Ichthyological anatomy, or a study of phish

Michael Morgan IBM CERT A/NZ

  Technical stream: Thursday 12 October 2006, 15:40 - 16:20.

  download slides (PDF)

This paper describes the progression of techniques at financial fraud using social engineering and other methods to obtain financial credentials, and proceeds to cover options available to financial institutions to defend themselves and their clients from exploitation of stolen credentials.

The examples are based on actual phishing expeditions against international banks and the steps taken in investigating and responding to these attacks, including the problems of obtaining a 'get out of jail free' card in such circumstances, and the embarrassment this might present.

The attacks reported range from emails inviting prospective victims to visit a fake website, emails incorporating logon processes within themselves, hijacking web-browsing activity, to keyloggers targeting specific financial institutions.

We conclude with some speculation on future vectors and possible steps to prevent widespread use of these vectors. These steps cover public education, supplementary authentication factors, behavioural analysis, and denial of services to potential perpetrators.


Poll

Should AV software check search engine results for malicious sites even before the user clicks on them?
Yes
No
I don't know

Leave a comment
View 8 comments

Jobs Recruit Sidebar

VB100 certification

VB100 John Hawes dusts off his Linux skills for a comparative review of anti-malware products on the Ubuntu Server platform.
See full results.

Virus Bulletin currently has 129,047 registered users.