Sunday, February 15, 2009
The Threat of Online Security: How Safe is Our Data?
1) Non-technical attack is an attack that uses chicanery to trick people into revealing sensitive information or performing actions that compromise the security of a network.
a) Phishing is a broadly launched social engineering attack in which an electronic identity is misrepresented in an attempt to trick individuals into revealing credential. It is also known as THEFT.
2) Technical attack is an attack perpetrated using software and systems knowledge or expertise.
a) Denial-of-Services (DOS) attack
-- An attack on a web site in which an attacker uses specialized software to send a flood of data pockets to the target computer with the aim of overloading its resources.
b) Distributed denial-of-service (DDOS) attack
-- Attacker gain illegal administrative access as many computers on the internet as possible and uses the multiple computers to send a flood of data packets to the target computer.
c) Viruses
-- It is a piece of software code that inserts itself into a host, including the operating systems, in order to propagate; it cannot run independently, it requires that its host program be run to activate it.
d) Worm
-- It is a software program that runs independently, consuming the resources of its host in order to maintain itself, that is capable of propagating a complete working version of itself onto another machine.
e) Trojan Horse
-- It is a program that appears to have a useful function but that contains a hidden function that presents a security risk.
How safe is our data?
There have a lot of tools that can be used by the users to secure their data. The simplest aspects of network security are access control and authentication. Access control is a mechanism that determines who can legitimately use a network resources and which resources he, she or it can use. Typically, access control lists (ACL) define which users have access to which resources and what the rights they have with respect to those resources.
Once a user has been identified, the users must be authenticated. Authentication is the process of verifying that the user is who he or she claims to be. Verification is usually based on one or more characteristic that distinguishes the individual from others. The distinguishing characteristic can be based on something one knows like password, something one has like token, something one is like fingerprint.
Tokens qualify as something one has. Tokens come in various shapes, forms and sizes. There have two types of tokens such as passive token and active token. A passive token is the storage devices that contain a secret code used in a two-factor authentication system. Meanwhile, a active token is the small, stand-alone electronic devices that generate one-time passwords used in a two-factor authentication system. A two-factor authentication is combining something one knows with something one has.
A biometric system is one of the authentication methods that recognize a person by a physical trait. It identifies a person by measurement of a biological characteristic such as fingerprints, iris (eye) pattern, and facial features or voice. It can identify a person from a population of enrolled users by searching through a database for a match based on the person’s biometric trait. Furthermore, biometric system can divide by two types such as physiological biometrics which the measurements derived directly from different parts of the body and behavioral biometrics which the measurements derived from various actions and indirectly from various body parts.
Another tool that can use is public key infrastructure (PKI). It is using in encryption process. It is the process of scrambling (encrypting) a message in such a way that it is difficult, expensive or time consuming for an unauthorized person to unscramble (decrypt) it.
Thursday, February 5, 2009
The application of 3rd party certification programme in Malaysia
One of the famous application of 3rd party certification program in Malaysia is MSC Trustgate.com Sdn Bhd. MSC Trustgate.com Sdn Bhd was incorporated in 1999 and i
s a licensed Certification Authority (CA) under the operation of the Multimedia Super Corridor. Certification Authority is the body given the license to operate as a trusted third party in the issuance of digital certificates. They also offered complete security solutions and leading trust services that are needed by individuals, enterprises, government, and e-commerce service providers using digital certificates, digital signatures, encryption and decryption. Trustgate is licensed under the Digital Signature Act 1997 (DSA), a Malaysia law that sets a global precedent for the mandate of a CA. As a CA, Trustgate’s core business is to provide digital certification services, including digital certificates, cryptographic products, and software development.
VeriSign is the leading Secure Sockets Layer (SSL) Certificate Authority under Trust.com which also enabling the security of e-commerce, communications, and interactions for Web sites, intranets, and extranets. It provides security solutions to protect an organization’s consumers, brand, Web site, and network.
Digital certificate usually attach to an e-mail message or an embedded program in a web page that verifies that user or website is who they claim to be. The common functions of a digital certificate are user authentication, encryption and digital signatures. User authentication provides other security than using username and password. Its session management is stronger. Encryption can make the data transmission secured by using the information encrypted. The intended recipient of the data is only person to receive the message. Digital signatures are like the hand signature in the digital world. It can ensure the integrity of the data.
By using the digital certificate, the users will be able to make transaction on the internet without fear of having the personal data being stolen, information contaminated by third parties, and the transacting party denying any commercial commitment with the users. Furthermore, the digital certificates can assist the development of greater internet based activities.
With the increasing of phishing on the internet, customers want to make sure that whether they are dealing business with a trusted party. They are afraid of their personal information such as ID number, passwords, credit card numbers and so on, will be sent to those companies which do not exist in this real world. Thus, the certification from 3rd party is needed to ensure their information traveled over the Internet reaches the intended recipients and is safe. Most of the banks in Malaysia will show their verified certificate on their online banking website to avoid phishing.
Lastly, by applying that 3rd party certification, there are more secured for online shopping, so that the customers can shop safely.
Tuesday, February 3, 2009
How to safeguard our personal and financial data
Nowadays, most people rely on computers especially the Internet to create, store and manage critical information. But the Internet is no longer a safe place. Information transmitted over the Internet is more vulnerable and has a higher degree of security risk than internal networks because they are open to anyone. Hackers have ability to intercept and use that information, such as credit card numbers and expiry dates, to falsely do transactions. Therefore, protecting yourself from predators and theft on the Internet is very important to prevent our privacy information from exposure. The following are some suggestion to safeguard our personal and financial data.1. Password Protection
Do not choose a password and PINs that is easily guessed, like your telephone number, date of birth, IC number, or other associated data. You should select a robust and unique PINs to make it difficult for anyone to guess. Do not use sequential numbers (e.g. 123456) or the same number
more than twice (776790). Do not share or divulge your password to anyone. Memories your password. Do not write down your password or store it in computer hard-disk, diskette, mobile phone or other insecure means. Do not use your password when someone else can see you keying it in. Change your PINs regularly. Change your password immediately if you suspect it has been exposed to others or the moment you suspect any unauthorized access to your computer.
2. Always log off your online session
Log off your online session whenever you leave your computer, even for a short while. This immediately ends yours iBanking session and prevents further transactions from being when not carried out without a fresh login. You should also shut down your computer, when not in use, to prevent unauthorized access to your computer.
3. Do not disclose your personal data to suspected websites
To prevent your personal information frodisclose your m being captured by bogus websites, you should not disclose your personal, financial or credit card information to little-known or suspected websites. The best way to protect our financial and personal data is by conducting the transaction with trusted, well known online retailers that using the reputable payment processors like Paypal or Google Checkout.
4. Protect your computer from viruses and malicious programs Apart from destroying important data on your computer, viruses or malicious programs such as Trojan Horse may run a password sniffing program in the background to capture your password keystrokes without your knowledge. Being constantly online may increase your risk exposure for your computer. To avoid getting infected, you should:
- Never download any file from sites (e.g. program, game, picture, mp3 song) or people (e.g. email attachments) that you aren't sure about.
- Delete junk or chain emails.
- Never use features in your programs that automatically get or preview files.
- Install firewall and virus detection software to protect against hackers, virus attacks or malicious "Trojan Horse" programs. You should also update your software's virus definition frequently.
5. Check your account and transaction history details regularly Always check your transaction history details and statement regularly to make sure that all details are updated and there are no unauthorized transactions on your accounts.
Phishing: Examples and its Prevention Methods
The act of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that may be used for fraud or identity theft. The e-mail directs the user to visit a Website where they are asked to update personal information such as: passwords, credit/debit card info, Social Security number, and the credit union/bank account numbers that the legitimate organization already has. The Website, however, is a spoof and set up only to steal the user's information.
