Welcome Guest. | Log In | Register | Membership Benefits

Taking Cybersecurity Lessons To The Bank

Lessons learned from frequent attacks make banks good role models in defending against bad guys

Nov 09, 2010 | 11:45 PM | 

By Robert Lemos, Contributing Writer

Banks are under attack -- not so much from gun-toting bank robbers, but from sophisticated cybercriminals.

Using programs such as Zeus to compromise customers' PCs and siphon money from their bank accounts, cybercriminals stole or attempted to steal nearly $100 million in the first three quarters of 2009, according to the Internet Crime Complaint Center. Traditional bank robbers on average stole $4,029, and all the U.S. bank robberies in 2009 totalled about $35 million, according to the FBI's Uniform Crime Reporting (UCR) project.

"Criminals are out there right now harming both the commercial account holders and financial institutions," Sari Stern Greene, president of Sage Data Security, told attendees last week at the Cybercrime Symposium 2010 in Portsmouth, N.H. "And every time this happens, it harms the whole community."

Banks have the money, so they are today's targets. But they aren't the only ones. Zeus and other malicious programs can easily be used to provide access to corporate PCs in other industries as well. For that reason, security managers should look to what's working -- and what's not working -- for the banking industry, say security experts.

Even the most educated customer may not have a defense against a targeted Zeus attack. For that reason, James Woodhill, founder of Authentify and a cybercrime policy expert, argues that education is not the answer.

In his presentation, Woodhill pointed out that it took a noncontroversial medical practice -- the use of penicillin -- nearly 30 years to spread out to general medical practitioners. Innovative defenses against cybercrime could take just as long, he says.

"Education won't help a bit -- not at this scale," Woodhill says. "It takes a long time to get information through to a large group of people."

But being aware of the problem can at least help consumers know their options, argues Sage's Greene. "The challenge is how to inform customers without scaring them away," she says.

Any company that allows users to access corporate data from laptops or home computers is importing risk, says Gary Warner, director of research in computer forensics at the University of Alabama at Birmingham.

"Work from home equals risk at home," Warner says. "If one of your employees has Zeus on their computer and they work from home, then so do their friends in the Ukraine."

Companies should have quarantine zones for home computers and laptops that have left the company premises until their security can be verified, Warner advises.

In the online world, attributing attacks is difficult, which makes online theft an attractive crime.

In the physical world, bank robberies are a low-percentage crime. They account for only about 2 percent of all robberies -- and arrests are made in 60 percent of the cases, according to the FBI's Uniform Crime Reporting (UCR) program. In the virtual world, criminals conduct attacks from safe havens where laws are vague or law enforcement agencies don't often pursue online criminals.

To prosecute cybercriminals, there must be attribution, experts say. But many companies want to clean up the crime scene -- their computers -- and sweep the incidents under a virtual rug. Companies should stop hiding these incidents and pursue investigations of attacks that use Zeus and other malware, experts say.

"If you go in and delete malware off a computer, you don't know why they got the malware, you don't know where the malware came from, you don't know what it might have stolen while it was there, you don't know what data left your company because of the infection, and you don't know if the user understands how he got infected so he won't go do it again," UAB's Warner says.

The current attacks on banks also show the limitations of both application whitelisting and intrusion detection that depends on blacklists, such as antivirus tools, observers say. Blacklisting cannot keep up with the changing threat, and whitelists are too hard to maintain in general-use computing environments, says James Lyne, a senior technologist for Sophos.

"Any one control fails to deal with the threat," Lyne says.

Rather than make binary decisions, organizations should use blacklists and whitelists -- plus reputation and other information -- to help decide whether to allow access to a user, Lyne says. In addition, companies and banks need to use policies and controls to make security a foundation of their corporate culture, he says.

Banks are good at building process controls that help protect them against fraud, says Rick Simonds, CTO of Sage Data Security. "You need controls," he says. "You have a lot of controls on bank employees, and that helps them with security."

But while some banks have a lot of controls to detect fraud committed by insiders, they don't always monitor outside transactions in as much detail, Lyne says. A good defense should account for both the external threat and the internal threat.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS












Featured Webcasts
Featured Whitepapers
Featured Reports
Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.