Sunday, February 8, 2009

Phising : Example and its prevention methods


WHAT IS PHISING??

Phishing is an attempt by perpetrator by using computer to acquire sensitive information criminally and fraudulently such as usernames, passwords, credit card numbers, bank account number, account data or other information to invade people privacy.

HOW PHISING WORKS??

Phishing is usually carried out by sending e-mail, instant message, and phone call which the content of the messages will often ask you to reveal your personal information. They will use fake website they have created instead of legitimate one to steal the information from people, the fraudulent email address that they have sent usually redirect to the perpetrator website which is fake so that it looks similar to the original website. Many people may not know this website is real or not, if they are lack of awareness, most probably they will fall into this trap.

The chart below shows that the phishing crime is increasing each month from October 2004 to June 2005.

The most common target for the phishing is Paypal, eBay and online banks are used to let the perpetrator commit fraud. Here is the example of phishing:


a) This is example of phishing targeted at paypal users.

b) Phishing e-mail , disguised as an official e-mail from bank.


c) An example of a phishing e-mail targeted at eBay users.


d) Phishing e-mail from Citibank.


PPPREVENTION METHODS OF PHISHING:
There are a few ways to prevent being a victim of phishing scams. Here are the methods to avoid the phishing scams.

1. If you get an email or pop-up message that asks for personal or financial information, do not reply.
2.
Read the message carefully before enter your password or any personal identity to the sender.
3.
Examine the link that provided in the email because real email will have a link to original or official websites.
4.
Use anti-virus and anti-spyware software, as well as a firewall, and update them all regularly to detect phishing easily.
5. Make sure any received call is really from real banks or right people.
6.
Always keep your password and username safe from other people.


Saturday, February 7, 2009

How to safeguard our personal and financial data?


Nowadays, computer and internet are very common to everyone. We will rely on computer to save our personal data and using online financial services to do financial transactions such as online banking in order to safe time. Therefore, the safeguards that you make are not sufficient enough to protect your confidential data. Other than that,in the dynamic financial sector, people have to differentiate themselves with innovative technologies that improve customer service, streamline back-office operations, and strengthen risk management. Unfortunately, these same technologies often open doors to a variety of malicious attacks.
Today’s threats are significantly more dangerous than those of just a few years ago.
Financial institutions have become prime targets for cyber attacks by organized crime
with the sole objective of profiting at customers’ expense.

Here have few tips to keep your personal and financial data safe:

Encryption

Encryption refers to algorithmic schemes that encode plain text into non-readable form or cyphertext, providing privacy. The receiver of the encrypted text uses a "key" to decrypt the message, returning it to its original plain text form. The key is the trigger mechanism to the algorithm.
Until the advent of the Internet, encryption was rarely used by the public, but was largely a military tool. Today, with online marketing, banking, health care and other services, even the average householder is aware of encryption.
As more people realize the open nature of the Internet, email and instant messaging, encryption will undoubtedly become more popular. Without encryption, information passed on the Internet is not only available for virtually anyone to snag and read, but is often stored for years on servers that can change hands or become compromised in any number of ways. For all of these reasons encryption is a goal worth pursuing.

Firewall

A system designed to prevent unauthorized access to or from a private network. Firewalls can be implemented in both hardware and software, or a combination of both. Firewalls are frequently used to prevent unauthorized Internet users from accessing private networks connected to the Internet, especially intranets. All messages entering or leaving the intranet pass through the firewall, which examines each message and blocks those that do not meet the specified security criteria.

intrusion detective system

Intrusion detective system tries to identify attempts to hack or break into a computer system or to misuse it. IDSs may monitor packets passing over the network, monitor system files, monitor log files, or set up deception systems that attempt to trap hackers. While a firewall should always be your first line of defense, an IDS should be next.
For example:Think of your network as a prison. The outside is protected by a large wall (firewall), while the inside is protected by cameras and corrections officers (an IDS). There are several types of IDSs, the most common types work the same. They analyze network traffic and log files for certain patterns. While a firewall will continually block a hacker from connecting to a network, most firewalls never alert an administrator. An IDS will flag the events and alert an administrator. The administrator can then see what is happening right after or even while the attacks are still taking place. This gives an administrator the advantage of being able to analyze the techniques being used, source of attacks, and methods used by the hacker.

Biometric security

It is the automated methods for uniquely recognizing humans based on one or more intrinsic physical or behavioral traits . There are 2 characteristic, physical (fingerprints, irises,retinas, facial partterns, and hand measurements) and behavioral (gait, signature, and typing patterns)
Biometric system have the potential to identify individuals with very high degree of certainty. Physical attributes are much harder to fake than identify cards. Biometric system are personal recognition based on "who you are" as opposed to conjunction with "what you know" (pin) or "what you have" (ID card). Recognition of a person by his body, then linking that body to an externally established “identity”, forms a very powerful tool for identity management


*

How safe is our data?

Nowadays, many viruses and destructive data methods are being made every single day. The cyber world has become a battle field with no end to stopping the online security threats. Here we can take a look at some of the latest online security threats.

Insider threats are the highest-ranking IT security concern. Insider misuse and unauthorized access by insiders are considered the top two IT security threats by our survey respondents.

Spam follows closely behind insider threats as a category of concern. This may be attributed to the prevalence of spam, the fact that spam is highly visible to everyone in the organization and that spam serves as a vector for many other types of attacks.

Malware such as computer viruses, worms, trojans, adware, and spyware still ranks highly in the list of concerns. There is significant variation between organizations in terms of the frequency of malicious code attacks, most likely due to variation in how well organizations defend against such security events.

Besides that, unauthorized access by outsiders is ranked only slightly behind malware in terms of seriousness. It is quite possible, however, that in some organizations, hackers have obtained unauthorized access without the awareness of the organization. Hence, the number of hacking incidents is likely underreported in the statistics.

Another point is that IT security professionals take the threat of physical loss or theft of computer hardware and storage somewhat seriously, a significant number think it is only a minor threat.

Although many organizations are experienced in fighting electronic fraud, survey respondents rank fraud in the middle of the list of security concerns. These results most likely reflect the fact that many high-risk organizations, such as banks and financial institutions. IT security professionals are not sufficiently worried about the threat of pharming attacks. Similarly, we do not find very high levels of awareness of the threat of phishing, at least among respondents outside of the financial services sector.

Most IT security professionals and managers do not view electronic vandalism/sabotage as a serious threat. Such computer crimes in the past were motivated by a desire to gain bragging rights among hackers.

IT professionals vary considerably in their perception of the seriousness of denial of service (DoS) attacks. This disparity is most likely due to the variation in the "attractiveness" of the organizations in our sample as targets.

Extortion by electronic means ranks last in the list of IT security concerns. This is most likely because of the infrequency of such attempts. Therefore, it is not surprising that most IT security professionals do not consider extortion a serious threat.






Related Links:
http://www.readwriteweb.com/archives/top_online_security_threats_for_2009.php
http://www.computereconomics.com/article.cfm?id=1214
http://www.entrepreneur.com/technology/techtrendscolumnistpeteralexander/article78616.html

Saturday, January 31, 2009

An example of an E-Commerce success and its causes

The name "Google" originated from a misspelling of "Googol," which refers to the number represented by a 1 followed by one-hundred zeros. Having found its way increasingly into everyday language, the verb, "google," was added to the Merriam Webster Collegiate Dictionary and the Oxford English Dictionary in 2006, meaning, "to use the Google search engine to obtain information on the Internet. The term of "Googol" was coined by Milton Sirotta, nephew of American mathematician Edward Kasner, and was popularized in the book, "Mathematics and the Imagination" by Kasner and James Newman. Google's play on the term reflects the company's mission to organize the immense amount of information available on the web.

Google began in January 1996, as a research project by Larry Page, who has soon joined by Sergery Brin, two Ph.D, students at Stanford University in California and company was 1st incorporation as a privately held company on 4 September 1998.

Google was an American public corporation, earning revenue from advertising related to its Internet search. e-mail, online mapping, office productivity, social networking and video sharing services as well as selling advertising free version of the same technologies. Google has continued its growth through a series of new product developments, acquisitions and partnerships. Environmentalism, philanthropy and the positive employee relations have been important tenets during growth of Google.

The key reasons for Google's success is a belief that good ideas can and should come from anywhere.
Google's early success is based on several key factors:

  • Technology
    • Along with its innovative approach to page ranking, Google is a purpose-built hardware company, building all its own servers from components it buys directly for their manufacturers. According to Drummond (Google's General Counsel), Google now operates the world's largest distributed computer system.

  • Business Model Innovation
    • By perfecting the nature of targeted ads, Google not only has created a highly effective revenue generator, it has produced what it hopes to be a better experience for its users. It is Google's goal to make their targeted ads at least as relevant and useful to users as the search results themselves.
  • Brand
    • According to Drummond, a European study recently determined Google to be the number one most recognized worldwide brand. Indeed, Google has become a verb ("I can't wait to get home and Google him") which poses real challenges to a company seeking to protect the strength of its mark.
  • Focus On The User Experience
    • Product decisions at Google are driven by optimizing for the user experience first and for revenue second. The folks at Google firmly believe that the better the user experience, the more easily money will follow.
  • Bottom up Approach
    • Nurturing great ideas from all levels of the company, not just the top.
  • Creativity
    • Demand creativity by giving employees "free thinking time" to develop pet projects, no matter how far from the company's central vision.
  • Managing Innovation
    • Google management adopted unconventional management style. Engineers are encouraged to work in a small team to improve productivity. Management is always available to employees so that their idea can be heard.
I believe that all of these are important factors in developing any great technology company. Powerful customer-focused technology with an eye towards making money -- that's pretty much the formula. Even brand, which can be prohibitively expensive to develop ahead of customer traction, will likely follow product leadership. Google's success isn't rocket science, it's just good old fashion company building. Good for them for the discipline. It's an excellent model to follow.