Phishing: Trends and Countermeasures Blaine Wilson.

18
Phishing: Trends and Countermeasures Blaine Wilson

Transcript of Phishing: Trends and Countermeasures Blaine Wilson.

Page 1: Phishing: Trends and Countermeasures Blaine Wilson.

Phishing: Trends and Countermeasures

Blaine Wilson

Page 2: Phishing: Trends and Countermeasures Blaine Wilson.

Phishing

• What is Phishing• History of Phishing• Types of Phishing• Examples• What can we do

Page 3: Phishing: Trends and Countermeasures Blaine Wilson.

What is Phishing

• Phishing is the criminally fraudulent process of attempting to acquire sensitive information such as user names, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication

Page 4: Phishing: Trends and Countermeasures Blaine Wilson.

History of Phishing

• First documented in 1987• First called Phishing in 1996• Switched to financial institutions in 2001• 2005, 1.2 million impacted, $929 million• 2006, half done by Russian Business Network• 2007, 3.6 million impacted, $3.2 billion

Page 5: Phishing: Trends and Countermeasures Blaine Wilson.

Targets of Phishing

• Phishing• Spear Phishing• Whaling

Page 6: Phishing: Trends and Countermeasures Blaine Wilson.

Types of Phishing

• Link manipulation• Phone phishing

Page 7: Phishing: Trends and Countermeasures Blaine Wilson.

Link manipulation

• Tampering with the link to fool users– www.greatamercianinsurance.com– [email protected]

• Text not matching the link• Using images for links

Page 8: Phishing: Trends and Countermeasures Blaine Wilson.

Phone phishing

• Leaving a phone number instead of a website

Page 9: Phishing: Trends and Countermeasures Blaine Wilson.

Examples

Page 10: Phishing: Trends and Countermeasures Blaine Wilson.
Page 11: Phishing: Trends and Countermeasures Blaine Wilson.
Page 12: Phishing: Trends and Countermeasures Blaine Wilson.
Page 13: Phishing: Trends and Countermeasures Blaine Wilson.

What can we do

• Law enforcement• Industry• Consumers• us

Page 14: Phishing: Trends and Countermeasures Blaine Wilson.

Law enforcement

• Law– CAN-SPAM Act of 2003– Anti-Phishing Act of 2005

• Enforcement– 2004 Federal Trade Commission files charges– 2005 files 117 federal lawsuits– 2007 – first defendant of CAN-SPAM

Page 15: Phishing: Trends and Countermeasures Blaine Wilson.

Industry

• Eliminating phishing emails• Monitoring and takedown of phishing sites• Browsers alerting users to fraudulent websites

Page 16: Phishing: Trends and Countermeasures Blaine Wilson.

Users and Consumers

• Training like Anti Phishing Phil– Trains users to look at the URL– TCP/IP addresses– Misspelling

Page 17: Phishing: Trends and Countermeasures Blaine Wilson.

us

• Take training ourselves and pay attention• Don’t condition users to click on TCP/IP

addresses• Get a consistent domain and suffix• Don’t reduce the security settings of the

browser• Personalize the login process• Protect against cross site forgery requests

Page 18: Phishing: Trends and Countermeasures Blaine Wilson.

Questions?