Naming and shaming doesn't catch crims

Organisations and security researchers sick of seeing cybercriminals getting away have begun to name and shame scammers, but this may be helping rather than hindering criminals, according to Kaspersky Lab senior security researcher Stefan Tanase.

Stefan Tanase
(Credit: Michael Lee/ZDNet Australia)

Tanase, who spoke at the Kaspersky Lab Cyber Conference 2012 in Cancun, Mexico, said that cybercrime is becoming a mature industry, and that the criminals involved often have over 10 years of experience in creating malware. This maturity, he said, has led criminals to conduct their activities like corporations, reinvesting their profits in researching and developing new ways to scam people.

He pointed to the examples of Koobface, a worm that targeted the Facebook platform, and Vplay, a Romanian site that made its profits by streaming television shows that it did not own the rights to. The masterminds behind Koobface and Vplay were earning up to US$2 million and US$0.5 million per year, respectively, when they were in operation. Koobface in particular had a fully fledged accounting system to track profits, and sent daily profits via SMS to its masterminds.

Tanase said that while these groups are making money, they aren't necessarily going unnoticed by law-enforcement organisations, especially in the case of Koobface. Yet, despite knowledge of their operations, and in some cases holding specific information such as the likely physical location of scammers, Tanase said that law-enforcement organisations are often doing nothing.

"Both Western law enforcement and Russian law enforcement were aware of who these people are, who these people were ... but nothing happened," he said.

"I can only hope that these people will pay the consequences for what they did. It doesn't make us very happy to see several criminals operating out there [with] law enforcement knowing who they are."

This has led to information-security researchers, security companies and affected organisations becoming increasingly frustrated with a lack of action. This has, in some cases, forced them to take matters into their own hands.

Facebook eventually released information about Koobface's operators, which Tanase said was likely due to the company growing impatient with the damage that the offenders were doing to its business.

"For Facebook, it was [probably] a business decision. If these guys are not going to get stopped by legal processes, let's at least disclose what information we have about them, and make them stop."

But Tanase said that the approach of "naming and shaming" could jeopardise any hopes of bringing the criminals to justice.

"I'm questioning if this was actually the best choice, because I'm questioning if these guys will ever get arrested now that they are trying to hide."

He said that criminals only go to jail via trial by judge and jury, not trial by media, and that letting criminals know they are under investigation only makes it more difficult to track them.

Tanase said that the more appropriate response is greater cooperation, better laws and faster investigations.

"If an investigation takes three years, and a cybercriminal is active for one year, they will probably be able to make an exit without being caught. We need better cybercrime laws, which can allow us to better fight cybercrime — to fight faster and to be able to respond quicker — but at the same to protect the internet citizens' privacy.

"Any security researcher in the world can confirm that this can only be achieved through collaboration."

Without some sort of change, Tanase said that criminals will continue to win, as law enforcement fails to keep up.

"What we're seeing right now is cybercriminals creating and implementing real-life exit strategies, and the idea is that if they don't get caught before they quit, they will probably never get caught."

Michael Lee travelled to the Cyber Conference 2012 as a guest of Kaspersky Lab.

Talkback

Also, you run the risk of giving them just what they want - attention.

meskimeski February 9th, 2012
Report offensive content Reply (+1) (0)

The law cannot keep up with the internet already.

The intellectual property argument is "epic fail". We now have two generations that are happy to share content whether their own or someone else's. I see a prliferation of download sites that ask for your credit card for 'membership' so that you get access to unauthorized movies and TV. Yeah, guys, like I'm gonna be dumb enough to hand out my details!

Malware is the more serious issue which has plagued us from the days of floppy disks. These days with "open" architecture built into operating systems and browsers, the user can pick up malware without even realizing it. I can find out that my machine participated in a DDoS attack without my knowledge. I got rid of my Hotmail account because I was getting SPAM from myself!.

While money-moguls keep chasing the former, it is the latter which will prove to be bigger downfall.

TreknologyTreknology February 9th, 2012
Report offensive content Reply (+1) (0)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

B.S Artist ? (M.A Oxford )

8 minutes ago by Abel Adamski on NBN FUD: will Abbott ever learn?

B.S Artist ? (M.A Oxford )

8 minutes ago by Abel Adamski on NBN FUD: will Abbott ever learn?

Mobile Devices Were Wrecking My Health. Here's How I Plan to Change That. - ZDNet (blog) http://t.co/zMWCOZOr #mobiledevices

"take up of the highest plan was again higher in April, making up 50 per cent of all services activated in April"

1 hour ago by Abel Adamski on NBN users opt for 100Mbps

What has not been considered which may well be the case, is the key attribute of the FTTP. Upload capability. 82% chose an upload capacit...

1 hour ago by Abel Adamski on NBN users opt for 100Mbps

"@ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/PiR0zeF1 #infosec #hack #cybersecurity"

Cool: NZ will host part of Square Km Array http://t.co/a2mz3DC5. Sad: @smh couldn't bring themselves to acknowledge it http://t.co/l90oLuYp

Build your own smartphone stand http://t.co/I0avWsRO

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/vA11Otks

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/FqSe1Uju

SKA bid ends in three-way tie AU/NZ/ZA http://t.co/aGw6dndH < interesting outcome

RT @MADinMelbourne: roxon "will enable more families to access credit" @MLolderandwiser: Privacy Act amendments http://t.co/Mv4c7PC2 via @zdnetaustralia

Is #PR dying at the hands of #SocialMedia? Check out how #UnitedAirlines suffered a Social PR hiccup in 2008 http://t.co/OVpYX8Uv

The interface is nowhere near as clean and user friendly as the Rdio streaming service apps. It doesn't compete with Rdio which has very ...

