New Strategies to Fight Phishing
As the Fraud Threat Grows, Battle Plans Change
By Tracy Kitten, March 30, 2012. Credit Eligible
When it comes to financial fraud, banking institutions are losing the battle. The primary culprit: phishing.
Phishing schemes, which are most often carried out by e-mail or instant-messaging, aim to dupe users into sharing sensitive information such as usernames, passwords and credit card details by masquerading as trustworthy entities, such as a bank or government agency.
Worldwide, phishing attacks increased 37 percent from 2010 to 2011, according to the security firm RSA. Last year, RSA estimates, one out of every 300 e-mails included some kind of malicious link or phishing attempt.
Losses associated with phishing are striking, too. In mid-March, the Russian Federal Security Service arrested eight suspects for the roles they played in a $4.5 million phishing scam that crossed several international borders. Working, in part, from information provided by security analyst firm Group-IB, Russian authorities linked the hackers to an online banking trojan called Caberb, which was allegedly used to establish remote access to computer systems and databases. [See 8 Arrested in $4.5 Million Scheme.]
The average phishing attack yields $4,500 in stolen funds for the fraudster, RSA estimates. And large U.S. banks are increasingly the primary targets.
RSA’s online fraud report, The Year in Phishing, notes that while phishing attacks are targeting credit unions and community banks less often, attacks last year on nationwide banks increased 10 percent.
RSA expects phishing schemes to increase this year, as attacks spread to more nations, target more brands and communicate malicious messages in more languages. “Although phishing is one of the oldest online scams, and user awareness is higher than ever, it seems that Web users still fall for phishing, unknowingly parting with their credentials over convincing-enough replicas of websites they have come to trust,” the RSA report states.
Targeted attacks known as spear-phishing, which often identify e-mail users by name and title, pose an increasing threat. But even phishing attacks that are transmitted broadly with generic messages continue to get around e-mail spam filters and trapping methods.
The Core Problem
Why has the financial industry struggled to counter or at least contain phishing attacks? Because it has failed to address the core problem: human manipulation.
“It’s easy for technical people to understand technical issues,” says online security expert Markus Jakobsson, who has studied phishing. “But this is psychology, and technical people are not good at that.”
Social engineering is the challenge. Addressing human behavior is the struggle.
Dave Jevans of the Anti-Phishing Working Group says phishing comes in many forms and flavors. “We’re going to see phishing forever,” he says. “I still get hit by it in paper [mail]. And if we haven’t solved it on physical paper, we aren’t going to solve it on the Internet.”
DMARC: Just A Step?
The complexity of the Internet poses its own challenges, Jevans says, making the effectiveness of initiatives like DMARC, the Domain-based Message Authentication, Reporting Conformance, questionable. DMARC is an industry effort that requires cooperation among e-mail service providers, such as AOL, Gmail, Hotmail, Yahoo!
“There is so much existing infrastructure out there,” Jevans says. “You’re talking about re-jiggering every e-mail infrastructure on the Internet, and that’s a core problem.”
During RSA Conference 2012, held earlier this month in San Francisco, the benefits and challenges of DMARC were weighed by online security experts from Hotmail, American Greetings and PayPal. [See Can DMARC Hook Online Phishers?]
DMARC standardizes how e-mail receivers perform e-mail authentication by providing a uniform reporting mechanism, said Andy Steingruebl of PayPal. “DMARC offers a way for senders to be verified, and it creates a system that’s built on reputation.”
Ultimately, DMARC can block suspicious e-mails, based on certain levels of authentication, before they ever hit the inboxes of intended recipients. Thus, e-mail senders are expected to experience consistent authentication results for messages that go through DMARC-affiliated providers AOL, Gmail, Hotmail, Yahoo!, as well as other e-mail receivers that implement DMARC.
