Slashdot Log In
Cybercrime Is a Franchise Model That Scales
Journal written by Presto Vivace (882157) and posted by
kdawson
on Fri Apr 11, 2008 12:08 PM
from the maybe-it-pays-after-all dept.
from the maybe-it-pays-after-all dept.
Presto Vivace notes a report from the RSA conference on the cybercrime economy, and it's not an optimistic one. Part of the problem is that in many places cybercrime pays much better than legitimate work, including security research. "As the panelists explained, a single spam message might be tied to as many as 10 separate organizations and perhaps five suppliers. Every task in the criminal economy has become a separate specialty. Some people sell e-mail lists, others sell lists of compromised IP addresses, there are sellers of credit card numbers, and those who sell access to bot nets. Then there are those who handle product fulfillment for spammers, and those who specialize in laundering money."
Related Stories
[+]
Cybercrime Organizational Structures Evolve 70 comments
An anonymous reader writes "The latest findings of a report explore the trend of loosely organized clusters of attackers trading stolen data online being replaced by hierarchical cybercrime organizations. These organizations deploy sophisticated pricing models, crimeware business models refined for optimal operation, crimeware drop zones, and campaigns for optimal distribution of the crimeware. These cybercrime organizations consist of strict hierarchies, in which each cybercriminal is rewarded according to his position and task."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Office Space clearly had an impact (Score:5, Funny)
Re:Office Space clearly had an impact (Score:5, Insightful)
The hard part is getting it out of the country of origin, without it being linked to you as having "left" from you.
Parent
Re: (Score:3, Funny)
Re: (Score:2)
Once you have a million dollars, you have to bring that money back INTO the US to buy that house and car, and with no legal income, that is what raises a red flag with the IRS, and the FEDS, who monitor all money transactions over $5,000 now (used to be 10k before 911). You can still make the money, but you can't spend it.
The traditional way is to open a "legit" biz with high
Re: (Score:2)
Corporate purchases are watched pretty carefully, especially offshore stuff. They're actually really easy to track weird spending habits. How often do companies spring up out of nowhere, and suddenly start having hundred thousand dollar offshore contracts every few months (or a hundred thousand spread out over a year, still suspicious).
Re: (Score:2)
Re: (Score:2)
You mean like these folks did [wgal.com]?
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Cut of the source (Score:4, Insightful)
Re:Cut of the source (Score:5, Insightful)
The ultimate responsibility for what happens on someone's computer is theirs. There's a lot of hatred for Microsoft floating around here, and for good reason, but holding them responsible because people can't protect their computers in the most rudimentary ways is wrong. It also opens the doors for holding any software responsible for any hacking that occurs on them, even if the user could have prevented it with negligible effort. Considering the state of security in the software industry, that would destroy pretty much every company in existence and set us back 10-20 years.
Parent
Re: (Score:2)
Microsoft never claimed to be completely secure? Probably all the sale speech for all Microsoft products (since windows 95 or before) includes some kind of claim regarding security (usually in the form of "this is safe, anything else is not") And probably the security experts aren't the main customer base of Windows, normal people only know that it says that
Re:Cut of the source (Score:4, Interesting)
Parent
Re: (Score:3, Interesting)
Not all, but most definitely are:
- Unpatched Windows XP (and below) PC's
- patched but already infected Windows PC's
- patched but rootkitted Windows PC's
- patched Windows PC's just infected this week with a zero-day exploit.
So the rest of the botnets would be shared webservers running insecure PHP bulletin boards, and servers running unpatched MS SQL, but these are a tiny fraction.
As you can see, Microsoft's greed is largely responsible for most of
Re: (Score:2)
Re: (Score:3, Funny)
If you want to actually execute it, you have to:
1 - save it to disk
2 - change its permissions
3 - then (and only then) execute it.
It is preferable to force a command line session (terminal window) for step 2, with a "difficult" sequence. Say.. chmod +x CutePuppies.exe. And it should show up on the desktop either...
No "is this allowed?" dialog. No "please enter your password" dialog. Just.. don't.. execute.. it.
I would even go so far as to for
Re: (Score:2)
What fantasy land do you live in? http://www.symantec.com/avcenter/attack_sigs/s22902.html [symantec.com]
http://www.securityfocus.com/news/11511 [securityfocus.com] Concerning the Flash Vuln
http://www.securityfocus.com/news/11512 [securityfocus.com] How fully patched Vista box owned due to the flash vuln, with little to no user interaction.
When an attack exploits a weakness in something running on the system then in essence CutePuppies.exe may not run without interaction, but CutePuppie
And my mother always said that (Score:5, Funny)
BRB, watching to see if the kettle boils.
Re: (Score:2)
Re: (Score:2)
For those who don't get it, Randall, the guy on the left, writes XKCD, and the guy on the right is me (check out the name badge, infidels).
Off course (Score:2)
There are after all established concepts of taxes, payday loans and patents that pretty much amount to the same thing.
