Home > Security Tips > Threat Monitor
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

THREAT MONITOR

Countermeasures against targeted attacks in the enterprise


Markus Jakobsson, Contributor
06.12.2008
Rating: -4.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


SearchSecurity.com Security School
This lesson is part of SearchSecurity.com's Intrusion Defense Security School lesson, Anatomy of an attack featuring Markus Jakobsson. For additional resources visit our lesson home page, or to browse more Security School lessons, visit our Security School Course Catalog.

In the early days of computing, viruses commonly hopped from one machine to another via floppy disk. Few machines had proper antivirus protection, and even fewer users cared about security as malware was largely benign and had limited network and application resources at their disposal.

Now we are entering a new age when not only is malware prevalent and dangerous, but human actions also matter more than any myriad of security technologies an organization may have in place. This confluence has spawned a flood of targeted attacks that look to exploit human mistakes. At the core of many of these attacks, we find social engineering. Social engineering attacks prey on human vulnerabilities, and are fueled by the availability of data about potential victims.

For more information

Passwords, Social Security numbers and sensitive business information can be uncovered with a simple search. Learn how.

A reader asks our expert panel, "Should social engineering tests be included in penetration testing?"

Get the latest social engineering news and expert advice.
This tip will explore some of the most prevalent and dangerous varieties of targeted attacks victimizing enterprise users today, and how security organizations can defend against them.

The effectiveness of social data mining
A key piece of the puzzle in preventing targeted attacks is to make data mining difficult. Also known as buddy mining, this is when attackers seek to learn who knows who, and how. If attackers have an understanding of the trusted relationships within an organization, they can exploit that knowledge to plant malware and acquire sensitive data.

For instance, if an attacker learns that two employees with an organization, Joe and Lucy, are friends, he or she might send Joe an email purporting to be from Lucy. The text of the message might say, "Joe, take a look at this funny slideshow I put together. Later! Lucy." If the attacker can persuade Joe to open the email amid the guise of his trusted relationship with Lucy, it gives the attacker power over that user to spread malware virtually at will.

Similarly, consider a malicious email to all employees appearing to come from the system admin, saying "We are under attack by viruses, and I am working on updating our firewalls. To help me protect the system, please install the attached virus shield on your machines right away. Thanks! Bob". Such a message seeks to exploit the trusted relationship between employees and IT staffs.
How can an attacker obtain the organizational charts of a company he or she wishes to target? There are many ways. For example, consider the simple Google query: "at site:linkedin.com"

This will return a list of public LinkedIn profiles to be returned, and each result will specify the name of the person working in the specified company, his or her position, and maybe even a list of his or her closest colleagues. An attacker who knows the email address formatting conventions within a company would automatically know the email addresses of many potential victims. But knowing the names of employees may let him find personal email addresses for target individuals, too, in order to reach victims outside the protective shields of their companies. This can be achieved by looking for other instances of name and other identifying information; after all, given only name, gender and zip code, 90% of Americans are uniquely identifiable.

Defending against social data mining
How can enterprises defend against social data mining? To aim at the root of the problem, one can protect the names of employees on corporate websites, and discourage employees from maintaining public profiles on social networks (whether for work or for fun). That makes it harder for an attacker to design and initiate an attack. Companies can also scan computers that are brought inside the corporate firewall; this protects against device infections that occur in employees' homes and in public places beyond the network perimeter.

There are secondary lines of defense to consider, too. For one, better spam filtering makes it harder to reach the potential victims, and good antivirus protection from an established vendor that provides regular, reliable updates will effectively block many dangerous attachments.

But we must recognize that since social engineering takes advantage of human vulnerabilities, and not technical weaknesses, that also means that education must be a part of the defense system, just like technical countermeasures are. If users are at least vaguely familiar with the common techniques used by fraudsters, they are likely to be less susceptible to such attacks. And providing users with an understanding of how much personal information is commonly accessible to just about anybody may humble them, making them less likely to believe that every correctly addressed email is legitimate.

The worst thing an enterprise can do is to think: "Why us? We do not stick out, why would anybody target our employees?" Almost nobody thinks they will have a traffic accident, but still, people do. Sometimes, a spoonful of paranoia is a good first step.

About the author:
Dr. Markus Jakobsson is a Principal Scientist at Palo Alto Research Center. He is a founder of the security startup RavenWhite, which addresses security problems associated with authentication, malware and click-fraud. He is also one of the founders of SecurityCartoon, an educational approach targeting typical Internet users.

Previously, he has held positions as Associate Professor at Indiana University, Adjunct Associate Professor at New York University, Principal Research Scientist at RSA Security, and was a member of the Technical Staff at Bell Labs. He is a visiting research fellow of the Anti-Phishing Working Group (APWG), and is a consultant to the financial sector.

Dr. Jakobsson teaches on phishing and counter-measures, click-fraud, the human factor in security, cryptography, network security and protocol design. He is an editor of "Phishing and Countermeasures" (Wiley, 2006) and co-author of "Crimeware: Understanding New Attacks and Defenses" (Symantec Press, 2008). He received his PhD in computer science from University of California at San Diego in 1997.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Threat Monitor
Debian: A niche OS with a not-so-niche security flaw
Web advertising exploits: Protecting Web browsers and servers
Ransomware: How to deal with advanced encryption algorithms
Hidden endpoints: Mitigating the threat of non-traditional network devices
Protecting exposed servers from Google hacks (and Google 'dorks')
Windows registry forensics guide: Investigating hacker activities
More built-in Windows commands for system analysis
Tracing malware's steps with RE:Trace
Worst practices: Learning from bad security tips
Worst practices: Encryption conniptions

Social Engineering
Quiz: Anatomy of an attack
Stolen data ending up in Google cache, say researchers
Information security book excerpts and reviews
Should social engineering tests be included in penetration testing?
What kind of data is compromised during a Google hack?
How Russia became a malware hornet's nest
Are senior level executives a target for social engineering attacks?
How does a mail server respond to fake email addresses?
RSA Conference: Children must learn about cyber risks
Social engineering

Enterprise Data Protection
How to avoid DLP implementation pitfalls
Quiz: Data loss prevention
PCI DSS 1.2 clarifies wireless, antivirus use
Sophos to acquire mobile data protection company Utimaco
Should users have a removable boot drive for online banking?
Unified communications trigger data leakage dangers, survey finds
NitroSecurity covers its bases with RippleTech deal
Easing e-discovery preparation by mapping enterprise data
Quiz:: E-discovery and security in the enterprise
Growing Mac use prompts call for better security

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
dumpster diving  (SearchSecurity.com)
pretexting  (SearchCIO.com)
shoulder surfing  (SearchSecurity.com)
social engineering  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts