Filters can't stop phishing attacks: NCR

Software filters that are designed to block access to fraudulent Web sites are largely ineffective at protecting against new attacks, according to security experts.

A number of companies -- including Microsoft, McAfee and Neowin -- have developed anti-phishing filters that are designed to warn users if they attempt to access a known or potential phishing Web site. The filters are made to combat the growing problem of fake Web sites that attempt to dupe Web users into divulging personal information.

But these filters are relatively useless since many phishing Web sites go offline relatively fast, and the filters are unlikely to be updated in time to protect users, said NM Suprabhat, South Asia Pacific marketing manager for software and security at NCR.

"I think the fraudsters are operating much faster than that [filters]. Most of these [phishing] sites are there for less than a couple of hours," said Suprabhat.

According to Tariq Sharif, program manager on Microsoft's IE Security team, the phishing filter being built into the upcoming IE7 browser will attempt to recognise potential phishing sites using heuristics, and by looking up a list kept online by Microsoft -- but he admits that the system has its flaws.

"When you visit a site that uses common phishing tactics but isn't listed on the server as a known phishing site, Phishing Filter will display a strong yellow alert.... Since the Phishing Filter heuristics are based on a learning machine, there might be a case where an actual phishing site may not even be flagged as suspicious (false negatives) and some sites which are legitimate could be marked as suspicious (false positive)," Sharif wrote in a recent blog entry.

Sharif said to help fight the problem of false positives and negatives, the browser would have to be in continuous contact with Microsoft's Phishing server, which he said would "not scale very well".

"Therefore to keep the number of mistakes to its lowest and for Phishing Filter to work most effectively it contacts the Microsoft servers to determine if a Web site is phishing or not," said Sharif.

The Anti-Phishing Working Group recorded more than 14,000 phishing reports in July 2005. On average, a site remained online for about six days.

James Turner, security analyst at Frost & Sullivan Australia, compared anti-phishing technology to anti-virus technology, which is also dependent on an attack being launched before it can be defended against.

"There are some [phishing Web sites] that are going to be there for two weeks and others that will be there for a few hours. Signature-based antivirus is totally at the mercy of when [the virus] is identified to when it is inoculated against -- that is a huge issue. With the constant threat of zero day attacks, signatures can't carry us forward," said Turner.

According to NCR's Suprabhat, the problem is getting worse as phishers become better at creating more authentic [yet illegal] Web sites: "I have seen some of these phishing examples -- I think even a bank employee would get fooled. Those sites are so well made and so cleverly written. Two hours is enough... to keep [the phisher] in business."

Talkback

Filters Cant but education can minmise the threat

In my opinion over 70 % of phising attemps start with bogus email.

Education of the user can stop this.

Hovering over links or checking the properties of a link can reveal the truth and if it doen't match the text in the link it is Bogus. Most ebay scams are like this, when you hover over the link the site it links to is some nkown free site or user site on Yahoo or similar.

Anthony WebsterAnthony Webster September 29th, 2005
Report offensive content Reply

Mistake?

I'm pretty sure Neowin hasn't developed anything of the sort. Was it possibly mistaken for Norton or something?

Dave LeggDave Legg October 3rd, 2005
Report offensive content Reply

RE: Mistake?

Ssssh, dont let them find out the secret plan (you know, the one about buying out Norton).

AnonymousAnonymous October 17th, 2005
Report offensive content Reply

Muhahhaha

yeah we are famous once again! ;)

Neobound ;)Neobound ;) March 9th, 2006
Report offensive content Reply

Neowin?

Neowin is a Windows (and more) tech site, they don't develop software of any kind.

AnonymousAnonymous November 5th, 2005
Report offensive content Reply
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Australia Live

Acer RC 500 Mode Desply In the front you can see the LCD mode display for FM, Music and so on. It doen't functioning,. I t does...

4 hours ago by Wael Alhaili on Acer Aspire RC500

The New ZDnet Australia looks awesome! http://www.zdnet.com.au/ ^IBB

You mean they will do what every other medium to large company does, wow.

12 hours ago by daneelr on David Jones rethinks telco contract

No need for an alternative to outlook when outlook 2010 comes out. With the social media plug ins, outlook 2010 will make outlook the em...

12 hours ago by brucemills on Top alternatives to Microsoft Outlook

I see ZD have now rectified the displaying of the names of posters, relating to their previously anonymous posts. What a shame, it was so...