Examples phishing:
1) Phishing e-mail from TrustedBank:
An example of a phishing e-mail, disguised as an official e-mail from a (fictional) bank. The sender is attempting to trick the recipient into revealing secure information by "confirming" it at the phisher's website. Note the misspelling of the words received and discrepancy. Such mistakes are common in most phishing emails.
2) An example of a phishing e-mail targeted at PayPal users:
In an example Paypal phish (right), spelling mistakes in the e-mail and the presence of an IP address in the link (visible in the tooltip under the yellow box) are both clues that this is a phishing attempt. Another giveaway is the lack of a personal greeting, although the presence of personal details would not be a guarantee of legitimacy. A legitimate Paypal communication will always greet the user with his or her real name, not just with a generic greeting like, "Dear Accountholder." Other signs that the message is a fraud are misspellings of simple words, bad grammar and the threat of consequences such as account suspension if the recipient fails to comply with the message's requests.
3) An example of a scam email from Citi Bank:
ISPs, banks, etc. do not ask for passwords and the like to be entered by email. Be suspicious of any email message that asks for personal information. Don't ever follow a link in an email that asks you to update or verify sensitive information. If you want to contact a company, go to their Web site by using a link from your records or telephone them. How to avoid falling for a Phishing (fishing) Scam?
Most of the case of phishing are related to your bank account number ,password ,credit card detail information, social security card number and your e-currency account information .Some of the latest phishing are related to you paypal ,yahoo mail ,gmail and other free mail service .Just to keep in mind none of those official company mentioned above will ask you to provide any information via e-mail .If you receive the similar request to ask you to provide the detail or link to the web site in that mail ,it must be internet phishing scam.
Phishing Prevention Methods:
1) Do not reply to or click on a link in an e-mail that warns you, with little notice or prior legitimate expectation that an a account of yours will be shut down unless you confirm your billing information. Instead, contact the company cited in the e-mail using an authenticated telephone number or other form of communication that you sure is genuine.
2) Legitimate companies, especially financial institutions should never ask you to verify your account information. If you get an e-mail that asks for this type of information, delete it and report it to the company being phished.
3) Before submitting financial information through a website, look for the locked padlock on the browser’s status bar or look for http:// at the beginning of the web address in your browser’s address window. The presence of a padlock and the http:// does not guarantee that the website is legitimate or secure. However, the absence of either the padlock or the http:// does indicate that the web site is not secure.
4) Identifying a phishing e-mail may be easier than it appears. Sometimes, the entire e-mal is a graphic which may be a sign. If you cannot highlight words, then you know it’s a graphic, sometimes with a link. Also, if you hover your mouse over graphic or other link, you can usually view the actually link (at the bottom of your screen or a hover line). The link may be something else than it actually says in the e-mail. If you do click on the graphic or link, check the url to make sure it actually is from the domain of your financial institution.
5) Use anti-virus software and make sure you have a firewall in place.
6) Review all financial statements (online or paper) as soon as you can so you can see if any unauthorized
7) Never send e-mail with sensitive personal or financial information. E-mails are not secure. Visit official websites and login securely to send this type of information.
8) Always be aware of attachments in e-mails. Never open an attachment from someone you do no know. This could contain a potential virus.
9) Always make sure your web browser contains the latest patches. Newer browsers will eventually contain anti-phishing features to help you even more.
10) NEVER click on a link in an email in order to enter your log-in information or password. Instead, if you think the email may be legitimate, go directly to the company website using your Internet Explorer or Netscape browser. (Do not copy and paste a url address out of a suspicious email.)Hackers can easily mask a fake link, making it look like it is going to the proper site when it is not. Instead, type the link into your browser window by hand.
11) Learn your financial institution’s security measures. PayPal, for example, will never send you an email that does not begin with your full name. If you receive an email with a salutation like, “Dear PayPal Member” you know it is a fake.
12) Monitor your credit rating closely. Keeping a careful eye on your credit score is the best way to learn if you have fallen victim to an identity scam. An ID Theft protection product from MyIDFix.com can alert you to identity problems immediately so that you can fix them before they get out of hand.
