SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Fear, greed, lust: Phishing's sure-fire lures

Fear, greed, lust: Phishing's sure-fire lures

By:  Rafael Ruffolo  On: 25 Jun 2007 For: ComputerWorld Canada Creator

A report from McAfee outlines the persuasive "mind games" cyber criminals play to get users clicking their way into an IT security breach. Experts discuss the right way to train your staff

IT professionals may want to give their staff a refresher course on phishing attacks.

In a recent study, McAfee outlined the increasingly persuasive nature of phish attacks and the psychological “mind games” that cyber criminals use to trick their prey. The study said scammers play up to users’ emotions, using fear, greed and lust to ultimately steal personal and proprietary financial information. McAfee found the most important key to an Internet scammers’ success is creating the illusion of legitimacy and familiarity.

“The technique we’ve seen the most is mimicking another organization’s e-mail,” Jean Pascal Hebert, an account manager at McAfee, said. “Typically these are the most successful types of attack and can entice an individual to release information they should not be releasing.”

Hebert said that more education is needed to combat these sophisticated attacks, but some security experts say this will take a major change in the training process to succeed.

Rohit Sethi, manager of Security Compass, said that most IT managers have failed to provide interactive training to their staff in order to help them understand the fundamentals of phish attacks.

“A lot of times what you’ll have in an organization is an IT professional who understands the subject matter expertly, but they don’t have an understanding of how to train properly,” Sethi said. “So they’ll stand in front of their users and say – ‘don’t do this and don’t do that’ – and a lot of times users won’t pick up on it.”

Sethi said that traditional training strategies neglect to demonstrate how a user’s computer can be compromised and why the data leak occurs. He said that taking the time to develop this base understanding will allow users to apply their knowledge and adapt to future phishing attempts.

“A lot of companies will use a checklist approach, where you have somebody trained and, therefore, they can sign off and say that they’re trained,” Sethi said. “It follows policy, but they don’t really end up measuring the effectiveness of the training, so we’ll see a lot of [IT managers] frustrated with the effectiveness of their training and user awareness.”

Sahba Kazerooni, security consultant at Security Compass, sees most training policies as a substitute for competence, and in turn, makes users increasingly ineffective to changing phishing attacks.

“A SANS Institute top 20 list of vulnerabilities that effect Internet security, now has users listed as a threat for the first time,” Kazerooni said. “This has kind of led to the whole idea of phishing, all of a sudden, being a much bigger threat than it has been in previous years and users becoming a much bigger threat to IT security.”

Hebert agreed, saying that IT managers should take the time to develop internal campaigns to teach their users. He also said that implantation McAfee’s free SiteAdvisor tool, which flags potential danger sites, is one of the first steps that companies should take to help “lock the front door.”


Sign up for our Newsletters












Print |  Views: 840   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Rafael Ruffolo Rafael Ruffolo was a senior writer for ComputerWorld Canada from 2006 to 2011. He was the winner of a Kenneth R. Wilson award for business journalism in 2009.

Related Content

CWC View: It's still the Wild, Wild West
CWC View: It's still the Wild, Wild WestSome of you might know the name Michael Calce, but most of us will remember his alter ego, Mafiaboy, for a long, long time.
Malware attackers picking their targets
Malware attackers picking their targetsAlthough the number of known viruses kept growing at a steady pace, 2006 witnessed a remarkable step down in the volume of visible attacks by worms, viruses and other malware, according to F-Secure Corp.’s Data Security Wrap-up Report for the second half of 2006. At the same time, however, targeted attacks using backdoors, booby trapped document files and rootkits became increasingly commonplace.
Bloggers vulnerable to embedded malware, expert says
Bloggers vulnerable to embedded malware, expert saysInternet users who employ Web-based services such as Bloglines or Web browsers such as Firefox to read Web site feeds and blogs are vulnerable to embedded malicious code that can install spyware, log users' passwords, scan PCs and corporate networks for open ports and more.
BlackHat USA 2008 - Day 2 Review
today was the second and final day of the blackhat usa briefings. a lot of great content was presented today. much like yesterday we’ve included some highlevel comments on the various presentations that tadd and i attended. we will be attending defcon over the weekend and tying that into one final posting next week. what follows is our summary.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.