The new face of cybercrime

Phillip Hallam-Baker, VeriSign In this issue of Industry Insider, computer scientist Phillip Hallam-Baker says the rise of the professional hacker means the IT world must unlearn old lessons.

You once could explain away Internet attacks as destruction for destruction's sake. But many of the juvenile delinquents of the 1990s have since graduated from mere vandalism to hacking for monetary gain.

One of the consequences of this change is spam. Who hasn't received dubious e-mail propositions from people purporting to be Nigerian merchants? Respond to them, and you risk joining a crowd of people who have lost huge sums in scams run by organised crime.

Most spammers do not intend to sell. All they want is to "phish" your credit card number. Messages now zip around the Internet purporting to come from trusted companies and asking you to "verify your account." The victim is taken to a Web site that looks genuine but is run by a fraud ring. Besides the direct loss from the stolen card numbers, this fraud damages confidence in Internet security.

This is the new face of cybercrime. Whereas hacker vandals once coveted bragging rights, professional hackers have profit in mind. What's more, they are considerably more determined and have better resources than vandals. A new approach is necessary, and we must unlearn some of the lessons drawn from hacker vandalism.

Conventional wisdom has it that a system is only as secure as its weakest link. Hacker vandals instead concentrated their efforts on compromising the parts of the system that were the most difficult to break. That's where the bragging rights were to be had.

But latter-day professional hackers are not too proud to attack the weakest link in the system. Why spend months beating your head against the ring of steel constructed by a top security architect working for a major bank? That method doesn't make sense, when you can find customers who will just tell you their account number and password if you ask in the right way.

E-mail provides the gap in the ring of steel. Even though practically every e-mail client is capable of sending and receiving secure e-mail, these features are rarely used. Why bother, when the hacker vandals consider e-mail forgery beneath them? Phishing fraud creates the need for secure e-mail, but we cannot simply wait for the world to agree on that point.

We must design e-mail security for everyday use by real users, not occasional use by experts. When a real letter comes from my bank, it is printed on letterhead with a prominent bank logo. We need an e-mail security solution that shows the difference between genuine and fake e-mails with equal simplicity.

The Internet Engineering Task Force's MARID working group is currently considering Sender-ID, a simple proposal for e-mail authentication. Computer security specialists have often dismissed schemes of this type, arguing that an expert user could in theory circumvent them. But a professional spammer has no use for a security vulnerability that only works for a limited time and allows a limited number of messages to be sent. Such a vulnerability is not profitable.

I would like to see reverse firewalls embedded in every cable modem and wireless access point for home users.

Another example of the different approach required is the reverse firewall. A traditional firewall is designed to stop attacks from the outside coming in; a reverse firewall stops an attack going out. This precaution reduces the value of recruiting your home computer as a member of a "botnet," a group of "zombie" machines hijacked to distribute huge amounts of fraudulent e-mail or launch denial-of-service attacks without being traced directly.

I would like to see reverse firewalls embedded in every cable modem and wireless access point for home users. Normal users have no need to send out floods of e-mail, which reverse firewalls can stop, but they do allow a normal flow of e-mail.

Part of the VeriSign Anti-Phishing Solution is a service that tracks down the sources of phishing attacks and asks the Internet service provider to shut them down. This is not the type of service that VeriSign would have considered offering five years ago.

Traditional law enforcement techniques are a poor match for hacker vandals seeking thrills. The result often feels like playing "whack a mole," the carnival game that requires the player to smack mechanical moles quickly and repetitively with a mallet.

The professional hacker rarely tires of doing the same thing until it stops making a profit, establishing an identifiable modus operandi. The tools used, the targets chosen, the zombies exploited and the language used all combine to provide a detailed profile of the perpetrator. One long-term aspiration is that by combining data from all the information sources we manage -- payment services, firewalls and DNS (domain name service) infrastructure -- we may uncover future attacks and their perpetrators before they occur.

