AVG urges mandatory cybercrime reporting

Voted by

suzanne.tindalJune 22nd, 2011

Governments should require mandatory reporting of cybercrime to draw attention to the constant large-scale attacks on banking customers, according to Yuval Ben-Itzhak, the chief technology officer of security vendor AVG.

"If you're a victim [of] cybercrime, there's no law, that at least I'm aware of, that requires you to go and report about that. We hear only of a few cases, and most of them go silent, so there's a false belief everything is fine," Ben-Itzhak told ZDNet Australia.

"The reality we're seeing as security vendors, investigating, dealing with criminals on a day-to-day basis, the volume is really scary and it's continuing to grow," he said. "The sophistication of attack and the innovation we're seeing in cybercrime in the last few quarters definitely indicates the people behind it are professionals."

Ben-Itzhak points to the fact that malware is continuing to be distributed globally, and can install itself onto millions of computers automatically without causing conflicts with the user's installed software.

"We're seeing malware that can hijack your web browsing session [and] intercept the exact moment when you're visiting your online banking," Ben-Itzhak said. "You believe you are interacting with your bank. The SSL lock showing on your browser is still valid. The connection looks reliable, it's the domain of your bank, it's not a phishing site. But someone managed to inject an additional field into your screen asking you a question that is not a question by your bank, it's a question by the malware."

Criminals know to match the HTML layout, and the look and feel of the banking sites, and they're constantly updating the malware as the banks update their own look and feel. "This is not a trivial task. It requires constant updates. It requires some [quality assurance] not to break anything so someone will feel something is wrong happening here," says Ben-Itzhak.

"The amount that they're charging from your account is well-calculated to make sure it goes under the radar of the bank fraud alerting system," he said.

The "AVG Community Powered Threat Report — Q2 2011" (PDF), released yesterday, points to the increasing professionalism of these attacks. As just one example, criminals now use stolen digital certificates to create "trusted malware". AVG detected 53,834 pieces of signed malware in the first five months of 2011 comparing to 39,102 during the whole of 2010, an annualised increase of over 300 per cent. Mobile malware is also on the rise.

Mac OS X and iOS users will need to re-think their security posture, according to AVG, now that their combined market share has reached 7 per cent. "The unwritten rule in security research says the 5 per cent and 10 per cent market share levels indicate when a product/OS becomes interesting enough for certain hackers to target and when the volume of attacks is expected to soar," the report said. "The first major wave for Mac users is a rogue AV [anti-virus]; the main reason is that it is the quickest and easiest way to monetise."

Ben-Itzhak's comments echo statements made at last month's AusCERT information security conference. Amil Klein, chief technology officer at Trusteer, predicted that next-generation mobile malware is only months away, and Queensland police believed that less than 1 per cent of computer crimes are reported to police.

"It's not interesting for the media if Mr X from down the street was compromised. No-one knows about that person," Ben-Itzhak said. "But suddenly, if there are five thousand people in the city being compromised, well, that's a story that will get the headlines. And I think it's for the lawmakers to start to step forward and request reports for these cases."

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

RT @pepperminttech: CASE STUDY: using #msdyncrm to cope with growing number of client comms http://t.co/TECEVm6H #personalinjury #legaluk...

RT @zackwhittaker: ZDNet: EMC hones focus on hybrid cloud, big data http://t.co/uOb50mgR

US, Australia team up on cybersecurity: http://t.co/OCFR5khp

Security services provider Earthwave reports 700% rise in DDoS on clients in Q1. http://t.co/LOBC8NOo

Dynamics CRM saves email-drowned utility http://t.co/S5rvxbcU

RT @MSDynamicsCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/LKjZzQcR #msdyncrm #crm2011 ^pb

Tech News: Mac OS users on security: No worries - The Mac users that ZDNet Asia spoke to regarding Flashback and oth... http://t.co/fhw6gJ0T

RT @msdynamicscrm: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/B5logcak...

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

1 hour ago by rizowski on ABC's Bitcoin miner tackled in minutes

Vic councils tender for VMware partner - ZDNet Australia: Vic councils tender for VMware partnerZDNet Australia#... http://t.co/V9rukN7Q

Cybercrime golden age over in two years?
http://t.co/qdeIhHXP #techwd #Tech_ar #reversing

US, Australia team up on #cybersecurity http://t.co/AKDgHpmB

Microsoft's So.cl network launched amid Facebook press http://t.co/MkUizROL

Students create "v'ideo parties" with MSFT new social service http://t.co/uH9ffvLa

RT @zdnetaustralia: Melbourne City Council pulls parking fine cameras. Turns out Melbournites park too close together: http://t.co/pqbJbeJy

Vic councils tender for VMware partner - ZDNet Australia http://t.co/eTTZFXVG #australia #technews

@Microsoft So.cl combines search and social media, designed to aid students networking and sharing information ZDNet http://t.co/zQW8Zecr

