Monday, January 12, 2009

Technology can’t prevent Identity Theft

The Wall Street Journal recently published an article (LINK HERE) explaining the problems that exist when we depend on technology to solve social problems. It is a good article and has links to some of the more famous identity theft attacks that have happened recently, including the Barrack Obama twitter hijack listed below. It even lists some of the more basic criminal tactics I have never really classified as identity theft such as

1) Impersonating parking lot attendants to collect fees
2) Impersonating garbage men to collect tips
3) Impersonating people like policemen, security guards and meter readers

The reason I bring this article up, is it reminds me of a white paper I read for my technical review as part of my preliminary exam. The paper was titled “Detecting Social Engineering” and it talked about this method which would allow a computer to analyze a phone conversation and determine if one of the two callers is not telling the truth.

The first way of doing this, comparing the information received to information in a database made sense, but the second method used “natural language processing techniques” to determine if a person is lying. This piece was the part where I felt it start to go into a fairy tale. I find it hard to believe that there is software that can take a text conversation and pick out what are lies in it. Computers don’t have the ability to “think” like humans (yet) and until they do, they can’t be expected to solve a human problem.

I believe the solution to problems such as Identity Theft or Social Engineering do not lie solely in technology or human education, but is some combination of both.

Nate Evans

Labels: , , ,

Wednesday, June 25, 2008

An interesting Social Engineering Example

This is a very interesting story posted on CIO insight involving social engineering:

Every few days, Richard would seek out Sally, a twenty-something salesclerk at a retail outlet of a telecommunications conglomerate. When they first met, Richard, who’s in his early 30s, said he was the manager in charge of buying telecom equipment for a fast-growing startup, and he did, in fact, make a purchase on each visit.

Richard and Sally became friendly, and after a month, he took her out to lunch and confessed, “You’re a nice woman, but I’m not interested in you as a friend. I’m on a secret mission from the CEO of your company, and we need your help.”

He explained that a midlevel manager had been stealing trade secrets from the company, and they needed Sally’s help to replicate the methods they thought the manager was using. Sally had access to a PC that was connected to the corporate network, and Richard told her how to retrieve confidential files. He swore her to secrecy, telling her that only the CEO, a vice president, Richard and now Sally knew of this operation.

What Richard didn’t tell Sally was that this was all a lie: He actually worked for her company’s rival. Unwittingly, Sally became a corporate spy for the competition and began dutifully relaying files to a secret e-mail account.

A few weeks later, Richard told Sally that the vice president wanted to meet her at a restaurant. When they arrived, Sally saw the executive sitting at a table across the room with a man she didn’t recognize. Richard walked over to their table and, out of Sally’s earshot, began chatting with the companion. Unbeknownst to the VP, the man was an agent who was working with Richard and had arranged to meet the VP at the restaurant.

Richard soon returned to Sally and told her the VP had had second thoughts about meeting in public for fear it could jeopardize the operation. He said the VP wanted to recognize her cooperation, so Richard asked Sally to glance over at the VP. When Sally turned toward the executive, she could no longer see Richard, who then waved to the VP. The executive waved back, and Sally assumed that he was acknowledging her.

Weeks passed, and Richard gave Sally a $15,000 bonus as part of the “anti-fraud team.” Months later, he gave her a $30,000 bonus. She was hooked and would do anything Richard asked.

Eventually, Richard told Sally the truth. Though shocked and dismayed, she was too deep into the scheme to back out.


Do you think this could happen to your company?

Nate Evans

Labels: , ,

Wednesday, May 28, 2008

Cramming

I recently came across a very interesting article on “cramming.” Cramming is when a “scamming company” gets a hold of your phone number and bills you for a variety of services such as voicemail accounts, call waiting, etc.

For example, the author of this story got “crammed” when his wife signed up to win a free Vegas Vacation on one of those online popups. He suddenly had a bill for 4 voicemail accounts on his AT&T bill. AT&T can’t remove the charges as the phone companies just pass charges through (similar to how collect calls work). There is no authentication involved, all that is needed is a phone number. Meaning if I entered your phone number into this form, you would be billed 14.95 a month X3 for three new voicemail services.



The FTC states that you should:
1) Call the company and request that they refund your money.
2) Call your telephone company and see their policy for this
3) File a complaint with the FTC

None of the following guarantee you get your money back. My experience with a recent scam has been that the company does not have a real phone number, or no one ever picks up. The Phone companies, or Credit Card Companies can usually block charges but will rarely do so each month (meaning you need to call them each month). And a complaint with the FTC will get resolved in the usual government fashion... slowly.

To read more, including a couple scripts on his calls: http://arstechnica.com/articles/culture/cram-this.ars

Overall I would recommend that everyone be diligent online. Use common sense (A free Vegas Vacation is too good to be true) and check your bills carefully!

Nate

Labels: , ,

Tuesday, January 15, 2008

Employee anger almost causes problems for company

Before I jump into my story, I wanted to introduce myself. Michael McCoy honored me by asking if I could contribute to this blog. My name is Nate Evans and I am a PHD candidate at Iowa State University in computer engineering. My research expertise is in an area very close to identity theft, social engineering. In some ways you could classify identity theft as a small piece of social engineering, but I don’t want to step on anyones toes here! I currently am working on my dissertation and am employed part time for the Walt Disney Company and The Krell Institute.

So in short, expect stories from me involving people ripping other people off.

When people define social engineering and try to explain the problem about it, they normally start with something like this:

“You can spend millions of dollars building a super secure computer system, but if the system admin sells his pass for $1,000, your system is now worth $1,000.” What if the system admin does not sell the password but instead uses it against the company to destroy or sell company data? This brings me to my story.

Recently a 51 year old administrator, Andy Lin, was given 30 months in jail and fined $81,200 for trying to destroy a medical drug database in a company he was employed with.

Way back in 2003, Andy learned that his company, Medco, was going to lay people off and he wasn’t sure he would survive the layoffs. In a fit of anger, he decided he would make the company pay by writing a script to delete everything in the company’s database. The script was set to go into effect automatically on his birthday April 23, 2004.

Well a couple weeks rolled by and Andy did not get laid off. As such he attempted to edit the code to make it ineffective. He failed and on April 23, 2004, the code deployed anyway.

Luckily the code contained numerous bugs and his program just crashed. Andy, still the cautious type, fixed the bug and reset his doomsday timer to the April 23, 2005.

Fortunately for the company, another System Admin was looking into this odd crash and found Andy’s code. On January 2005, Andy was arrested and pleaded guilty to one count of transmitting computer code with the intent to cause damage in excess of $5,000, and he was sentenced last week.

Its amazing how much damage one employee could do to a company. If that database was deleted the company would be in massive trouble. Imagine if the employee, instead of destroying it, sold it to the competitors...

You could take one of two lessons from this: Either don’t trust people, or pay your system administrators more!

Nate Evans
ISEAGE PBS Leader
The Krell Institute

Labels: , , , , , , ,

  • All Material is Copyright © 2009 Michael McCoy and SEAS, L.L.C
  • Deter. Detect. Defend. Avoid ID Theft - www.ftc.gov/idtheft