Experts Offer Insights on Overcoming Challenges
Spear-phishing campaigns are becoming localized, small and capable of slipping past spam filters, and current efforts to mitigate risk aren’t doing the job, says Gary Warner, director of research for computer forensics at the University of Alabama at Birmingham.
One big problem: Conventional phishing prevention practices assume that DMARC – the Domain-based Message Authentication, Reporting and Conformance initiative that aims to standardize how e-mail receivers perform e-mail authentication – will be the ultimate answer, say Warner and Greg Coticchia, CEO of Malcovery Security, an anti-phishing technology company recently spun off from the university.
“The whole premise behind DMARC is that if I sign my outbound e-mail and someone receives an e-mail that’s from my domain but hasn’t been signed by me, they will know that they should reject it,” Coticchia says in an interview with Information Security Media Group [transcript below]. “The problem is, if I send you an e-mail and I say it’s from wellsfargosecurity.com, the consumer doesn’t know that wellsfargo.com and wellsfargosecurity.com are two different places. In fact, some of these banks already do business from 150 different domain names.”
Warner says another key issue is the siloing of systems and departments at most organizations.
“The fraud analyst group is one place,” he explains. “The network defenders are in another place; the perimeter defenders are in another place.” As a result, these different departments aren’t coming together to facilitate enterprise security intelligence to identify trends.
Enterprise security intelligence, Warner says, requires the use of big data and the application of data-mining principles to find that proverbial “needle in a haystack.”
Right now, “the larger the organization, the greater chance there is that there are silos,” especially within and among security and fraud response teams, he says. As a result, those departments are not able to adequately consume intelligence, he says.
During this interview, Warner and Coticchia discuss:
- Why standard countermeasures have proven ineffective when it comes to mitigating spear-phishing risks;
- Why DMARC will never be a silver-bullet; and
- The role of big data in fighting phishing.
At UAB, Warner focuses on the problems faced by cybercrime investigators in law enforcement and elsewhere. He also serves as chief technologist at Malcovery. Earlier, Warner was IT director for a publicly traded energy company. For the past six years, he has been active in the FBI’s InfraGard program. He also has served on the national board of the Energy ISAC and currently serves as a Microsoft Security MVP.
Coticchia has more than 25 years of experience in high-tech products and services. He previously served as CEO and co-founder of eBillingHub, now part of Thomson Reuters. He teaches business-to-business marketing and entrepreneurial leadership at the University Of Pittsburgh Katz School Of Business.
Spin-Off Company
TRACY KITTEN: Can you give us a brief overview of Malcovery and what it does?
GREG COTICCHIA: Gary’s work at the University of Alabama at Birmingham was really renowned in the areas of phishing, spam and malware, and close to $3 million of the research had been put into the technology … that helped identify the source and nature of cyber-attacks. It’s a very valuable thing.
In today’s world, as you know, we have a perimeter. We have multiple layers of defense that are really starting to crumble as a variety of new technologies are brought into the office, between tablets and mobile and just the structure of data. As a result of that, we have to be much smarter in our security technology. Malcovery is based upon all the technology that Gary and his team developed at UAB so that we could actually identify the source and nature of those cyberthreats. In today’s world, in many cases you’re playing “whack-a-mole,” just dealing with the symptoms, and we’re dedicated to the idea that if you can find the root source, the root cause, you can be much more effective in today’s world.
Biggest Phishing Mistakes
KITTEN: What is the biggest mistake the online world is making, where phishing prevention is concerned?
