Network World

Weblogs

Search / DocFinder:
Advanced search
Research Centers
Vendor Solutions
Site Resources
Special Issues

Signature SeriesEnterprise All-Stars
Enterprise All-Stars NEW

You in action
You in action

New Data Center The New Data Center: Wireless & Mobility
Wireless & Mobility NEW

The New Data Center: Server Virtualization
Server Virtualization

Welcome | Gearblog archives     Search   RSS feed  

NOTE:
Gearblog has morphed into Gibbsblog. All new postings, same great Gibbs. Come on over!

The world of phishers and what it tells us about on-line crime


By Gearhead, NetworkWorld.com, 06/20/05

"The typical phisher ... isn't a movie-style villain but a Romanian teenager, albeit one who belongs to a social and economic infrastructure that is both remarkably sophisticated and utterly ragtag."

An interesting story in the Wall Street Journal discusses the world of phishers as charted by Christopher Abad, a researcher who works for Cloudmark.

Abad apparently spent months digging into how phishers work and one of the more bizarre aspects of phishing is that "... phishing scams ... have ... become so complicated that, just as with medicine or law, the labor has become specialized."

Turns out there are guys who work the front end of the scam (getting the identity information and bank account data), guys who design the "bait" (the bogus Web sites), while others run the back end, getting the actual funds and routing the proceeds to the other parties. How is cheating prevented? The phishers have a rating system to track who is "honest" and who is isn't!

That this world should exist doesn't come as a surprise -- with every new, poorly policed market where any significant amount of money is involved comes organized crime. But this isn't like real world organized crime.

We've read any number of articles that refer to "Mafia" involvement in on-line crime but usually don't have any solid evidence to back up the assertion. It appears that for today, the bulk of on-line crime can be attributed to "working hackers" running what might be thought of as cottage businesses. Interestingly, should the Mob ever want to take over the on-line crimes business the decentralization and lack of physical access would make such a play extremely difficult.

The problem for law enforcement is that the on-line world will always be diffuse, decentralized, and highly volatile making catching the bad guys a matter of luck rather than traditional crime solving. Add to that the inherently trans-national nature of the problem and unless international law enforcement becomes a lot more cooperative and sophisticated we can expect the problem to grow rapidly.

The cheapest and most effective solutions lie in better consumer education, better business processes on the part of financial institutions, and better client operating systems. The first two are very difficult as consumers are hard to educate and banks and their ilk seem to be willing to operate on-line at a level of acceptable risk for them (but not for the consumer). As for better operating systems (either by engineering the OS itself or adding extensions that make a more secure environment), well, there's where the opportunity lies.

Back to Gearblog

Comments

Newsletters
Sign up for one of NWW's Application newsletters.

Web Applications
Network Optimization
Network Systems Management
Network/Systems Management News Alert
View all newsletters

Email Address:

Vendor Solutions

White Papers

CIO Viewpoints: Exchange 2007 Risks and Mitigation Strategies
- Dell

CIO Strategies for the Retention and Deletion of Email
- Dell

Leveling the Field: Powerful Software Solutions for Midsize Companies
- Oracle

More...

Special Report

Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009 - F5 Networks
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.


Research Centers: Applications | Application Development | Applications-Standards | Applications Vendor Solutions | Collaboration | CRM / ERP | Databases | Directories | Grid Computing | Java | Messaging | .Net | RFID | SOAP | Web Services | XML | Convergence & VoIP | Convergence Regulatory | Convergence Services | Convergence Standards | Convergence VoIP Vendor Solutions | Video | IP PBX | SIP | VoIP | VoIP Services | E-Business | DNS | RFID | Supply Chain | Web security LANs & Routers | Acceleration | Gigabit Ethernet | Lans-Standards | Routers | Wireless LANs | Network Management | Application Management | Desktop Management | Management Test Patch Management | Operating Systems | Linux | NetWare | Unix | Windows Outsourcing | Managed Services | Offshoring Security | Firewalls - VPN - Intrusion | Identity management | Patch Management | Microsoft Security | Privacy | Security Standards | Spam & Phishing | Viruses & worms | Web Security | Wireless Security | Servers & Desktop | Backup-Recovery | DataCenter | Desktops | Desktop Management | Grid | Servers | Server Blades | Servers Desktops | Utility Computing | Small & Medium Business | Broadband | Telework | Handhelds & PDAs | Home Networking | Security | Storage | Compliance | Infiniband | Network-Attached Storage | SANs | Storage Management | Storage Virtualization | Virtualization | Vendor News | Bankruptcy | Earnings | Lawsuits | Layoffs | Standards | Start Ups | Vendor Markets | Education | Financial | Healthcare | HIPAA | Manufacturing | Retail | Wide Area Network | Broadband | Carriers | Frame Relay | Metro Ethernet | MPLS | Service providers | Wireless services | Wireless & Mobile | Wireless LANs | PDAs & handhelds | Wireless Security | Wireless Services | Wireless Standards | Wireless Switches | All Company Profiles