The rise of the professional hacker is certainly a cause for concern, but it is also a challenge and an opportunity -- one that I and many other security professionals intend to rise to meet.

biography
Phillip Hallam-Baker is principal scientist at VeriSign.

Talkback

Is this guy serious? Firewalls operate on any directional flow of traffic today. I really can't believe this is getting such a large amount of coverage. He calls normal operating functionality a "reverse" firewall and people think he's come up with some revolutionary idea. I can't believe this guy is the principal scientist at verisign. This is a complete joke.

.. July 22nd, 2004
Report offensive content Reply (0) (0)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

Just remember that Google haven't broken any laws here, they're just doing what all their other multinational competitiors do; minimise t...

2 minutes ago by Pachanga on Much ado about Google's tax

ルイヴィトン バッグ : http://www.lovebagjp.com/ Louis Vuitton bags, Louis Vuitton pretension nose about,Louis Vuitton daydre...

20 minutes ago by bundLourb on Reservoir blogs: Fan fakes Tarantino diary

シャネル バッグ : http://www.bagssalejp.org/ Chanel trap,chanel shekels,gucci bags,direct purse,poor recent Louis Vuitton keep...

2 hours ago by bybrinkLync on Reservoir blogs: Fan fakes Tarantino diary

I guess but in both cases, dead body!

12 hours ago by Doubt on National Botnet Network coming: Earthwave

I think it's for the very reasons you mention in your first paragraph that there is no CBA. With the ideological differences and vested ...

12 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

Good points; but how do you establish consensus about the terms of reference of a cost-benefit analysis? What is to be included? How far ...

13 hours ago by Gwyntaglaw on NBN cost-benefit analyses are so 2011

I live in a small country town & have done since 2002. When I got to this town it had no mobile phone & no broadband. The only reason w...

13 hours ago by fibretech on Regional review highlights NBN, mobile

Hi there, just became alert to your blog through Google, and found that it is really informative. I am going to watch out for brussels. I...

13 hours ago by Uttedsips on Fujitsu Stylistic ST5011

Like most things in life, the devil is in the details. If a cost benefit analysis included a societal element, I'm certain nobody on eit...

13 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

The coalition has done nothing else but keep changing their view over the last 2 years. -first it was "there is nothing wrong with the ...

14 hours ago by djz on NBN cost-benefit analyses are so 2011

Use the force Luke... FFS

14 hours ago by Beta on Regional review highlights NBN, mobile

michael kors outlet http://www.michael-kors-discount.com/#5923

14 hours ago by michael kors bag on Best iPhone travel apps

Hey butterflyeffecs and lex, Sorry you're not fans of this piece. But you're dead right in that it is the thoughts and experience of a se...

14 hours ago by LHopewell on Android fragmentation steers Vic Health

teen cams
http://www.aloe-vera.cz handjob

14 hours ago by MyncWenry on Fusion-io ioDrive (80GB)

We have fashional replica bags designer .Replica luxury bags sale here are perfect compromise of quality and price. The replica handbags ...

14 hours ago by Machelle on Telecom NZ CEO Paul Reynolds to leave

It's not a question of whether anyone at HSU would know how to do this, but whether they would have connections with people who could. T...

14 hours ago by meski on CT, phone clone

Fred, I can tell you what the difference between FTTN and FTTH is. FTTH means we will be developing technology and services that we sell ...

15 hours ago by andye on NBN FUD: will Abbott ever learn?

You are 100% right – Abbott is a paragon of tenacity. Now if he could only try that hard to get Malcolm Turnbull's phone number, we co...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

Very interesting to hear Ben and thanks for providing some real-world examples. I suspect the NBN has actually improved things for a grea...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

Hi Geoff, my opening paragraph simply suggests that the leader of the opposition party would rightfully be turning to his communications ...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

This story has been voted 12000 times in the last 24 hours!

18 hours ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar