By Jennifer LeClaire TechNewsWorld Part of the ECT News Network
11/29/05 7:43 AM PT
The good news is cybercrimes targeting businesses are at their lowest level ever, according to the Computer Security Institute (CSI). The annual CSI/FBI Computer Crime and Security Survey noted that the average loss per cybercrime incident in 2005 was about US$250,000.
eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.
One visit to the Computer Crime and Intellectual Property Section of the U.S. Department of Justice's Web site offers an eye-opening glimpse into the world of cybercrime.
Case after case details how the Feds are cracking down on cyber-criminals, defendants are pleading guilty, and the judged are being sentenced to prison.
Out of Control
Despite aggressive law enforcement efforts, however, experts say cybercrime is growing at a rampant pace; a pace that rivals drug trafficking.
Cybercrime includes such illegal activities as child pornography, stock manipulation, software piracy, and extortion -- and security experts expect those activities to multiply as technology becomes more pervasive in developing countries.
"Last year was the first year that proceeds from cyber crime were greater than proceeds from the sale of illegal drugs, and that was, I believe, over US$105 billion," Valerie McNiven, who advises the U.S. Treasury on cybercrime, told Reuters recently. "Cybercrime is moving at such a high speed that law enforcement cannot catch up with it."
Phishing for Phishers
One practical example is phishing. Security experts said phishers, those who use fraudulent e-mail and fake Web sites to gather sensitive personal information from users, typically run their scam for 48 hours or less before moving on to the next ploy.
StillSecure Chief Strategy Office Alan Shimel told TechNewsWorld that phishing is a prevalent problem -- and one of the leading means for cyber-criminals to dupe victims.
"There are two ways organized crime groups get data: one name at a time through phishing scams or the wholesale method whereby they break into credit card processors and grab confidential information by the tens of hundreds of thousands," Shimel said. "There is no silver bullet that will solve phishing, spam, zombies, worms, Trojans and the like."
Beyond Phishing
Victimizing individuals is one level of cybercrime. Victimizing companies is another. Software piracy makes up a huge percentage of the cybercrime reported today. The Business Software Alliance reports that 35 percent of the software installed on computers is pirated. That represents a loss of nearly $33 billion to the software industry worldwide.
The good news is cybercrimes targeting businesses are at their lowest level ever, according to the Computer Security Institute (CSI). The annual CSI/FBI Computer Crime and Security Survey noted that the average loss per cybercrime incident in 2005 was about $250,000.
That compares to $500,000 in 2004 and more than $3 million in 2001. Increased demands on corporations to comply with rules and regulations like the Sarbanes-Oxley Act are partially credited.
Portable Devices Used Illegally
Then there's pornography. One of the latest trends with this old-fashioned crime is using handheld devices, like cell phones, PDAs and portable MP3 players, to transfer images of child pornography.
In fact, portable devices are becoming a useful tool for cyber-criminals, according to a report from Purdue University's Center for Education and Research in Information and Security. A report entitled "iPod Forensics" authored by cybercrime expert Dr. Marcus Rogers notes that the criminal element is finding alternative uses for the popular devices.
Protecting Corporate Assets
Will cybercrime continue to run rampant? Can corporations protect themselves? StillSecure's Shimel said the only way to stop this sort of crime is through layered security.
"You really need a layered model. It's a defense in-depth attitude," Shimel said. "You can put solutions in place to manage your risk, to reduce your risk, but I don't know if you can truly eliminate risk in today's environment. It seems the mouse just continues to get smarter."
Curious Moves on the P2P Playing Field November 29, 2005
Eminently affordable, easily and quickly downloadable, digital movies made by the next wave of indie film makers, coupled with 21st century online distribution techniques, represent the kiss of death for Hollywood.
Related Stories
StillSecure CTO Outlines Biggest Network Security Vulnerabilities November 08, 2005
TechNewsWorld recently caught up with StillSecure CTO Mitchell Ashley to discuss security trends of note, why some points of the network are especially vulnerable, and how companies can protect their networks from the enemy.
Report: VoIP Sets Stage for Security Appliance Surge September 08, 2005
Irwin Lazar, senior analyst at The Burton Group, told TechNewsWorld that he has not witnessed market conditions that resemble what In-Stat is describing. In-Stat's report that 75 percent of companies that have implemented VoIP plan to replace their security appliances within the next year is optimistic, he said.
Report Suggests Security Software Attacks Increasing June 21, 2005
Yankee Group recommended quality assurance and penetration testing measures such as reviewing security designs early and often; integrating security tests into regular software builds; reviewing code base; and truly simulating the tactics of an attacker.
Companies Not Keeping Up With Network Security Needs June 21, 2005
Vernier President and CEO Simon Khalaf said that the survey revealed some "shocking" findings about companies' knowledge level about internal network security. "Companies did not realize how open their network and their systems are to attacks from within the company," he said.
Evil Twins a Menace to Wireless Security June 04, 2005
Once the wireless victim has connected to the illegitimate WiFi hotspot, the Evil Twin attacker can gain access to the user's log-on details, along with personal and confidential information that aids the attacker in identity theft and other illegal activities.
Related News Alerts
More by Jennifer LeClaire
The Digital Car: Cool Automotive Accessories, Part 2 January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.