• Tidak ada hasil yang ditemukan

CyberSecurity Malaysia | An Agency Under MOSTI

N/A
N/A
Protected

Academic year: 2017

Membagikan "CyberSecurity Malaysia | An Agency Under MOSTI"

Copied!
37
0
0

Teks penuh

(1)

BRIDGING BARRIERS:

LEGAL

AND

TECHNICAL

OF

CYBERCRIME CASES

(2)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

AGENDA

Fraud Ecosystem

Crimeware You Can Afford

Wildfire Infection

(3)

The Shift in Threats

From amateur virus writers to organized

money making professionals !

Virus

Worm

Internet Trojan

(MITM / MITB)

Phishing

Spyware

Spam

2005

2000

2003

2004

2010

Mobile

Threats

(4)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

The Enemy has Changed

Script Kiddies

Chen-Ing Hau,

24

(author of CIH virus)

Joseph McElroy, 16

(Hacked into Nuclear US Lab)

Jeffrey Lee Parson, 18

(5)

Professionals

Ehud Tenenbaum

The Analyzer

Albert Gonzalez

TJX Hacker

Andrew Schwarmkoff

Russian phishing mob

(6)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(7)

Technical

Infrastructure

Cash Out 

Fraudster 

Fraud Eco System

Harves-ng 

Fraudster 

Opera-onal 

Infrastructure 

 

Communication

Fraud forum / chat room

User Account

(8)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(9)
(10)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Air Parcel Express: Truly Global

(11)

High Grade Trojans

(12)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(13)

Trojans

Drop

(14)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

AGENDA

Fraud Ecosystem

Crimeware You Can Afford

Wildfire Infection

(15)
(16)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Zeus 2.0

Most popular Trojan Kit ($3,000)

Feature 

Zeus 2.0 

Polymorphism 

  

HTML Injec-ons 

  

MITB capability 

  

Documenta-on 

(17)
(18)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(19)
(20)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(21)
(22)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(23)
(24)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(25)
(26)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Next Frontier: Mobile Trojans

Man-in-the-Mobile – SMS Bypassing

`

U s er

$

B ank

Phishing for mobille

(account ID/pwd)

Hacker capture

credentials

Login attempt

One Time Password

(OTP)

Sent

OTP Forwarding

Successful Login

(27)

Trojan Infrastructure

Command & Control

Bot-Herder

Infection / Update

Drop Zone

Bulletproof hosting,

unlimited

(28)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(29)

AGENDA

Fraud Ecosystem

Crimeware You Can Afford

Wildfire Infection

(30)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(31)
(32)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Cost of infection and hosting

(33)

AGENDA

Fraud Ecosystem

Crimeware You Can Afford

Wildfire Infection

(34)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Advanced Persistent Threats

Cybercrime Reborn

1980-2010

2010-2020

Aurora (Jan 2010)

Defense, Critical Infrastructure,

Media, Finance, Internet

Night Dragon (Feb 2011)

(35)

Advanced Persistent Threats

35

(36)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Recent Spear-phishing against a

(37)

Q & A

Contact:

Referensi

Dokumen terkait

Penceroboh juga boleh mencuri identiti pemilik akaun dan melakukan apa sahaja dengan akaun yang dicerobohi seperti membuat post , comment dan menghantar mesej atas nama

PayPal accepts money from the purchaser by credit cards, debit cards or from. the purchaser’s bank

Conventional warfare and space warfare are expensive whereas cyber warfare is cheap.. It is also accessible to many groups

One of the management responsibilities in ensuring the effective implementation of Information Security Management System (ISMS) in organization is by setting up an

SimWorks Anti-Virus (www.simworks.biz/sav/AntiVirus.php?id=home) reported that this trojan horse combines several malicious mobile phone programs that work to spread

Antara ciri-ciri penggunaan telefon pintar adalah menerima dan membuat panggilan telefon, menjadi Pembantu Digital Peribadi (PDA) untuk membuat temu janji dalam kalendar,

Approved cryptographic lightweight algorithms are as in ISO/IEC 29192: Information technology -- Security techniques -- Lightweight cryptography standards.. ISO/IEC 29192-2: 2012

In information security, assurance means confidence that the organisation is protected against security threats, confidence in the implementation of security controls, and