Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Hackers Recruited for Cyberwarfare | Main | Google Looking More Like Enterprise Software Vendor »

Phishing and Countermeasures - Part 2

In Phishing and Countermeasures - Part 1 I reviewed an introduction to phishing, phishing attacks, spoofing and countermeasures, and pharming from Jakocsson and Myers Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft. Today I'd like to turn to security tools and spear phishing.

Chapter 5, Status Quo Security Tools, covers anti-spam techniques, public key cryptography, SSL and honeypots. The anti-spam section includes a discussion of blacklisting, whitelisting, filtering, charging for email, Domain Keys and Sender ID. The information is generally available elsewhere but the section is concise and covers the main points. The public key cryptography and SSL sections address topics that are probably well understood by most readers; the authors take a more formal and academic approach than found in most security texts. The final section on honeypots provides an overview, advantages and disadvantages, as well as technical details on low interaction honeypots (like Honeyd) and high interaction honypots (like Honeywall).

Chapter 6 spear phishing combines a formal analysis of spear phishing with case studies. The first part of the chapter carefully dissects a context-sensitive attack and build a formal model for such attacks. An especially appealing aspect of this chapter is the five case studies ranging from trawling for publicaly available private data (like mother's maiden names), the role of social networks in spear phishing and the potential for stealing information from browser convenience features like autofill.

In part 3, we'll take a look at human-centered design considerations, passwords, and mutual authentication.

Phishing and Countermeasures - Part 1 (introduction, attacks, countermeasures, pharming)
Phishing and Countermeasures - Part 2 (security tools and spear phishing)
Phishing and Countermeasures - Part 3 (human centered design,considerations, passwords, and mutual authentication)

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/416

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net