02.11.2014 Views

untangling_the_web

untangling_the_web

untangling_the_web

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

DID: 4046925<br />

UNCLASSIFIEDNFeR eFFIOIAL l:JSE ot.LY<br />

. "Welcome to CitF' message will remain even if user enters new<br />

I FAo Edit V_ FIMO~<br />

I .,.. i , ...... '!i) Jl ~I ~~d opens new ~ebp~e._ _ _ _ ..<br />

1A,gure-u I@J J;1tp::. I/<strong>web</strong> de-us cihh"nk C:r)m/~~rmkihh/SA;ripl':s.!"m')ILverify i&1J<br />

:3 -..r?' Go<br />

ci'ti"<br />

Faked address is live JavaScript;<br />

Note <strong>the</strong> "https:/I"<br />

II by submlUng yo",.'og.ln Informallon.<br />

ATMlD~b,t C~Hj<br />

(ON) I Card II<br />

PIN<br />

r--<br />

Note <strong>the</strong> use of Citi logos and copyright<br />

Ame'11berof ~"':'<br />

CltlgrouR Pll'iJiW Pt:Ofni£il<br />

r.lITiS&' Conditions<br />

. p d, t'l '" -r.'1:'" t' 'i~,l;<br />

cffi<br />

CJILto",<br />

Note absence of SSL (locked padlock)<br />

l<br />

" Internet<br />

There is a worrisome refinement of <strong>the</strong> traditional phishing attack that gained a lot of<br />

attention beginning in 2005. Spear phishing is exactly what it sounds like: precisely<br />

targeted phishing attacks that try to lure users to provide personal data by cleverly<br />

conceived social engineering strategies. Instead of <strong>the</strong> blanket approach of sending<br />

thousands (millions) of emails blindly, spear phishing carefully selects its audience<br />

and targets <strong>the</strong>se users with very legitimate-sounding emails. For example, one<br />

spear phishing attack targeted students and faculty at <strong>the</strong> University of Kentucky.<br />

Spear phishing emails typically appear to be coming from a trusted source: your<br />

company's HR or IT department or your own little credit union. Also, a spear<br />

phishing attack may try to sound as if your security is at stake, e.g., you have been<br />

locked out of your account because of unsuccessful attempts to break into it, and in<br />

order to unlock your account you will need to reenter your personal information.<br />

Fake spear phishing emails have even been used to educate people about <strong>the</strong><br />

dangers of spear phishing. "In June 2004, more than 500 cadets at West Point<br />

received an email from Col. Robert Melville notifying <strong>the</strong>m of a problem with <strong>the</strong>ir<br />

grade report and ordering <strong>the</strong>m to click on a link to verify that <strong>the</strong> grades were<br />

correct. More than 80% of <strong>the</strong> students dutifully followed <strong>the</strong> instructions. But <strong>the</strong>re is<br />

552 UNCLASSIFIEDhTeR eFFIelAL USE eNL\'

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!