25
EVIL GENIUSES How organized cybercriminals could take over the world Hillary Lipko, 1 st -year MSPP CS 6725 – Information Security Policies and Practices 22 October 2009

Evil Geniuses: How organized cybercriminals could take over the world

Embed Size (px)

DESCRIPTION

A security-oriented overview of organized crime on the internet and their use of botnets, malware and spyware.Includes partial transcript.

Citation preview

Page 1: Evil Geniuses: How organized cybercriminals could take over the world

EVIL GENIUSESHow organized cybercriminals could take over the world

Hillary Lipko, 1st-year MSPPCS 6725 – Information Security Policies and Practices

22 October 2009

Page 2: Evil Geniuses: How organized cybercriminals could take over the world

Questions to answer

Who? What? When? Where? Why? How?

Now!

Page 3: Evil Geniuses: How organized cybercriminals could take over the world

What’s going on? Who are these guys?

The profile of the “typical” cybercriminal has changed.

The motivation behind criminal activity on the internet has changed.

Malicious hackers are getting organized and “The Mob” wants in.

Page 4: Evil Geniuses: How organized cybercriminals could take over the world

Who are the stakeholders?

Everyone.

The “bad guys”Malicious programmers/hackersOrganized crimeRogue governments

The “good guys”Typical usersSecurity professionals/law enforcement“Us”

Page 5: Evil Geniuses: How organized cybercriminals could take over the world

Who are the “organized criminals?”

Page 6: Evil Geniuses: How organized cybercriminals could take over the world

Who are the responders?

Page 7: Evil Geniuses: How organized cybercriminals could take over the world

Who are the responders?

Page 8: Evil Geniuses: How organized cybercriminals could take over the world

Who are the responders?

Page 9: Evil Geniuses: How organized cybercriminals could take over the world

A side note about hackers…

Hackers Criminals

Entrepreneurs Scam artistsSoftware developers

Computer criminals

Organized cybercrime

Page 10: Evil Geniuses: How organized cybercriminals could take over the world

Questions to answer

Who? What? When? Where? Why? How?

Now!Everyo

ne

Page 11: Evil Geniuses: How organized cybercriminals could take over the world

What are the threats?

Identity theft Fraud Trafficking Extortion Cyberterrorism

Compromised infrastructuresWarfare

Page 12: Evil Geniuses: How organized cybercriminals could take over the world

So about those bots…

Software applications that run automated tasks over the internet

Not all bots are badSpidersIRC botsChatterbotsGame bots

(a.k.a “internet bots” or “web robots”)

Page 13: Evil Geniuses: How organized cybercriminals could take over the world

What are the means?

BotnetsDDoS, access number replacementSpywareSpam, adwareClick fraud, fast flux

Discussion communitiesCommunicationMarketplace

Page 14: Evil Geniuses: How organized cybercriminals could take over the world

Questions to answer

Who? What? When? Where? Why? How?

Now!

Everyo

neRobot

takeover

Page 15: Evil Geniuses: How organized cybercriminals could take over the world

Why computer crime?

It’s quick; it’s easy. Low risk Better ROI Not location-reliant

Page 16: Evil Geniuses: How organized cybercriminals could take over the world

Why is this a problem?

It’s quick; it’s easy. Can be hard to trace Expensive to prevent inexpensive attacks Borderless by nature

Page 17: Evil Geniuses: How organized cybercriminals could take over the world

Questions to answer

Who? What? When? Where? Why? How?

Now!

Everyo

neRobot

takeover

Cheap

+effective

Page 18: Evil Geniuses: How organized cybercriminals could take over the world

So where are the bad guys hiding?

Everywhere.

Depressed economies and transitional governments

Russia, China, North Korea, Iran, etc. Dark corners of the internet

Page 19: Evil Geniuses: How organized cybercriminals could take over the world

Where do they come from?

Traditional organized crime is a business. Political unrest Poor legitimate economic opportunity Greed

Page 20: Evil Geniuses: How organized cybercriminals could take over the world

Questions to answer

Who? What? When? Where? Why? How?

Now!

Everyo

neRobot

takeover

Cheap

+effective

Everywhe

re

Page 21: Evil Geniuses: How organized cybercriminals could take over the world

How does organized cybercrime work?

Malware and botnet marketplace Financing Complacency

Page 22: Evil Geniuses: How organized cybercriminals could take over the world

How do we protect against these threats?

User vigilance Honeypots Proactive threat response

Page 23: Evil Geniuses: How organized cybercriminals could take over the world

How can we respond to incidents?

Black holes Tracing Blocking Clean & patch Escalation?

Page 24: Evil Geniuses: How organized cybercriminals could take over the world

Questions to answer

Who? What? When? Where? Why? How?

Now!

Everyo

neRobot

takeover

Cheap

+effective

Everywhe

reLOLcats

Listen to the

bunnyIf we knew, we wouldn’t

be here

Page 25: Evil Geniuses: How organized cybercriminals could take over the world

Questions?