26
Identity Theft Rob Forsyth Managing Director, Sophos, Asia Pacific

Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Identity Theft

Rob Forsyth

Managing Director, Sophos, Asia Pacific

Page 2: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

“On the Internet, nobody knows you’re a dog”

5th July 1993

The New Yorker

Page 3: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Overview – Identity Theft

• Some background

• Has legislation helped?

• Examples of attacks and the implications for an individual or company

• What vulnerabilities can be created and what impact can these have?

• What defences can be deployed to defeat this form of attack?

• Where will this problem go next?

Page 4: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

History

• Identity theft as a specific IT term first appeared in the 1990s

• This lead to the US Identity Theft and Assumption Deterrence Act 1998

• Now it can occur much more anonymously than ever before

• Now the attack can be made from a greater distance

• It can build over time rather than just be a one off attack

• It can have a greater impact then ever before

ID theft costs Australia $5b a year**source The Australian Institute of Criminology

Page 5: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Methods - some old and some new

•Dumpster Diving

•Changing Your Address

•"Old-Fashioned" Stealing

•Installation of Trojan Horses (trojans) on to your computer

•Phishing and spear-phishing

Page 6: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Australian Legislation

• Cybercrime Act 2001

• Criminal Code Amendment (Theft, Fraud, Bribery & Related Offences) Act 2000

• Financial Transaction Reports Act 1998

• The Spam Act 2003

• State based Crimes Acts - various years

• The NSW Crimes Act 1900

• The NSW Crimes Amendment (Computer Offences) Act 2001

In common language – most legislation protects against fraud

Page 7: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

So, we are well protected by the Law, but it still happens

Please note that these following companies were innocent victims, and no adverse implied implication

Some examples, there are a number of different messages

Page 8: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

NOTM – September 2006

• National Online Talent Management agency

• IT theft may have been tied to recruitment of child porn

• Company appears to have closed

Page 9: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Coca Cola – August 2006

• Poor grammar and muddled dialogue a clue

• Campaign to recruit mules or for future spear phishing

• Very short lived campaign with ‘disposal’ email contacts

• International Brand – Hong Kong focus

• Advanced fee fraud?

• Seeking mules?

Page 10: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Microsoft - March 2007

• A banner ad was served on MSN sites and Windows Live Messenger• "SystemDoctor 2006" ran scripts that popped up a security warning

directing people to install a registry scanner that was itself malware

Defence requires web visibility to identify block the high risk links, script and malware detection to block malicious downloads and call home protection to block malware from updating and reporting its activity

Page 11: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Troy Inc. March 2007

• Complete rip-off of a legitimate site

• Offered employment

• “Just download an application”

• Attacks the vulnerable and desperate

• May not have been for identity theft

• Hundreds of these attacks each day

Page 12: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Troy Inc.

Page 13: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Three website examples

• Visa

• Westpac

• Avis

Please note that these following companies were innocent victims, and no adverse implied implication

Page 14: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

The URL is proceeded by numbers -everything after that is irrelevant

Page 15: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

The URL is misspelt - note that the keyboard can also be used by phishers

Page 16: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

The URL is HTTP and not HTTPS and no padlock.

Too much information is being sought

Page 17: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Newer or future challenges – will ID theft follow?

• Spam (defined by the Spam Act and the following would be covered)

• Spasms (spam over SMS)

• Spim (spam over instant messaging)

• Spit (spam over IP telephony)

Further reading at <www.theregister.co.uk>

•Illinois couple sued for sending 5 million

spam cell phone messages

Page 18: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Image spam

• Has moved through various file types

Real fears for the ‘newbie's’

Page 19: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

So what’s the impact if a trojan is installed?

Many of these attacks will download a trojan horse to the victims computer

Page 20: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Vulnerabilities that can be created

• Phishing - user name and password or just information

• Bank, eBay, PayPal, on-line gaming, your CV etc.

• Ransomware

• Botnet or ‘zombification’ to carry out other attacks• Security reduction for future attack

• Rogue webserver (porn server)

• Webcam control

• Infection of your employer's network

• Become a person of interest to the police

Risks are not always obvious or immediate

Page 21: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

What should we do about this?

Page 22: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

What defences can be deployed to defeat this?

• Endpoint anti-malware software• Combined protection covering viruses, worms, Trojans,

spyware, adware + unwanted applications

• Functioning endpoint firewall

• Gateway email protection

• Gateway web protection

• OS and anti-malware correctly patched

• Network Access Control (NAC)

Defense in depth

Education is much of the answer

Page 23: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Knowledge and access to information is the best defense

Sensible online behavior reinforced by a good IT / HR policy

Some final thoughts

Page 24: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Security threat report 2007 – some ‘highlights’

• Malware authors continuing to deliver more focused attacks

• Explosive growth of web-based downloaders to spy on users

• New mass-mailing worm, Stratio had over 1000 unique variants

• Most spam continuing to be relayed by poorly protected computers

Further reading at <www.sophos.com>

Page 25: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Where will this problem go next?

• More of the same issues but 'better' and faster

• They will follow the money

• Chase new vulnerabilities

• New technologies like IM and VoIP

• Mobile devices2005 2006

Page 26: Financial Services Conference 20th March 2007 RF …...Microsoft - March 2007 • A banner ad was served on MSN sites and Windows Live Messenger • "SystemDoctor 2006" ran scripts

Identity Theft

Rob Forsyth

Managing Director, Sophos, Asia Pacific