Government Technology

    Digital Communities
    Industry Members

  • Click sponsor logos for whitepapers, case studies, and best practices.
  • McAfee
  • Net App
  • Perceptive Software

Upsurge in Attacks for Stealing Personal Banking Details



November 26, 2007 By

F-Secure warns computer users of an upsurge in attacks against banking sites, targeting personal user data. These attacks use a new generation of malicious codes in a technique called "Man in the Browser".

Historically, cyber criminals have always sought ways of stealing the personal and banking data of web users. The techniques used by these criminals have become more sophisticated in order to adapt to the growing sophistication of the security solutions. It started with software that was capable of retrieving the data typed into the computer keyboard ("keyloggers"), and then more complex mechanisms arrived on the scene, such as phishing and pharming.

Phishing uses emails that the sender disguises to look as if they come from a financial establishment. When the web user clicks on the link contained in the mail, he finds himself on a bogus site that imitates that of his bank, and which retrieves his personal banking data.

Pharming consists in automatically redirecting the web user to a false site (imitating the site of his bank) when the user wishes to visit the real site, but without the user having to click on a link of any kind, since the usurping of the address takes place at Internet level. The "Man in the Middle" technique consists in the cyber criminal pretending to be the bank's site, intercepting the data passed by the user, and then using that data to access the real bank site to gain access to the account.

The latest technique used for these attacks is known as "Man in the Browser". Once the PC has been infected, the malicious code is only triggered when the web user visits his online bank site. This type of malware is capable of retrieving the information (login and password) that is entered by the web user on the real web page of the bank site by intercepting the HTML code on his web browser. This personal data is then sent directly to an FTP site where the cyber criminal stores it, before selling it on to the highest bidder on other web sites used by cyber-criminals.

Security products using behavioral analysis are the best solution against such attacks, as the malicious codes are designed specifically for certain banking sites. They are not distributed en masse, unlike attacks using phishing. This restricted distribution constitutes a real challenge for security software publishers when it comes to referencing these viruses and using signature recognition.

"With the enhancements that banks have deployed in terms of authentication security on their online banking sites, phishing attacks are becoming less and less effective and attacks of the 'Man in the Browser' are set to increase," says Mikko Hypponen, chief research officer at F-Secure.



| More

Comments


Add Your Comment

You are solely responsible for the content of your comments. We reserve the right to remove comments that are considered profane, vulgar, obscene, factually inaccurate, off-topic, or considered a personal attack.

In Our Library

White Papers | Exclusives Reports | Webinar Archives | Best Practices and Case Studies
Living in a Smart City: Chattanooga, TN
The only one Gigabit broadband service in the United States for residential and business customers is now available citywide in Chattanooga, Tennessee. Let's meet people who live and work in one of the smartest city: what services do they embrace today, what is their vision for the future, and what kind of culture do they think makes this all possible and what's their definition of a smart city.
Creating Your Smart Grid: A How-To Guide
The smart grid promises to bring unprecedented opportunities for both utilities and consumers, improving safety, reliability, efficiency and security. The latest communications technologies will greatly improve awareness of grid conditions – in real time – for better control, management and decision-making.
WHITEPAPER: D Block Spectrum Act and the FirstNet Broadband Network. What does it all mean?
On Feb 22, 2012, the Middle Class Tax Relief and Job Creation Act of 2012 was enacted into law. This law will ensure the establishment of a nationwide, interoperable public safety broadband network in every state and territory in the U.S. Learn about the new law and what you can do to prepare for it now.
View All

Digital Communities members get access to our collaboration task forces

427 Members

77 Discussions

84 Files

Latest members Become a member

Digital Communities members get access to our collaboration task forces

669 Members

145 Discussions

150 Files

Latest members Become a member

 


Featured White Papers & Reports

The Future of the Desktop in Government

Until recently, there was no alternative to the familiar desktop computer, and its expensive upgrades and maintenance requirements. For cash-strapped local governments, the desktop computer is quickly becoming an unsustainable option for future progress. Now, a technology known as virtual desktop infrastructure (VDI) offers an alternative. It can be significantly more affordable than buying individual computers for every employee, and it provides similar capability. This paper shows how VDI is the future of the desktop and is a game-changer for local governments.


View Full Library

Events

GTC East

Don't miss this opportunity to see the latest in digital government solutions, keep abreast of current policy issues and network with key government executives, technologists and industry specialists.

View All Events