Phishing is nothing new, but it’s far from old news.
Phishing e-mails are designed to look like they come from a trusted
source and extort personal information, which gets used in a
criminal or fraudulent way. Phishing is mass volume, small pockets
of money, adding up to a handsome gain for the bad guys. At first,
success rates were high, but as most of us have become better at
identifying a phish, success rates have greatly reduced.
So, what’s different about spear phishing? Spear phishing
techniques are highly targeted, and increasingly being used as the
initial wave in more sophisticated malware attacks that are
designed to steal confidential data. For example, spear phishing
has been widely attributed as being the original infection point in
the widely publicised RSA security breach.
Typically, spear phishing e-mails have four common factors:
1. The e-mail is pretending to be from a trusted source, often a
figure of authority, making it even more pressing for the recipient
to open the e-mail.
2. The information in the e-mail is relevant to both the alleged
source and the recipient, making it highly targeted.
3. It contains a seemingly valid request for the user to take
action e.g., to open an attachment or click on a link. This request
is in context with the content of the e-mail.
4. The e-mail is targeted, so is sent out in much lower volumes
compared to traditional phishing attacks, making it harder to
detect.
Targeted attacks leverage online profiles, access credentials,
org charts, hobbies and interests from social profiles in places
like Facebook. Let’s look at three likely attack
scenarios:
- Employees can be tricked into clicking a malicious link from a
trusted colleague through their compromised Facebook status
feed. - A generic spam e-mail is sent from a compromised account to one
of your employees, which leads them to a malicious site. - Sophisticated attackers collect LinkedIn data on their target
and send a tailored lure, which more than likely leads to
data-stealing code.
The vast majority of targeted attacks start with a spear phish
and without the right security in place, users could be unwittingly
opening the door to confidential data theft.
Given such a situation, a frequently asked question that arises
is what can organizations do to stop employees getting duped? And
can employee education help? The answer is – It does. Every
employee should be educated on spear phishing. They need to cast a
critical eye over e-mails and avoid clicking on links that could
lead to an infected site. If in doubt, users should always type
URLs into a browser rather than click on them straight from an
e-mail.
To support this education, many organizations use fictitious
e-mails to see which users click on the links within the e-mail.
When they do, they can be taken to training materials about trying
to spot a spear phish. Employers should repeat the process; keep
employees’ awareness high, educated and cautious. And they
should remember to re-educate employees that continue to get
duped.
It is important for organizations to remember that spear
phishing is a means to an end; the ultimate goal is to obtain
company-specific confidential data. And let’s be clear, no
security solution can guarantee to stop 100 percent of these
threats. While targeted attacks have evolved in frequency and
sophistication, many security defences have failed to adapt. Old
techniques don’t address the intertwined correlation of
attacks across web and e-mail to protect against data theft and
cybercrime call-home communications. The growing prevalence of
cloud apps, along with increases in SSL traffic, mobility and
remote users are also adding more blind spots to traditional
defences.
Maximize Defences
Use layered defences, with a dynamic understanding of the web
and how it relates to e-mail. It’s their best chance to stop
the e-mail before it even reaches the end-user.
Protect confidential data in use, in motion and at
rest
If a user becomes infected, ensure that confidential data is
protected and call-home communications are blocked, so sensitive
information doesn’t leave the organization. Check with your
security vendor that their real-time security can identify unknown
as well as known threats to provide proactive protection. And
ask them how they correlate real-time web security intelligence
with e-mail security trends.
In short, organizations should have a multi-layered approach to
protecting against these difficult-to- detect spear phishing
e-mails.
Here are five best practices organizations should follow to stop
themselves from being the next ‘Catch of the Day’:
Security: Adopt a unified security strategy
that integrates web, e-mail, and data security. Think about home
users and mobile devices. Layer defences to optimize protection and
most importantly, ensure confidential data is protected regardless
of where it is or what device it’s on.
Protection: Communicate best practices to users
to protect their online identities, lock-down their Facebook
profiles and make sure passwords are strong, changed frequently and
not being used for multiple online accounts. Encourage users to
Google themselves and see what personal information of theirs is
unwittingly being shared online.
Education: Educate users on how to spot a spear
phish. Test employees to see where people are still falling for a
phish and re-educate them to develop their knowledge and keep them
vigilant.
Acceptance: Accept that you are a potential
target no matter what your role or level is in the organization.
You are a potential security hole and an opportunity for a criminal
to gain entry into your organization’s network
Reputation: Question the reputation of a link
and don’t assume it’s safe to click on. And just
because an e-mail looks like it comes from a reputable source,
don’t rely on it being from who is says it’s from. If
in doubt, don’t open attachments and instead of clicking
links that could re-direct you a compromised website, type the URL
into the browser.
The author is Regional Director – SAARC India,
Websense
