<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>seki &#187; cybercrime</title>
	<atom:link href="http://www.spinlock.com/category/cybercrime/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spinlock.com</link>
	<description>Spinlock Technologies LLC</description>
	<lastBuildDate>Tue, 16 Feb 2010 13:29:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>The botnet peril</title>
		<link>http://www.spinlock.com/2009/03/botnet-peril/</link>
		<comments>http://www.spinlock.com/2009/03/botnet-peril/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 13:11:22 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[trends]]></category>
		<category><![CDATA[botnets]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=55</guid>
		<description><![CDATA[For as many times as we have heard that e-commerce is at risk due to the actions of sophisticated cyber-criminals, it is astounding how little has been done to protect against wholesale attacks against users and, more importantly, against the major retailers who are more and more dependent upon commercial trade over the Internet. It [...]]]></description>
			<content:encoded><![CDATA[<p class="firstLetter">For as many times as we have heard that e-commerce is at risk due to the actions of sophisticated cyber-criminals, it is astounding how little has been done to protect against wholesale attacks against users and, more importantly, against the major retailers who are more and more dependent upon commercial trade over the Internet. It is this very dependency that accounts for the high value of so-called asymmetric attacks, and today&#8217;s nemesis in this regard is the <em><a title="botnet, defined (Wikipedia)" href="http://en.wikipedia.org/wiki/Botnet" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/Botnet?referer=');">botnet</a>,</em> ad hoc confederations of unsuspecting users&#8217; computers that have been coopted by cybercriminals through the use of malicious software.</p>
<p class="firstLetter">The Hoover Institution recently published a <a title="eWMDs: the botnet peril (Hoover Institution)" href="http://www.hoover.org/publications/policyreview/35543534.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.hoover.org/publications/policyreview/35543534.html?referer=');">call-to-arms about botnets</a>, provocatively declaring that botnets should be called &#8220;electronic weapons of mass destruction&#8221;, given the fact that critical infrastructure can be easily put at risk by botnet operators.<span id="more-55"></span> And this point is driven home in the fact that major power and telecommunications utilities are already highly interconnected with the public Internet, thus allowing for the asymmetric leveraging of tens or hundreds of thousands of mundane home computers &#8212; via the illicit introduction of malware &#8212; into attacks on such things as <a title="SCADA, defined (Wikipedia)" href="http://en.wikipedia.org/wiki/SCADA" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/SCADA?referer=');">SCADA</a> (supervisory control and data acquisition) elements that manage critical infrastructure.</p>
<p class="firstLetter">As a case study, the article&#8217;s authors explore the case of the April 2007 cyberattack against Estonia, both in terms of what was put at risk as well as how the world should respond to such cases. Although we still find it a stretch to make the parallels with military conflicts too concrete, the point is well taken that such forms of asymmetric warfare put the advantage in the corner of the attacker, whether that attacker is a sophisticated nation-state or a ring of profiteering cyber-criminals. Both of these groups are abetted by the same lack of security on the Internet.</p>
<p class="firstLetter">Although the article is long on observation and short on prescription (aside from advocating a very active form of defence), it is a very well-reasoned summary overview of the threats that exist today on the Internet. In short, it explains why we need a call-to-arms and what might happen if we don&#8217;t heed the warning.</p>
<p class="firstLetter">
<p><em>The article entitled </em><a title="eWMDs: the botnet peril (Hoover Institution)" href="http://www.hoover.org/publications/policyreview/35543534.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.hoover.org/publications/policyreview/35543534.html?referer=');">eWMDs: the botnet peril</a><em> by John J. Kelly and Lauri Almann appears in </em><a title="Policy Review (Hoover Institution)" href="http://www.hoover.org/publications/policyreview/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.hoover.org/publications/policyreview/?referer=');">Policy Review</a><em>, No. 152, Dec. 2008/Jan. 2009 b</em>y<em> <a title="The Hoover Institution (main website)" href="http://www.hoover.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.hoover.org/?referer=');">The Hoover Institution</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2009/03/botnet-peril/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Underground digital economy spotlighted</title>
		<link>http://www.spinlock.com/2008/11/underground-digital-economy/</link>
		<comments>http://www.spinlock.com/2008/11/underground-digital-economy/#comments</comments>
		<pubDate>Mon, 24 Nov 2008 11:58:16 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mitigation]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=26</guid>
		<description><![CDATA[In October 2008, the Symantec Corporation published its Report on the Underground Economy, which is the culmination of a year-long effort to observe and record the behaviors of bad actors in the cybercrime arena. By watching the activities of malicious botnets over a long period of time, Symantec&#8217;s researchers were able to identify likely interaction [...]]]></description>
			<content:encoded><![CDATA[<p>In October 2008, the Symantec Corporation published its <em><a title="Report on the Underground Economy (PDF)" href="http://eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_underground_economy_report_11-2008-14525717.en-us.pdf" target="_blank" onclick="pageTracker._trackPageview('/outgoing/eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_underground_economy_report_11-2008-14525717.en-us.pdf?referer=');">Report on the Underground Economy</a>,</em> which is the culmination of a year-long effort to observe and record the behaviors of bad actors in the cybercrime arena. <a href="http://www.spinlock.com/wp-content/uploads/2008/11/200811-sym-underground.png"><img class="alignright size-full wp-image-27" style="margin: 2px;" title="200811-sym-underground" src="http://www.spinlock.com/wp-content/uploads/2008/11/200811-sym-underground.png" alt="" width="154" height="91" /></a>By watching the activities of malicious botnets over a long period of time, Symantec&#8217;s researchers were able to identify likely interaction strategies for trading stolen digital cargo and services.</p>
<p>What&#8217;s most interesting about this report is not the specifics of any particular set of cybercriminals, but instead in the number of channels used to convey the goods as well as the pedestrian style of commerce, including several online How-To guides, used to entice would-be sellers to peddle their stolen goods.</p>
<p>Although this report is heavily biased toward reporting numbers and statistics, by enumerating price lists for stolen data and of the number of command-and-control networks used on a daily basis by cybercriminals, CISOs can put a much more firm opportunity cost estimate for failure to apply proper controls to sensitive customer data. In addition, in an appendix to the report, Symantec offers readers its recommendations for mitigation strategies to shore up data security risks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2008/11/underground-digital-economy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
