 with subject tines such as 230 dead as storm batters Europe (in a week when there actually was a deadly storm in Europe). One executive of an anti-virus firm detected tens of thousands of variants of this message. At the beginning of 2007 anti-malware vendors detected about a quarter of a million incidents worldwide. At the end of the year the number of attacks had reached half a million, as reported in IT security threat summary by F-Secure, a pioneer in next-generation anti-ma[ware services. This doubling of detected incidents means that the bad guys launched as many attacks in one year as they had in the previous 20, F-Secure reports. The sharp escalation in volume indicates that in 2007 malware authors were adapting, refining, and massively propagating variations of existing techniques rather than innovating new strategies. Here are the main differences between phishing and emerging malware: * Phishing expeditions cast wide global nets. It's as easy to host multitudes of phishing sites as it is to host one. The new banking trojans attack one or a few banks that they know are rich targets. * Phishing gets the victim to cooperate in attacking her bank's server. Banking trojans rely on stealth to steal crucial software code at the * Anti-phishing strategies first detect new viruses in action worldwide and then devise countermeasures. Strategies against banking trojans constantly probe every site for suspicious behavior and try to disable it before it strikes. F-Secure, the anti-malware vendor, has dubbed the new behavior-based strategy Man in the browser. This is a common scenario: The man (i.e. trojan) uses some ploy to create a facsimile of crucial elements of a legitimate online banking system. One way to start this chain of events is to intervene in the sign-on procedure by first rejecting the username and password and then copying the user's second response onto the imposter system. Then the trojan lies in wait in some cozy corner of the browser, doing nothing but watching for useful coding strings, such as Welcome to Citibank that identify a rich target. Once inside the banking software, it can execute a fake transaction, such as Transfer $987.00 to the Guesswho account. F-secure's behavioral counterstrategy is to monitor every action on a user's browser, looking for suspicious strings of code. …

Read the paper · More papers on PaperTik