Home > Security Tips > Threat Monitor > How to protect your company against cybercrime
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

THREAT MONITOR

How to protect your company against cybercrime


Ed Skoudis
05.02.2006
Rating: -4.60- (out of 5)


Threat Monitor
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Listen to the podcast

Listen to this tip on your PC or download to your favorite mobile device.

Organized cybercrime is alive and well. Criminals are invading cyberspace, utilizing its anonymity, widespread reach and disjointed law enforcement status to further their illicit moneymaking schemes. Security practitioners need to be aware of this activity and understand what they need to defend against.

The motive

For cybercriminals, it all comes down to the bottom line. Attackers threaten organizations with denial-of-service floods unless the companies fork over $20,000 to $50,000. Such extortion attempts, once focused on offshore gambling and porn sites, have recently moved up-scale, targeting small- and medium-sized e-commerce sites, including cash-rich financial services companies associated with investments and credit card processing. Flooding such sites hits the bottom line dramatically and quickly, making them a tempting target for attackers.

Other cybercrime attacks focus on stealing sensitive information from employee and consumer computers, including account numbers, credit card numbers and passwords for critical applications. With this sensitive information, attackers can assume the identity of consumers, fraudulently purchase high-ticket consumer electronic devices and ship them overseas for resale at a handsome profit. Using the cash available from these attacks, bad guys have created an organized cybercrime industry, channeling some of their ill-gotten gain back into research and development to create more powerful malware for more insidious attacks.

Ask the Expert: Ed Skoudis

Submit your questions about this tip or other information security threats to Ed Skoudis, author of Counterhack Reloaded and Malware: Fighting Malicious Code.

The technique

Many of these criminal schemes, especially denial-of-service extortion and the pillaging of personal financial information for credit card fraud, involve bots, semi-autonomous agents surreptitiously installed on victims' computers for remote control en masse. Groups of bot-controlled machines under the command of a single attacker are called botnets. With a botnet of ten-thousand to one-million controlled systems, an attacker can benefit from huge economies of scale. In a flood, a botnet can let an attacker generate Gigabits per second of traffic, gumming up even the hardiest of Internet sites. Using keystroke logging and screen scraping functionality on a botnet of thousands of machines, an attacker can pillage sensitive information from consumers and employees alike.

Your defense

To prevent your organization from becoming a victim of a botnet-generated denial-of-service attack, keep your ISP's emergency contact number on hand. Don't rely on the regular phone number for billing or the abuse e-mail address for critical emergencies like a packet flood. You need a hotline number that you can call for instant help if a flood ensues.

Going further, some ISPs have deployed automated sensor networks to detect and instantly throttle the traffic patterns associated with denial-of-service floods. Several vendors, including Arbor Networks, Mazu Networks and Cisco Systems, are marketing such flood-control technologies. Ask your ISP what kind of technologies they are using to detect and thwart such floods. If they don't answer, suggest that they investigate such technologies to help protect their most important customer, you.

Next, help prevent bots from being installed on your organization's computers. An organization failing to exercise due diligence in securing its computers could be held legally liable for identity theft attacks against its employees. To lower the chance of bot infiltration, thoroughly deploy antivirus and antispyware tools, and keep them updated on a daily basis. Antivirus tools typically have rudimentary antispyware capabilities, but this functionality pales in comparison with a full-blown antispyware tool. Thus, make sure you maximize your advantage by deploying both technologies. And, given that attackers have a chance to make more money the longer that a bot is installed, the bad guys release frequent updates of their bot code, necessitating daily updates to antivirus and antispyware signatures.

Furthermore, many bots are successfully deployed because of unpatched system vulnerabilities, especially client-side vulnerabilities in browsers. Make sure you rapidly test and apply the latest patches in your environment. When new vulnerabilities are discovered, for which there is not yet a patch, consider the work arounds offered by vendors.

About the author
Ed Skoudis is a founder and senior security consultant with Intelguardians, a Washington, DC-based information security consulting firm. His expertise includes hacker attacks and defenses, the information security industry and computer privacy issues. In addition to
Counter Hack Reloaded, Ed is also the author of Malware: Fighting Malicious Code. He was also awarded 2004, 2005 and 2006 Microsoft MVP awards for Windows Server Security, and is an alumnus of the Honeynet Project. As an expert on SearchSecurity, Ed answers your questions relating to threats.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Threat Monitor
Windows registry forensics: Investigating system-wide settings
Weaponizing Kaminsky's DNS discovery
Debian: A niche OS with a not-so-niche security flaw
Web advertising exploits: Protecting Web browsers and servers
Ransomware: How to deal with advanced encryption algorithms
Hidden endpoints: Mitigating the threat of non-traditional network devices
Protecting exposed servers from Google hacks (and Google 'dorks')
Countermeasures against targeted attacks in the enterprise
Windows registry forensics guide: Investigating hacker activities
More built-in Windows commands for system analysis

Organized Cybercrime
Anti-cybercrime legislation sent to president
Web security threats gaining attention at many companies
EV SSL certificates won't stop phishers, researchers say
Stolen data ending up in Google cache, say researchers
Built-in Windows commands to determine if a system has been hacked
Exploit research: Keeping tabs on the hacker underground
What security measures can be taken to stop crimeware kits?
Enterprise security in 2008: Malware trends suggest new twists on old tricks
Hijacked DNS servers could allow an Internet assault
Proposed legislation would strengthen cybercrime laws

Enterprise Data Protection
Oracle DBAs cite lack of security measures
IBM offers hardware-based encryption for x servers
Crypto landmark Bletchley Park in danger of closing
Product Review: Workshare Protect Premium 6.0
How to avoid DLP implementation pitfalls
Quiz: Data loss prevention
PCI DSS 1.2 clarifies wireless, antivirus use
Sophos to acquire mobile data protection company Utimaco
Should users have a removable boot drive for online banking?
Unified communications trigger data leakage dangers, survey finds

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
black hat  (SearchSecurity.com)
cracker  (SearchSecurity.com)
cyberextortion  (SearchSecurity.com)
cyberterrorism  (SearchSecurity.com)
Echelon  (SearchSecurity.com)
man in the middle attack  (SearchSecurity.com)
van Eck phreaking  (SearchSecurity.com)
zero-day exploit  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts