270 likes | 387 Views
A Brief History of Semantic Attacks or How Not to Get Screwed Online. Serge Egelman. Background. Disinformation Social Engineering Human, *not* technical problem Physical World Variants. Types of Scams. Phishing 419 Scam (“Nigerian Scam”) Check Fraud Overpayment Scam Pump-and-Dump.
E N D
A Brief History of Semantic AttacksorHow Not to Get Screwed Online Serge Egelman
Background • Disinformation • Social Engineering • Human, *not* technical problem • Physical World Variants
Types of Scams • Phishing • 419 Scam (“Nigerian Scam”) • Check Fraud • Overpayment Scam • Pump-and-Dump
Phishing • Stealing personal information • Authentication information • Social Security Numbers • Account numbers • Perpetrated via email • “Account update” • “Verify your information” • Fake websites • Pharming
Phishing Statistics • Countries of Origin • United States - 32.07% • Republic of Korea - 15.39% • France - 6.55% • China - 6.40% • United Kingdom - 4.06% • Germany - 3.85% • Spain - 3.81% • Japan - 3.05% • Italy - 2.48%
Phishing Countermeasures • Manual • Check URLs • Examine certificates • Never click • Automated • Spam filters • Challenge/response • Browser plugins
Phishing Toolbars • Clear Search • Scans email using heuristics
Phishing Toolbars • Cloudmark • Community ratings
Phishing Toolbars • eBay Toolbar • Community ratings
Phishing Toolbars • SpoofGuard • URL analysis • Password analysis • Image analysis
Phishing Toolbars • Trustbar (Mozilla) • Analyzes known sites • Analyzes certificate information
Phishing Toolbars • Trustwatch • Site ratings
But Do They Work? • No • 25 Sites tested • Cloudmark: 10 (40%) identified • Netcraft: 19 (76%) identified • Spoofguard: 10 (40%) identified • Trustwatch: 9 (36%) identified • Hardware Solutions • Too costly • Inconvenient
Trust Research • User Studies • Phishing Feeds • User Training • Embedded training • Games • Detection • Email • WWW • IM
419 Scam (“Nigerian Scam”) • Businessman needs to launder money • Make you rich • Requires upfront fees • Sometimes more than money is lost • Often perpetrated from Nigeria • Though now all over the world
Check Fraud • Victim is selling something online • Anxious buyer needs item immediately • Sends money order • Buyer must ship item after receiving check • Check is a forgery • But item is already sent • Example • P-P-P-Powerbook!
Overpayment Scam • Check fraud variant • Money order is far larger than sale price • “Oversight” by buyer • Buyer needs check for the difference • Original money order is forged
Pump-and-Dump • Scammer invests in penny stock • Sends messages hyping the stock • People invest • Value goes up • Scammer “dumps” the stock