A Practical Approach to Managing Phishing
In the summer of 2006, the authors of this white paper examined PayPal’s approach to managing phishing. We realized that our strategy was based on preventing financial loss in the victim’s account – long after the original phishing email had duped its victim. However, it became rapidly clear to us that there was a holistic dimension that our previous approach missed. Equally clear was the fact that we couldn’t eradicate this problem on our own – to make a dent in phishing, it would take collaboration with the Internet industry, law enforcement, and government around the world.
Read the Article
|
PDF Virus or Spam3 min. 28 sec.
A lot of PDF files have been floating around as of late - is it a virus or just spam?
Watch the Video
|
Why Phishing Works
This paper addresses the question of why phishing works. We analyzed a set of phishing attacks and developed a set of hypotheses about how users are deceived. We tested these hypotheses in a usability study: we showed 22 participants 20 web sites and asked them to determine which ones were fraudulent, and why.
Read the Article
|
Understanding Phishing and Pharming
With insight into the threats of phishing and pharming, this paper is intended to help identify what a phishing attack is, what it looks like in a network, and how it can be mitigated, as well as what pharming attacks may look like based on different attack scenarios and how to alleviate their effect on your business assets. We will also outline how, historically, these two types of attacks have developed into today's sophisticated, deadly duo aimed at business, consumer, and government entities.
Read the Article
|
Phishing and Pharming "The Deadly Duo".
Phishing and Pharming are two of the most organized crimes of the 21st century requiring very little skill on the part of the fraudster. These result in identity theft and financial fraud when the fraudster tricks the online users into giving their confidential information like Passwords, Social Security Numbers, Credit Card Numbers, CVV Numbers, and personal information such as birthdates and mothers' maiden names etc.
Read the Article
|
Technical Trends in Phishing Attacks
In this paper, we will identify several of the technical capabilities that are used to conduct phishing scams, review the trends in these capabilities over the past two years, and discuss currently deployed countermeasures.
Read the Article
|
How to Eliminate Spam
Industry analysts estimate that spam currently accounts for close to 80 percent of email messages sent and causes close to $5 billion in economic losses annually. The problem with spam is very similar to that of pollution: spammers profit from their activity at the expense of the rest of the population, just like polluters of the environment profit while annoying or endangering others.
Read the Article
|
The Next Step in the Spam Control War: Greylisting
This paper proposes a new and currently very effective method of enhancing the abilities of mail systems to limit the amount of spam that they receive and deliver to their users. For the purposes of this paper, we will call this new method "Greylisting". The reason for choosing this name should become obvious as we progress.
Read the Article
|
The Pharming Guide
A grouping of attack vectors now referred to as "Pharming", affects the fundamental way in which a customer's computer locates and connects to an organisations online offering. Enabling the Pharmer to reach wider audiences with less probability of detection than their Phishing counterparts, pharming attacks are capable of defeating many of the latest defensive strategies used customer and online retailer alike. This paper, extending the original material of "The Phishing Guide", examines in depth the workings of the name services of which Internet-based customers are dependant upon, and how they can be exploited by Pharmers to conduct identity theft and financial fraud on a massive scale.
Read the Article
|
Fighting Internet Worms With Honeypots
This paper will evaluate the usefulness of using honeypots to fight Internet worms. The first part of the article will discuss some background information on worms and their ubiquity, then move on to discuss some of the interesting interactive functions of honeypots. Finally, we will study how a honeypot framework can be used to fight off Internet worms and even perform a counterattack, before we conclude with some future perspectives.
Read the Article
|