3 hours ago by Jeff12345 on Spotify finally goes live in Australia

RT @ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/0rCoszCl #infosec #hack #cybersecurity

by http://t.co/vmlLt4bh: SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the ... http://t.co/ySDRbo3l

It's official. The SKA bid has ended in a three-way tie between Australia, South Africa and New Zealand: http://t.co/Wn1niauX ^LH

Biometric bugs too dangerous for public?
http://t.co/48XQpWiY

Aussies getting ripped off by retail: Choice http://t.co/6ZQ0wuCJ via @zdnetaustralia

Thats really interesting to find this post especially in this period of my life I'm Italian, I'm owner of a website that ships worldwide...

3 hours ago by salbini on Aussies getting ripped off by retail: Choice

Android's biggest security flaws - ZDNET - ZDNet Australia http://t.co/4j4R1x6Q

RT @Techmeme: RIP webOS: Again and for good this time (@jkendrick / ZDNet) http://t.co/RhADp6WL http://t.co/fFYGIy5R

Cybercrime golden age over in two years? http://t.co/LyqqjWYU #Cybercrime #Gescrise #Riskmanagement (via @ECCOUNCIL)

RT: ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/X0In9ijs #infosec #hack #cybersecurity

Cybercrime golden age over in two years? http://t.co/VJnt6nEo #infosec #hack #cybersecurity

NBN users opt for 100Mbps - http://t.co/C2Vs7d3t

Yes, if only he had access to FTTP instead of wishing for wireless or space optics, perhaps the comedy site would still be up and running...

4 hours ago by Beta on NBN users opt for 100Mbps

I could not resist :-)

I remember that website well, you must too, it was full of so many comedy pieces.

4 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

Bazaarvoice acquires rival PowerReviews; adds SMBs to CRM portfolio: By Andrew Nusca | May 25, 2012, 4:42am PDT ... http://t.co/WngvcsxL

MikeSkoey, what a naive collection of words. How do you know what context Paul has been working in. How do you know he implemented whats ...

5 hours ago by AnonymousCIO on 30 servers to 7: BUPA redoes virtualisation

Post 'social' improved speed to information and context http://t.co/7u9odG7N

HC, don't be so mean to Todd...

He is actually one who may not be just politically opposed ;-)

5 hours ago by Beta on NBN users opt for 100Mbps

No, Quigley is, as CEO's of all companies are, quite simply motivated for his company to be a professional and successful company, as it ...

5 hours ago by Beta on NBN users opt for 100Mbps

Forced lol. btw I tried to load your website www.nonbn.org but all I got was a "website unavailable" I really wanted to donate some mone...

5 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

http://t.co/aDIOqQ4c http://t.co/NeUOcLt5

What has the debt level got to do with what plan people chose? I'd point out that the debt wont be $50 billion but i'd be wasting my bre...

5 hours ago by mstat_z on NBN users opt for 100Mbps

Quigley is entirely politically motivated, this is headline grabbing and nothing more. The statistic should read - "of those who took up ...

6 hours ago by merarischroeder on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

"the artificial speed tiers will mean that on average speeds the country will be left well behind others and social inequality will incre...

6 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

The most insulting aspect of the ads is CommBank's expectation that we would accept a bank account with fees unless you deposit $2000/mth...

6 hours ago by gikku on Triple J's Spotify conundrum

NBN users opt for 100Mbps - Communications - News http://t.co/3A84AASP

That's right. Quigley DOES know best. So when Quigley presents a plan to the shareholders (us) and says "this is our worst case scenario...

6 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

"NBNCo predict 13% of premises passed by fibre will opt for wireless because it is cheaper." Which leaves 87% well above the 70% estimate...

6 hours ago by Beta on NBN users opt for 100Mbps

HC the critics said the NBN wouldn't make a cent (yes, yes here comes the, it's still in debt arguments - we know what you meant and so d...

6 hours ago by Beta on NBN users opt for 100Mbps

Look what you did Gwyn...LOL. Yes, but as you have been told umpteen times Mathew (whenever you sprout the same old repetitive lines abo...

7 hours ago by Beta on NBN users opt for 100Mbps

10 cool iPad apps you'll wish you found sooner | 2 of 10 http://t.co/M9SXbnJS via @zite

SA Health's journey to ehealth Business News ZDNet Australia: Implementing e-health services for an entire state... http://t.co/QuiOy7OQ

London to become Intel's city-living R&D testbed - ZDNet UK (blog): IT PROLondon to become Intel's city-living R... http://t.co/5qdivDa1

#Google #Australia Much ado about Google's tax http://t.co/DCMsJGyN

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

by http://t.co/vmlLt4bh: Build your own smartphone stand: Looking for a smartphone stand, but not interested in d... http://t.co/DptVvkoB

Build your own smartphone stand: Looking for a smartphone stand, but not interested in dishing out the dough? We... http://t.co/TgSeZIdM

last couple of hours to submit your application for #crmidol. Step up and take your chance! http://t.co/7vQxdbY3 #scrm #crm #value

The rural Silicon Valley http://t.co/vqV6bl5i

Build your own smartphone stand http://t.co/IY6VxA7n

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar