Forum for Science, Industry and Business

Sponsored by:     3M 
Search our Site:

 

Identity thieves’ "phishing" attacks could soon get a lot nastier

18.10.2004



"Phishing" e-mails appear to be sent by legitimate businesses, but are actually created and distributed by thieves who are trying to steal personal information. Photo by: David Bricker


The number of people who succumb to identity thieves’ "phishing" e-mails could go way up if immediate action isn’t taken to preempt the next generation of attacks, according to Markus Jakobsson, an Indiana University School of Informatics researcher.

A report by cybersecurity expert Jakobsson describing worst-case phishing scenarios was recently cited by Howard Schmidt, chief information security officer for eBay Inc., during his testimony before a U.S. Congressional subcommittee on government reform. The report has also been presented to members of the U.S. Government Accountability Office and the Cyber Security Industry Alliance, based in Washington, D.C.

"I came up with the worst kind of attacks I could think of and then worked on how to defend against them," said Jakobsson, who is associate director of IU’s Center for Applied Cybersecurity Research. "Phishers haven’t invented these attacks yet, but the phishing attacks that are happening now are getting more and more sophisticated."



Today’s phishing e-mails are already pretty tricky. Many spoof legitimate companies’ domain names by linking not to legitimate domain names, such as "ebay.com," but to misleading domain names, like "secure-ebay.com," which are owned by phishers. Some users, encountering fake Web sites that look real, unwittingly give away vital personal information such as social security numbers, bank account numbers, access codes, usernames and passwords. Another version of phishing takes advantage of the fact that many users configure their e-mail clients to display pictures and text formatting within the messages. This makes it possible for phishers to show users the name of a legitimate domain name within the body of their e-mails -- while linking to a differently named Web site.

Phishing messages that appear to be sent by such trusted companies as eBay, Citibank and others are currently duping 3 percent of the people who receive them, according to a recent survey by Gartner Inc. Aware of the threat, members of Congress are currently debating passage of the Internet Spyware Prevention Act, which would provide the Justice Department with $10 million to apprehend phishers and other online scam artists.

Jakobsson said preliminary data suggest that savvier, "context-aware" phishing attacks could have success rates as high as 50 percent. Context-aware attacks, as Jakobsson envisions them, would take advantage of users’ unique circumstances or personal relationships.

One kind of context-aware attack Jakobsson describes tricks eBay bidders into giving out identifying information by leading bidders to believe they’ve won an auction. He also explains how eBay sellers can be victimized by context-aware attacks in which false payments lure sellers to give out their passwords.

In another kind of context-aware attack, a potential victim might receive a message from a known person -- for example, a friend or loved one -- asking him or her to go to a Web site to update banking information. But how would a phisher know who was related to whom and how? "There are personal and business networking Web sites out there, such as orkut.com, where users’ relationships are easily seen," Jakobsson said. "A phisher can find out whether a person in your ’personal network’ list is a wife, a husband, a sister or a business associate, and take advantage of that."

In a third kind of context-aware attack, the phisher first creates a believable (but fictitious) problem with a user’s online account and then asks for a user’s personal information to fix it. By analogy, current e-mail attacks are like phone repair personnel showing up out of the blue, claiming a potential victim’s phone lines aren’t working, when the victim can easily tell they are. "But now imagine I, the attacker, actually cut your telephone lines," Jakobsson explained. "I wait for you to notice. Then I show up, claiming to be there to fix the problem. I appear legitimate and everything seems consistent, so you invite me onto your property. Whenever you get e-mails requesting personal information, no matter what the circumstances, be skeptical, even if what you’re seeing appears legitimate."

Jakobsson admitted the scenarios may instill some paranoia, but he is joined by eBay’s Schimidt and others in his assessment that such context-aware attacks are inevitable. To combat the problem, Jakobsson believes users, online businesses and government must get involved. "A number of us are recommending changes in the way eBay and others display online information," Jakobsson said. "Personal information should only be displayed publicly on Web sites if it is absolutely necessary, or if a user gives his or her specific assent, knowing the risks. Government can help by requesting or requiring these changes. And of course there must be a public awareness campaign."

The report, "Modeling and Preventing Phishing Attacks," is currently being considered for the International Financial Cryptography Association’s annual meeting in February 2005. Copies of the paper are available to journalists and scholars only upon request. The research was supported by RSA Laboratories in Bedford, Mass.

Jakobsson is part of a group at IU that develops technological counter-measures to phishing and other types of Internet fraud. Members of the group are currently working on authentication software that would protect users from unknowingly entering PINs, usernames and passwords at illegitimate Web sites.

David Bricker | EurekAlert!
Further information:
http://www.indiana.edu

More articles from Information Technology:

nachricht Efficient time synchronization of sensor networks by means of time series analysis
24.01.2017 | Alpen-Adria-Universität Klagenfurt

nachricht Ultra-precise chip-scale sensor detects unprecedentedly small changes at the nanoscale
18.01.2017 | The Hebrew University of Jerusalem

All articles from Information Technology >>>

The most recent press releases about innovation >>>

Die letzten 5 Focus-News des innovations-reports im Überblick:

Im Focus: Scientists spin artificial silk from whey protein

X-ray study throws light on key process for production

A Swedish-German team of researchers has cleared up a key process for the artificial production of silk. With the help of the intense X-rays from DESY's...

Im Focus: Quantum optical sensor for the first time tested in space – with a laser system from Berlin

For the first time ever, a cloud of ultra-cold atoms has been successfully created in space on board of a sounding rocket. The MAIUS mission demonstrates that quantum optical sensors can be operated even in harsh environments like space – a prerequi-site for finding answers to the most challenging questions of fundamental physics and an important innovation driver for everyday applications.

According to Albert Einstein's Equivalence Principle, all bodies are accelerated at the same rate by the Earth's gravity, regardless of their properties. This...

Im Focus: Traffic jam in empty space

New success for Konstanz physicists in studying the quantum vacuum

An important step towards a completely new experimental access to quantum physics has been made at University of Konstanz. The team of scientists headed by...

Im Focus: How gut bacteria can make us ill

HZI researchers decipher infection mechanisms of Yersinia and immune responses of the host

Yersiniae cause severe intestinal infections. Studies using Yersinia pseudotuberculosis as a model organism aim to elucidate the infection mechanisms of these...

Im Focus: Interfacial Superconductivity: Magnetic and superconducting order revealed simultaneously

Researchers from the University of Hamburg in Germany, in collaboration with colleagues from the University of Aarhus in Denmark, have synthesized a new superconducting material by growing a few layers of an antiferromagnetic transition-metal chalcogenide on a bismuth-based topological insulator, both being non-superconducting materials.

While superconductivity and magnetism are generally believed to be mutually exclusive, surprisingly, in this new material, superconducting correlations...

All Focus news of the innovation-report >>>

Anzeige

Anzeige

Event News

Sustainable Water use in Agriculture in Eastern Europe and Central Asia

19.01.2017 | Event News

12V, 48V, high-voltage – trends in E/E automotive architecture

10.01.2017 | Event News

2nd Conference on Non-Textual Information on 10 and 11 May 2017 in Hannover

09.01.2017 | Event News

 
Latest News

Breaking the optical bandwidth record of stable pulsed lasers

24.01.2017 | Physics and Astronomy

Choreographing the microRNA-target dance

24.01.2017 | Life Sciences

Spanish scientists create a 3-D bioprinter to print human skin

24.01.2017 | Health and Medicine

VideoLinks
B2B-VideoLinks
More VideoLinks >>>