Showing posts with label General - Cybercrime patterns. Show all posts
Showing posts with label General - Cybercrime patterns. Show all posts

Friday, 7 May 2010

Patterns

"Cybercriminals target non-conventional appliances" (ZDnet.co.uk, 09 April 2010). not surprising, and among the devices: mobiles phones, USB flash drives and peripherals.

and DDOS attacks linked with extortion/blackmail notices, "Chinese DDoS attacks hit News Limited" (ZDnet.co.uk, 14 April 2010)

Security review by Symantec and other issues of web security

Symantec published its report analysing cyber-issues in 2009. Most of the attacks continue to come from the US (19%), followed by China (8%) and a new comer, Brazil (6%). The bulk of the attacks (37%) focuses on acquiring data, then it is accessing structural tools of companies (26%) and piracy (15%). Fraud represents only 2%. It confirms that the new value or currency today is data, rather than money itself as a direct target. In other words, data is worth more than currencies.
The recent story about a Twitter user confirms that data is gold. He was able, after numerous tweets to different users including to a Twitter employee, to find the ID and password of that employee and conduct himself as an Twitter administrator (JDN, 6 May 2010). He has been arrested in France in the Massif Central, after collaboration with the FBI (Obama's account was hacked).

A lot of those attacks are performed by users dowloading PDF documents and believing that their banks would send them e-mails requesting for their information (74% of phishing). It confirms that users are "culprits" as much as the perpetrators. If people were a bit more careful in what they download and read, there would be less succesful attacks. It is certainly the message of Remy Fevrier from the French Gendarmerie Nationale (the French police under the military umbrella) at the FIC or Forum International sur la Cybercriminalite held in Lille from the 31 March to 1st April 2010. He explained that some firms went bankrupt because precious data was stolent by a competitor which was then able to offer the product at a lesser price because it did not have the costs of research and development.

Coming back to the Symantec report, to control other computers, attackers continue to use keystroke softwares, uploading users' details and zombies/botnets I suppose.
Firefox and Safari are the most vulnerable browsers on the web currently. IE and Chrome being stable and quite below (50 instead of around 100).

See the summary in French on JDN "Les menaces IT n'ont pas connu la crise en 2009" (6 May 2010)

Friday, 22 January 2010

Use of social networking

The tweet was silly, but the reaction to it is no better. Everything is out of proportion on both sides. Maybe we should set a course for both on how to use Twitter and social networking?

"UK Man Arrested And Banned From Airport For Twitter Joke About Blowing Up An Airport" (TechDirt, 19 January 2010)

Privacy, piracy, copyrights and censorship

The theme of the week seems to turn around protecting privacy.

"Hacking Surpassing Human Error For Data Breaches?" (TechDirt, 19 January 2010). For the author, the answer is actually positive: hacking is a major threat, more that insiders leaking data.

In the fight against piracy, will privacy be waived? "Swedish ISP Refuses To Give Up Info; Says IPRED Violates EU Privacy Rules" (TechDirt, 18 January 2010)

"The Similarity Between ACTA And Chinese Internet Censorship" (TechDirt, 20 January 2010) in that both requires strong involvement from ISPs. I also think that both infringed on privacy. But the issue of ISPs involvement is also close to more traditional searches and seizures: "Once Again, FBI Caught Breaking The Law In Gathering Phone Call Info; But Real Issue Is Why Telcos Let Them" (TechDirt, 19 January 2010)

Obviously, all this debate supposes there is such thing as privacy about data online. Hence the issue about cloud computing and expectations of privacy. "Do You Have Any Legal Right To Privacy For Information Stored Online?" (TechDirt, 19 January 2010) THe US have actually articulated that notion of expectation of privacy, even though the answer is not satisfactory: it is not because it is online that there is no expectation of privacy. It all depends on where and what was intended to be done with the data.

France Considers 'Right To Forget' Law, Apparently Not Realizing The Internet Never Forgets (TechDirt, 8 January 2010)


Thursday, 7 January 2010

View of the blog via Wordle


I use Wordle (http://www.wordle.net/create) to copy text from the blog (minus my name and the main sources TechDirt, ZDnet.co.uk as it is irrelevant to what I wanted) in order to get an idea of which words were recurring in the last two months. The results are insteresting if we put aside the words UK and French/France.
Have a look for yourself.

Tuesday, 8 December 2009

Smartphones and malwares

Not a surprise that smartphones start to be the target of viruses and other malwares. They are powerful computers when one think of their size.

"iPhone worm could be used to create botnets" (ZDnet.co.uk, 23 November 2009)
"Un nouveau virus s'attaque à l'iPhone" (JDN. 24 November 2009)

which in turn, means good jobs for technicians and ex-hackers/malware writers "Rickroll virus author hired by iPhone app company" (ZDnet.co.uk, 27 November 2009)

Friday, 24 July 2009

Cybercrime trends and security issues

Quite obvious: "US prosecutor: Cybercrime will follow the cloud" (ZDnet.co.uk, 13 july 2009)

More surprising: "Cisco reports rise in text-message scams" (ZDnet.co.uk, 15 July 2009)

And quite welcome: France now has its Agence nationale de la sécurité des systèmes d'information, or National Agency for security of information systems, with a budget of 90 millions euros and 120 people working and potentially 250 by 2012. Its role is to detect and prevent cyberattacks on information systems (=the net)

"La cybersécurité hissée au rang de priorité nationale" (JDN, 09 July 2009)

Friday, 26 June 2009

Security and cloud computing

Academics warn recently about the dangers of cloud computing, where softwares and data are stored in online companies' servers and accessible from the internet. E.g.: mobileme for Apple, Dropbox, etc... It's strange because it is one of the reasons why I have still not used those services, although I have to admit I am tempted sometimes for the sheer ease of accessing data anywhwere as long as I have a connection.

Cloud computing et confidentialité des e-mails (Euractiv, 17 June 2009)

Tuesday, 19 May 2009

House of COmmons' control on Government's policy and EU

The House of COmmons' European Scrutiny Committee delivered its 8th report (may 2009) and analyse, in particular, the UK Government's implementation of EU policy on cyber attacks. Pages 19 to 21, after having summarised the EU policy, the Committee analyses the Government's responses and note the lack of clarity of the Minister's reply.

http://www.publications.parliament.uk/pa/cm200809/cmselect/cmeuleg/19-xvi/19-xvi.pdf

Thursday, 7 May 2009

Cyberthreats - importance of botnets or virus?

It is obviously silly to leave computers infected whatever the reasons. The regulation applied here should simply be modified. The article is however interesting for another reason: the scale of the use of internet to connect medical devices and the threat to health this can create. Apparently, nobody has quantified the risk, which is scary when one thinks of the threat to the electric grid that happened a few weeks ago. It actually made me think of Beck's argument in the Risk Society (our use of inadequate criteria to assess risks because the type and scale of risks have changed since the 19th century)
"US red tape leaves Conficker on medical devices " (ZDNet.co.uk, 5 May 2009)

The Conficker worm also reveals that the real and most dangerous threat is invisible. This is particularly stressed in the French article where it is explained that the purpose of botnets is not be noticed, to be as invisible as possible even though the damages can be enormous for the person infected or for others not related.
"Forget Conficker — focus on the real threats" (ZDnet.co.uk, 29 April 2009)
Frédéric Guy (Trend Micro)"Nous identifions 800 à 1300 nouveaux virus par heure" (JDN, 20 April 2009)
"Un botnet ciblant les ordinateurs Mac" (JDN, 17 April 2009) with the scale of the threat being minimum given the few users of Apple
"Le zapping de la sécurité (avril 2009)" (JDN, April 2009)

Wednesday, 25 March 2009

Computer misuses: hacking and the rest

The Web Hacking Incidents Database just published its 2008 report. It is worth a read. Here are a few facts:

- 19% steal information in order to sell it = profit
- 24% deface a website (i.e. change its homepage with a message)
- 5% is phishing


The attacks originate for 66% from North America, 16% from Europe, 6% Asia, which is probably a reflection of internet access and use.


and Government websites & co represent 32% of the victims. Two explanations here: Government got sensitive information (hence theft and fraud) and they represent the law (thus issue of politics or hactivism)

http://www.breach.com/resources/whitepapers/downloads/WP_WebHackingIncidents_2008.pdf
for a partial translation in French see Journal du Net (March 2009)

Wednesday, 11 March 2009

Fraud on social networks: security or education issue?

The article probably reiterates what is already known, but I found it interesting because it explains with details how the lack of security is increased by the combination of people not using their common sense and the presence of networking offered to them by Twitter, Facebook, LInkedIn which all link together rather than being compartementalised.
Maybe people do need to be educated after all on this, notably in realising the snowball effect of having details exposed and linked to different sites.

"Why scammers find rich pickings on Facebook" (ZDnet.co.uk, 3 March 2009)

For the type of spam/scam, see "Do not falling victim of social networking spam" (CCRC, 27 February 2009)

The same issue seems to exist in the financial sector, which is pretty scary given the amount of financial data at stake and what it means for fraud. The study was provided by Cabinet Deloitte; it is in French, but still more or less readable because a lot is in tables. The most interesting thing for me was the last table: human error accounts for 86% in 2008 (79% in 2007) for breaches in security. In other words, people need to start taking responsibility for maintening security and stop blaming softwares developers and the like.
"Le secteur financier jugé trop peu sensible à la sécurité IT" (JDN, Feburary 2009)

Trends in cybercrime

The French Journal of the Net (JDN) provides tables for cybercrime trends in January 2009. A few viruses were around; infected websites so that malicious codes are distributed are trendy; wi-fi protection increases but still 44% of the computers are not secured enough to go online; spam comes predominantly from the US, then China (but a huge drop: 456 compared to 1546 for the US), then Russia, the UK and South Korea.

"L'état de la menace informatique dans le monde (janvier 2009)" (JDN, March 2009)


According to the American Clic Forensics firm, fraud using clicking is on the increase for the last term of 2008, with 17% of the clicks fraudulent, and a rise to 28,2% on sites providing sponsored links such as Google Ad or Yahoo. Zombies PC are playing an important part in spreading the problem.
Recrudescence de la fraude au clic fin 2008 (JDN, 30 January 2009)

and insiders are also creating risks increasingly "Insider Security Attacks On The Rise, MS Says" (TechDirt, 19 February 2009)

Sunday, 1 February 2009

Fraud - clickjacking increase; and police training

The American firm Clic Forensics registers a sharp increase in clickjacking, fraudulent modification of HTML code underlying a weblink on a website.
"Recrudescence de la fraude au clic fin 2008" (JDN, 30 January 2009) - the article shows graphs that are self-explanatory

see also "Flaw exposes Chrome, Firefox to clickjacking " (ZDNet.co.uk, 29 January 2009)

which makes police training more than necessary "Cyber-Crime: Law Enforcement Must Keep Pace With Tech-Savvy Criminals" (Digital Communities, 28 January 2009)

Sunday, 25 January 2009

Analysis of cybercrime risks and trends

It's always difficult to assess risks and trends, but fraud remains a top 5 with new developments using the social networking sites
"La croissance des escroqueries" (JDN, 19 January 2009) (the increase in frauds)

And for the countries at risk: "Emerging markets at greater risk of cybercrime" (ZDnet.co.uk, 14 January 2009)

Child porn and teens' behaviours

Facts: teens post pictures of themselves nude or in pornography positions (at least, sexually explicit). Pennsylvania took the view of charging girls for distributing child porn, boys for receiving and thus possessing it.
"20% Of Teens Send Sexually Explicit Photos Of Themselves?" (TechDirt, 8 January 2009)
"Teens Face Child Porn Charges... For Taking Nude Photos Of Themselves" (TechDirt, 20 January 2009)

Comments.
Sociologically, to be a teenager means to be interested by sex, and that's human nature (hopefully). However, what does it say of ourselves, adults, if our own children do not see the difference between sending a picture of oneself nude/sexually explicit to people who are not even their lover? What does it say of our capacity to create relationships a bit more meaningful?
Legally, the charge seems to run counter the spirit of the law. I do not believe the prosecution can protect the "children" and it will certainly not help them if they are found guilty and appear on the sex offender register.

UK institutions victims of viruses

Hospitals first, with hopefully only a few appointments cancelled as damage.
"Downadup virus hits PCs at five Sheffield hospitals " (ZDnet.co.uk, 22 January 2009)
More serious in terms of national security, and certainly more worrying, is the MoD's system victim of viruses. "Virus causes Ministry of Defence outages " (ZDnet.co.uk, 16 January 2009)

Wednesday, 7 January 2009

Cybercrime - statistics

Don't know how they gather the numbers and the information, but the French journal Journal du Net (JDN) publishes a series of tables for November 2008, for viruses, phishing, black market of credit card data (marche noir) and the use of technics to attack on the net.
"L'état de la menace informatique dans le monde (novembre 2008)" (JDN, 7 January 2009)

Tuesday, 6 January 2009

Hacking e-mail - fraud and prosecution

Interesting facts, pretty scary also because it would not be easy to be so suspicious about the e-mail. "Negros doc warns vs. email hackers" (CCRC, 16 October 2008)

and on the importance of criminalising the simple act of hacking whatever the outcome is... "Is The Indictment Of The Palin Email Hacker Legally Correct?" (TechDirt, 15 October 2008)

Saturday, 3 January 2009

Social-networking and rise of crime

Not a surprise really as people on those sites simply do not understand that they scream to the world private information they would not allow their enemy to hold. Criminal law can help, as the case about spam illustrates, but surely education is a better tool and should be a better way to spend the taxpayer's money.
"Facebook Wins Nearly $1 Billion From Spammer Who Will Never Pay Up" (TechDirt, 25 November 2008)

"Social-networking sites concern cyber-security experts" (CCRN, 30 December 2008)