Google's Chrome vs. Microsoft's IE: How's that halo effect? http://t.co/xz2YGQMU

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

2 hours ago by Kevin Cobley on National Botnet Network coming: Earthwave

Windows Phone: Photography the key to its success? http://t.co/14swIy1J

National Botnet Network coming: Earthwave http://t.co/BsCUwtGW via @zdnetaustralia

Windows Phone: Photography the key to its success? http://t.co/CBVdS9f7

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

Windows Phone: Photography the key to its success?: I tend to do a bit of digital photography when I go on trips... http://t.co/lAYofzgi

CASE STUDY: using #msdyncrm to cope with growing number of client comms http://t.co/qA1SxZLO #personalinjury #legaluk #solicitors #lawyers

Windows Phone: Photography the key to its success? - ZDNet (blog): ZDNet (blog)Windows Phone: Photography the ke... http://t.co/HPArdCe0

One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/F8nJ7xK6

“@ZDNet: One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/oAE1ifmp”....a DR solution, that is for the little guys.

TechnologyOne keeps profits growing: http://t.co/A7J5uDlT

“@btviewpoint: #Cybercrime golden age over in two years? - #Security - #News - http://t.co/ZEmny2dI

“@ZDNet: Can Windows 8 tablet be priced low enough to compete with iPad, Kindle Fire? http://t.co/b7n4Wb7C” .....unlikely, and disappointing

#Cybercrime golden age over in two years? - #Security - #News - http://t.co/Mvc37WAr

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

United States, Australia team up on cybersecurity http://t.co/41IYTcDx

$50m to Medicare locals for eHealth http://t.co/VM5ts5lf

RT @adrianbritton: Goodbye Friending #Facebook: We only part to meet again http://t.co/gXZEKtEE #socialmedia

We Are Specialty Supply Miu Miu Handbags, Miu Miu Pocketbook, Miu Miu Sunglasses And So On. Miu Miu Car-boot sale Online Strapping Reduct...

5 hours ago by ExedegamEmodo on Reservoir blogs: Fan fakes Tarantino diary

6 hours ago by forporoExpoxy on Reservoir blogs: Fan fakes Tarantino diary

Goods Shopping Location Diminish Of Japan's Largest Overseas Train Brands. Coach Outlet Recover 89% Off.We Entertain Stuffed Items Such A...

6 hours ago by MentIdott on Reservoir blogs: Fan fakes Tarantino diary

Our Stow away Tender Exercise Bags Of The Cheapest Quotation, 50-75% OFF. Secured Shipping To Japan. Detailed Inferior Instructor Handbag...

6 hours ago by Hieffiftsoinc on Reservoir blogs: Fan fakes Tarantino diary

1963年ナイキの創業者フィル・ナイトが訪日、オニツカ(現アシックス)の経営陣を訪問。 最新の機...

6 hours ago by Scafthapthinc on Reservoir blogs: Fan fakes Tarantino diary

6 hours ago by antaftilk on Reservoir blogs: Fan fakes Tarantino diary

Our Aggregate Wholesale Trainer Bags Of The Cheapest Consequence, 50-75% OFF. Self-indulgent Shipping To Japan. Exquisite Worthless Drill...

6 hours ago by meltygypent on Reservoir blogs: Fan fakes Tarantino diary

Celine belongings,Celine case,purse Celine,CELINE Celine is synonymous with je sais quoi and faultlessness prevalent since founding in 19...

6 hours ago by dendyBymNTedo on Reservoir blogs: Fan fakes Tarantino diary

7 hours ago by Fedaupdat on Reservoir blogs: Fan fakes Tarantino diary

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

7 hours ago by anonymuos on Microsoft admits Vista was 'cheesy'

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

8 hours ago by brozza on Broadband Speedtest

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

10 hours ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

you really think it's going to be such a grim future? looking at South Korea, Japan, even Czech Republic - I haven't seen either emit mo...

11 hours ago by romant on National Botnet Network coming: Earthwave

No... they'll just blame the NBN for that too ;-)

12 hours ago by Beta on National Botnet Network coming: Earthwave

It seems that some of the people who set up ACCAN (not staff members) took the view that it would somehow be against their view of 'consu...

13 hours ago by socrates on ACCAN gets govt tick amid industry criticism

Don't laugh, Mr Turnbull is dumb enough to try and use this against the NBN. I'm sure the noallitions magical FTTN will be impervious to ...

13 hours ago by Jingles on National Botnet Network coming: Earthwave

OMG, the sky will fall if we get NBN - it must be cancelled immediately! Sorry; was just channelling Malcolm Turnbull there for a moment...

13 hours ago by socrates on National Botnet Network coming: Earthwave

Thats just stupid.. what else is the NBN going to get blamed for? People die crossing the road, are you going to ban cars or police it b...

13 hours ago by fibretech on National Botnet Network coming: Earthwave

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar