Home > Security Tips > Threat Monitor > How to protect your company against cybercrime
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

How to protect your company against cybercrime


Ed Skoudis
Rating: -4.60- (out of 5)

Organized cybercrime is alive and well. Criminals are invading cyberspace, utilizing its anonymity, widespread reach and disjointed law enforcement status to further their illicit moneymaking schemes. Security practitioners need to be aware of this activity and understand what they need to defend against.

The motive

For cybercriminals, it all comes down to the bottom line. Attackers threaten organizations with denial-of-service floods unless the companies fork over $20,000 to $50,000. Such extortion attempts, once focused on offshore gambling and porn sites, have recently moved up-scale, targeting small- and medium-sized e-commerce sites, including cash-rich financial services companies associated with investments and credit card processing. Flooding such sites hits the bottom line dramatically and quickly, making them a tempting target for attackers.

Other cybercrim...


BROWSE BY TAG
Threat Monitor,   Enterprise Data Protection,   Enterprise Data Governance,   Hacker Tools and Techniques: Underground Sites and Hacking Groups,   Information Security Threats,   VIEW ALL TAGS

RELATED CONTENT
Threat Monitor
Server Message Block Version 2 security in question: Disable or patch?
Preparing for future security threats, evolving malware
Best practices for (small) botnets
Cut down on calls to help desk with cybersecurity awareness training
How to detect software tampering
How to prevent phishing attacks with social engineering tests
An enterprise strategy for Web application security threats
How SSL-encrypted Web connections are intercepted
How a corporate Twitter policy can combat social network threats
Cyberwarfare and the enterprise: Is the threat real?

Enterprise Data Governance
How to protect distributed information flows
Interpreting 'risk' in the Massachusetts data protection law
Creating an enterprise data protection framework
Analyst DLP study finds maturity, ranks top DLP vendors
Voltage, RSA spar over tokenization, data protection
Twitter gets condemned by CISOs at Forrester forum
PCI DSS compliance requirements: Ensuring data integrity
Trustwave acquires data loss prevention vendor Vericept
Data has become too distributed to secure, Forrester says
Cloud-based security services should start private

Hacker Tools and Techniques: Underground Sites and Hacking Groups
Chinese hacker says most are not skilled coders
Security researchers continue hunt for Conficker authors
Verizon report goes deep inside data breach investigations
Russian cybercriminals target H1N1 Swine Flu fears
Metasploit Project acquisition ups ante for penetration testing market
Successful rogue antivirus hinges on social engineering
DEFCON survey suggests hacker community on vacation
DoD urges less network anonymity, more PKI use
New hacker skills optimize revenue
Maturing cybercriminal economy buoyed by business savvy hackers

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cut-and-paste attack  (SearchSecurity.com)
data masking  (SearchSecurity.com)
data splitting  (SearchSecurity.com)
deperimeterization  (SearchSecurity.com)
Google hacking  (SearchSecurity.com)
masquerade  (SearchSecurity.com)
snooping  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


e attacks focus on stealing sensitive information from employee and consumer computers, including account numbers, credit card numbers and passwords for critical applications. With this sensitive information, attackers can assume the identity of consumers, fraudulently purchase high-ticket consumer electronic devices and ship them overseas for resale at a handsome profit. Using the cash available from these attacks, bad guys have created an organized cybercrime industry, channeling some of their ill-gotten gain back into research and development to create more powerful malware for more insidious attacks.

The technique

Many of these criminal schemes, especially denial-of-service extortion and the pillaging of personal financial information for credit card fraud, involve bots, semi-autonomous agents surreptitiously installed on victims' computers for remote control en masse. Groups of bot-controlled machines under the command of a single attacker are called botnets. With a botnet of ten-thousand to one-million controlled systems, an attacker can benefit from huge economies of scale. In a flood, a botnet can let an attacker generate Gigabits per second of traffic, gumming up even the hardiest of Internet sites. Using keystroke logging and screen scraping functionality on a botnet of thousands of machines, an attacker can pillage sensitive information from consumers and employees alike.

Your defense

To prevent your organization from becoming a victim of a botnet-generated denial-of-service attack, keep your ISP's emergency contact number on hand. Don't rely on the regular phone number for billing or the abuse e-mail address for critical emergencies like a packet flood. You need a hotline number that you can call for instant help if a flood ensues.

Going further, some ISPs have deployed automated sensor networks to detect and instantly throttle the traffic patterns associated with denial-of-service floods. Several vendors, including Arbor Networks, Mazu Networks and Cisco Systems, are marketing such flood-control technologies. Ask your ISP what kind of technologies they are using to detect and thwart such floods. If they don't answer, suggest that they investigate such technologies to help protect their most important customer, you.

Next, help prevent bots from being installed on your organization's computers. An organization failing to exercise due diligence in securing its computers could be held legally liable for identity theft attacks against its employees. To lower the chance of bot infiltration, thoroughly deploy antivirus and antispyware tools, and keep them updated on a daily basis. Antivirus tools typically have rudimentary antispyware capabilities, but this functionality pales in comparison with a full-blown antispyware tool. Thus, make sure you maximize your advantage by deploying both technologies. And, given that attackers have a chance to make more money the longer that a bot is installed, the bad guys release frequent updates of their bot code, necessitating daily updates to antivirus and antispyware signatures.

Furthermore, many bots are successfully deployed because of unpatched system vulnerabilities, especially client-side vulnerabilities in browsers. Make sure you rapidly test and apply the latest patches in your environment. When new vulnerabilities are discovered, for which there is not yet a patch, consider the work arounds offered by vendors.

About the author
Ed Skoudis is a founder and senior security consultant with Intelguardians, a Washington, DC-based information security consulting firm. His expertise includes hacker attacks and defenses, the information security industry and computer privacy issues. In addition to Counter Hack Reloaded, Ed is also the author of Malware: Fighting Malicious Code. He was also awarded 2004, 2005 and 2006 Microsoft MVP awards for Windows Server Security, and is an alumnus of the Honeynet Project. As an expert on SearchSecurity, Ed answers your questions relating to threats.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts