Hacker Economics 2: The Conspiracy of Apathy

Second in a series. Why banks and law enforcement thus far have failed to stymie the onslaught of malware and identity theft.

PAGE 3

April: The iFrame Problem
In early April, the Spring Edition 76service server in Hong Kong was taken down. Filters added the new Gozi variant to their lists of detected malware. On the run again, 76 and Exoric would fold up their tent and modify Gozi to be undetectable again while they found a new place to set up shop. And when they did, the steps would start again, the two sides entwined in an endless, uneasy foxtrot.

Jackson continued to help where he could but much of this was out of his hands. He had since immersed himself in another facet of 76service—its distribution mechanism.

No matter how inspired the idea of a subscription to infected machines was, or how cleverly engineered the bot that infected those machines was, 76’s and Exoric’s success with 76service, surprisingly, relied on something they didn’t develop themselves, but rather contracted out: distribution, for which they used iFrames, a browser feature that allows Web sites to deliver content from a remote Web site within a frame on a page. Think of stock quotes origination from one site streamed into a small box on another site. (For more about iFrames, see Death by iFrame.) 76 and Exoric used iFrames to infect computers – but in April they had contracted this part of the work out to another service, iFramebiz.com.

Jackson found a partial list of sites hosting the iFrames used exclusively for Gozi. Jackson sampled 5,848 pages, only a portion of the infected pages on his partial list (meaning 76 and Exoric probably paid tens of thousands of dollars for iFrame infections). Some of the iFramed sites on his list were offline. Some had been cleaned up. But 2,079 of them, more than a third of the sample, still had the code online, ready to deliver new, undetectable versions of Gozi as soon as they were ready. A month later, when Jackson took attendance again, 98 percent of the 2,079 were still hosting the iFrame.

Even if Gozi was gone for good, the iFramers would be happy to resell access to these iFrames to the next malware developer.

Transferred Risk
As much as the HangUp Team has relied on distributed pain for its success, financial institutions have relied on transferred risk to keep the Internet crime problem from becoming a consumer cause and damaging their businesses. So far, it has been cheaper to follow regulations enough to pass audits and then pay for the fraud rather than implement more serious security. “If you look at the volume of loss versus revenue, it’s not horribly bad yet,” says Chris Hoff, with a nod to the criminal hacker’s strategy of distributed pain. “The banks say, ‘Regulations say I need to do these seven things, so I do them and let’s hope the technology to defend against this catches up.’”

“John” the security executive at the bank, one of the only security professionals from financial services who agreed to speak for this story, says “If you audited a financial institution, you wouldn’t find many out of compliance. From a legal perspective, banks can spin that around and say there’s nothing else we could do.”

The banks know how much data Lance James at Secure Science is monitoring; some of them are his clients. The researcher with expertise on the HangUp Team calls consumers’ ability to transfer funds online “the dumbest thing I’ve ever seen. You can’t walk into the branch of a bank with a mask on and no ID and make a transfer. So why is it okay online?”

And yet banks push online banking to customers with one hand while the other hand pushes problems like Gozi away, into acceptable loss budgets and insurance—transferred risk.

As long as consumers don’t raise a fuss, and thus far they haven’t in any meaningful way, the banks have little to fear from their strategies.

But perhaps the only reason consumers don’t raise a fuss is because the banks have both overstated the safety and security of online banking and downplayed negative events around it, like the existence of Gozi and 76service.

So did the banks create a false sense of security or did consumers drive them to not address it through their apathy? The banks themselves might argue that they are acting responsibly. It’s hard to tell since most decline to talk about the problem. Bill Nelson is president of the Financial Services Information Sharing and Analysis Center, or FS-ISAC, a group for bank security executives where they can safely share intelligence and other information. Membership in the FS-ISAC has increased from 68 in 2004 to 2,200 this year. “That’s not a lack of interest,” says Nelson.

Nelson was the closest person to bank security executives who would speak on the record. He bristled at the notion that banks are carelessly pushing services they can’t secure. “It’s being misinterpreted that banks don’t care about security. They spend millions of dollars on this. These are good, quality people,” Nelson says.

If anything, say Nelson and others, blaming banks is precisely backwards. If you want to point fingers look at their customers, who’ve created the demand for the product in the first place. “It’s kind of ridiculous to think you wouldn’t, as a bank, use the Internet as a transport,” notes Hoff. “If you’re not offering some form of online banking, you’re going to wither away and go out of business.”

Eric Johnson, an economist at Dartmouth who recently published a study on malware on peer-to-peer networks says, “Customers are the banks’ worst enemies here. Customers are exposing lots of material that creates an environment for identity theft.”

Indeed, many malware problems are intimately connected to insecure PCs and finicky consumers who, even if they say otherwise, value convenience over security. As one CISO at a bank put it—anonymously, of course, “Users are pretty dumb.”

Next: Hacker Economics 3: MPACK and the Next Wave of Malware recounts the demise of 76service and the emergence of more powerful form-grabbing technology.

security

Loading...
Security MarketSpace
Practical Approaches for Securing Web Applications
Enterprises understand the importance of securing web applications to protect critical corporate and customer data. What many don't understand, is how to implement a robust process for integrating security and risk management throughout the web application software development lifecycle. Learn more »
An Executive's Guide to Web Application Security
Since so many Web sites contain vulnerabilities, hackers can leverage a relatively simple exploit to gain access to a wealth of sensitive information, such as credit card data, social security numbers and health records. It's more important than ever to examine your Web application security, assess your vulnerability and take action to protect your business. Learn more »
Web Application Vulnerabilities
Security managers may work for midsize or large organizations; they may operate from anywhere on the globe. But inevitably, they share a common goal: to better manage the risks associated with their business infrastructure. Increasingly, Web application security plays a significant role in achieving that goal. Learn more »
Retooling IT for a Mobile Workforce
Check out this research note from IDC for guidance. Learn more »
Today's Risky Data Environment
This paper explains how an IT and security service provider can provide a practical, manageable and reliable solution. Learn more »
Business Continuity - Are You Always Open for Business?
This Oracle business brief explains how mid-sized can improve performance by creating an IT infrastructure that makes working faster, easier and more effective. Learn more »
 
SPONSORED LINKS
 

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

White Paper: Managed Security for a Not-So-Secure World

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

White Paper: A Security Blueprint Delivered From within the Network

Return on Information: Google Enterprise Search pays you back

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths

White Paper: Improve Agility with Operational Responsiveness

White Paper: Legacy Tools: Not Built for the Helpdesk

Taking a Seat at the Executive Table: The Reality of Virtualization

White Paper: Next Generation Remote Infrastructure Management

Seven Design Requirements for Web 2.0 Threat Protection

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Lower IT Costs with Oracle Database 11g Release 2

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

Top Five CIO Challenges

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Mobile Security: The Essential Ingredient for Today's Enterprise

IDC White Paper: CCM for IT Compliance and Risk Management

Keeping Your Members Safe from Online Scams and Predators

Learn about the growing threat of insider data theft.

Upgrading to VMware vSphere with vWire

Maximizing website Return on Information with high-quality search

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: 5 Best Practices for Smartphone Support

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Streamline IT Costs. Boost Performance with WAN Optimization.

 
 
RESOURCE CENTER