13 hours ago by RS on Check out the new ZDNet Australia

Novatel Wireless MiFi 2352 (European version) & MiFi 2372 (American version, for AT&T, Bell, etc) from the official distributor. No con...

14 hours ago by XLRNAC on Internode MiFi

Thunderbird is the best I think. If not in the eyes of others, then at least its the best for me. Even it supports Windows as well as Lin...

14 hours ago by webtechquery on Time to ditch Outlook? Eight alternatives tested

RT: @brucemills: DealsDirect serves malware http://zdnet.com.au/339301927/ via @zdnetaustralia #fb

Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbz

Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oY9f

RT @3wconsulting: Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oY9f

DealsDirect serves malware http://zdnet.com.au/339301927/ via @zdnetaustralia

Well after a few days, the ridiculous childish replies (apart from one) seem to have disappeared! Let's hope it stays that way! Also...

21 hours ago by RS on Check out the new ZDNet Australia

RT @zdnetaustralia: http://bit.ly/cg9xad NSW gives Sharepoint a tick after running a pilot across different government units

lol, anonymous...
Seems you have to disable Windows ACPI Battery service as a workaround.

22 hours ago by skyrl on Microsoft investigates Windows 7 battery issue

Good to see a twitter feed on @zdnetaustralia - even if i did suggestion it oh, 18 months ago. new site looks amazing tho.

Applied Technology Consulting solutions,

IDC Study:
http://m.zdnet.com.au/worm-warni...

Ciao everybody, this is a good interview. Professor Olle Johansson [neuroscientist] put across a scenario to think about. I...

1 day ago by Donato on Are mobile phones killing our grandchildren?

Honestly. Big whoop if background radiation increased by over nine thousand times. And the temperature analogy is stupid. For that to ma...

1 day ago by CryptWizard on Are mobile phones killing our grandchildren?

Oh in regards to building the NBN without using Telstra being expensive, how do you know this to be true? It's All hear-say, lets al...

1 day ago by ZeroNut on Telstra wants more cash for assets

@Brumby: "They have realised it will cost way more then the $45 billion they said it would cost to build without using Telstra and ha...

1 day ago by ZeroNut on Telstra wants more cash for assets

New Dell Studio 1535 battery online shop During the next few days, enjoy 37% at New Dell Studio 1535 battery 1 year warranty 30 days ...

1 day ago by petersun on Dell Studio 1535

Vasso, hello... Telstra received the PSTN and the $b's in profit that go with it, with one simple clause - THEY HAD TO ALLOW COMPETI...

1 day ago by RS on CCC: Telstra bets on change of govt

It's all very well for the Competitive Carriers Coalition to be clamoring that big bad Telstra is holding the nation to ransom, even ...

1 day ago by Vasso Massonic on CCC: Telstra bets on change of govt

The iPad kill ebooks as we know them | TalkBack on ZDNet http://bit.ly/9Mgyey

http://www.zdnet.com.au/is-it-wi...
test before release of Win7 : " is it Windows 7 ? "

Want a tablet-based device but don't want an iPad? The HP Slate might be for you - ZDNet (blog)

Allianz CIO 'lost hair' over Linux upgrade http://zdnet.com.au/339301891/

Google discovers malware hidden on DealsDirect retail website http://bit.ly/cxKV8u /via @zdnetaustralia

Only Google could leave from China #2. http://blogs.zdnet.com/BTL/?p=31...

RT @brucemills ZDNet tests show Avg Internet speed in Aust is slower than Estonia http://ow.ly/1o8vq

brucemills

Tallinn, here we come! RT @brucemills ZDNet tests show Avg Internet speed in Aust is slower than Estonia http://ow.ly/1o8vq

Excellent yarn on Austrade potentially adopting Offcie 2010, from @jackie_holt: http://bit.ly/brccfU (@zdnetaustralia)

CCC believes that Telstra is gambling on a change in government to stop the NBN Co http://bit.ly/bZ3V96

@zdnetaustralia internet speed tests show Average Internet speed in Aust is slower than Estonia http://ow.ly/1o8vq

NSW gives SharePoint tick for roll-out. http://m.zdnet.com.au/nsw-gives-...

http://bit.ly/cKvfRs ASUS MS236H review

http://bit.ly/cKvfRs ASUS MS236H review

Inside ZDNet Australia