01 Mar 2011
Hackers are increasingly concentrating on attacks using social networking sites and techniques, and the industry needs to respond in kind, according to Cisco.
Tom Gillis, vice president and general manager of Cisco's security division, said at the DEMO 2011 conference that a recent attack on his company showed how social techniques are being used to get around security systems.
Gillis explained that Cisco tried using an image captcha to defeat automated Koobface attacks. This worked for 48 hours until the attackers set up a network of contractors who inputted the captcha data in exchange for electronic currency.
The attackers then set up a script to run on infected machines requiring the user to input captcha details or face a system reboot.
Cisco is also seeing a much higher number of targeted attacks against its employees and customers, using high-quality faked LinkedIn pages to gather data on key staff. These targeted attacks have much higher success rates than general malware spam.
"2010 was the first year that spam volumes went down. Spam went from spray and pray, with up to two billion emails being sent out on a campaign, to something much more targeted. You can get very high response rates to a legitimate-seeming profile," said Gillis.
Cisco is responding with similar tactics by crowdsourcing threat research. As more Cisco devices report suspicious activity the company can analyse patterns of traffic and use them to shut down malware command-and-control servers.
"You have to fight social with social," Gillis said.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Java Deveoper/Programmer/Software Engineer, Algo Trading...
Austin Fraser has the pleasure of appointing a number...
Austin Fraser has the pleasure of appointing a Java Developer...
Austin Fraser has the pleasure of appointing a Senior...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?