Re: (Score:2)
Is pay really the reason? (Score:5, Insightful)
Crime almost always "pays better" than so-called legitimate work (is crime really considered a profession?) Well I guess you could say it is a part of the problem, but the OTHER part of the problem is the risk of getting caught is too low. It is a risk/reward model. There are other factors in play here too, for example people's morality. Even if there were little risk and great reward, some people have a moral system that would still prohibit them from undertaking a life of crime.
Re:Is pay really the reason? (Score:4, Insightful)
Parent
Re:Is pay really the reason? (Score:5, Insightful)
Parent
Re: (Score:2)
So who decides who is a crook and who is not?
We The People.
In the perfect world, we would have a working democracy and organizations like RIAA would be legally disbanded and their money redistributed to their victims (such as artists) or used for worthwhile social programs. Unfortunately, we have a two-party system that stacked the rules to prevent election of grass-root candidates. Truly courageous people should join an uprising to restore working democracy. But in the meantime, stealing some money out of the system to weaken it's power can also be
Re: (Score:2)
1. Stealing from the "rich", (theoretically).
2. Giving to the "poor", (theoretically).
3. Discerened by the angry mob.
4. Done on the basis that people have a moral right to what other people earn.
Sounds a lot like Communism to me, and we all know how well that worked out.
Re: (Score:2)
Obliviously men with small penises or low libido and women with small breasts.
Re: (Score:2)
Re: (Score:2)
Robin Hood Rich/Poor Dichotomy (Score:2)
Re: (Score:3, Interesting)
>>> Can they save any for a rainy day, or would that make them no longer poor and ineligible for the next payout to the poor from Robin Hood?
If you're a medieval peasant (probably a serf) given enough money to buy a sack of flour you won't go hungry for a few weeks. You'll still be in need, with more money you could buy vegetables, more still you
Re: (Score:2)
Clearly we lack the mechanism to set consistent rules in "fair, non-authoritarian fashion by a group process".
Re: (Score:2)
In fact knowing a lot of this makes you a lot of money consulting people and companies wanting to do such a thing.
Re: (Score:2)
Crime really is a profession. The "criminal world" is in reality just the free market at work. There are services that people want performed and there are those who perform the service. Like a lot of laws, most of the computer trespass laws are there to protect stupid/uneducated people from themselves. They are there to protect those people from "being taken advantage of" by others. Of course in
I don't get it... (Score:2)
Re: (Score:3, Interesting)
Re: (Score:2)
Re: (Score:2)
The real mechanism at work is capturing credit card data.
That's the thing, though... if all they're after is credit card info, why bother with product fulfillment? That's what TFA referred to as one of the parties involved, so there's got to be more to it than just that. And wouldn't credit card companies figure out the statistics pretty quickly if a particular customer of theirs has a really high percentage of credit card numbers that end up being used fraudulently?
That makes me think that those stealing card numbers and/or personal data aren't bothering with p
Economies of scale (Score:3, Informative)
The problem: FBI Baltimore (Score:4, Interesting)
We need the FBI Baltimore office [fbi.gov] taken out of the business of distributing child porn and put on this problem. After ten years of work, they've arrested over 6,000 people.
How many computer criminals have they arrested? The Department of Justice doesn't seem to provide useful statistics [cybercrime.gov], but it looks like the number per year is in the 10-100 range.
This is backwards, given the relative size of the problems.
Part of the problem is that the FBI has a measurement bias against white-collar crime. See the FBI Crime Statistics [fbi.gov] page. Violent crimes are counted if they are reported; white collar crimes are only counted if there's an arrest.
Re: (Score:2)
Inciting crime? (Score:2)
Not sure how much it will scale before reaching some kind of saturation point. There are some numbers that cut in some way the amount of players in the field (like 50% of all internet spam coming from just one botnet, or malware removing other kind of malwar
And we STILL don't have a LEGAL definition of spam (Score:2)
The best we have from a judge — just quoted in a different article-submission [slashdot.org] is:
Awesome, judge, let's leave the judging to the demos... "Community standards", anyone?
Heck, according to my Firefox (2.0.0.13, thank you very much) spell-checker, the very word "spammer" does not even exist — much less legally defined. (Well, the word "firefox" does not exist e
Not just cyber (Score:3, Interesting)
In fact, society should be damned glad that most slashdotters are honest and have conscienses (no that's not spelled right, so jail me) because if most of us were dishonest we could do one hell of a lot of damage!
Some times I wish I could be dishonest, I'd be a rich man. But it's just not in my nature.
Another Part of The Problem (Score:3, Insightful)
Another part of the problem is that our cyber enforcement budget leans heavily toward pornography, gambling, and copyright.
Yet another part is that corporations and politicians are unwilling to kill their fatted calf that is "legitimate" UCE.
Remember that ancient business adage (Score:2)
In this case...online. Don't forget to get an easy to remember
I stopped being optimistic about security long ago (Score:2)
Those gigs were rarely happy ones. I came to the conclusion that there is no adequate technical solution to the security problem. Arguing that any given platform (Mac OS X, L
Re: (Score:3, Informative)