Editor's note: This is the second part of a BankInfoSecurity.com interview with Dr. Markus Jakobsson, a professor at Indiana University who is conducting research on phishing, and was originally conducted by Linda McGleeson, editor of BankInfoSecurity.com.
CUJ: So, you're saying if a consumer sees a padlock on his site, on a website, do they trust it more than one without? And, what are some of the examples you can give, and what is going wrong with SSL certification procedure?
Jakobsson: SSL is a...cryptographic technique used to secure the connection between a site and a user who connects to the site, so that nobody could tap into the conversation just by perhaps routing the traffic, and thereby learning what information is found. You don't want anybody to listen in to the credentials you've found. SSL has become one of the distinguishing aspects of whether something is a phishing site or not. Typically, phishing sites don't have SSL locks on them. But, unfortunately, this is not important, because the average consumers, they don't notice the absence of the lock. Studies that I have been part of performing have shown very explicitly that people notice the inclusion of incorrect information, like if you call them "Joe" and their name isn't Joe they immediately notice. But people won't notice the absence of material. For example, if there is not a lock at the site, then that is not so noticeable as if you have something. And that is, of course, a concern, too. For example, financial institutions like Bank of America, they rely on site keys, which is a visual mark that people would have to recognize in order to know that it is the site. And you can even deceive them by saying in an e-mail that, because of the Americans With Disabilities Act, we are now changing the image that you are going to see, and here, just below, you will find your current image. And, now, please go to this site, and the phisher would give a new image there, and acknowledge that you agree to this, but first, of course, you need to authenticate, so that we know that it is you. And that is one very bad way. But, back to the SSL. People don't notice it so much. And, people also don't notice where a lock is, if there is a lock.
Q: What are some of the educational efforts taking place to change consumers' reaction to phishing, and how effective is it, in your estimation?
JAKOBSSON: Banks have to educate their clients to some extent about phishing and online fraud, and they do it, of course. But this is dry descriptions and screen shots, and it doesn't really teach people to understand phishing. It's also not attractive enough that people feel like they want to read it. If anything, it's a little bit scary and intimidating. So, first of all, they don't necessarily target the people who need this information, and second, the presentation doesn't make it very easily digestible. And it might even be just a couple of screen shots of known attacks and not quite any instruction on how to spot versions of this or how to understand the underlying mechanism. Popular media also has a lot about identity theft. For example, Readers Digest last year carried two stories on identity theft and what to do. But these are very short and dry stories. They give a couple of suggestions like don't click on links, and all of these things that we are used to hearing. But banks do send out e-mails where you do have to click on links. So it's hard for the consumer to know what are the good links and what are the bad links, and it all boils down to understanding what is going on, and that is something that is not very well taught, in my opinion.
Also, I have, as part of my effort, developed a comic strip that you can see two panels of it in the paper that we were talking about, The Human Factor and Phishing, which is available on my webpage. This material is meant to make it very easy for the average consumer to understand important aspects of phishing and identity theft, and what to do to avoid it.
Q: In anticipating threats, you and others have been on the forefront of "thinking a step ahead" all the time. What are some of the things that you would recommend we, as banks and credit unions, do to strategically stem phishing attacks?
JAKOBSSON: Well, first of all, you need to understand trends in vulnerabilities, not only technical but human, too. And the human vulnerability (actually changes) over time, as people are educated and as new technology is introduced and penetrating the marketplace. Also, you need to understand trends in countermeasures. For example, if we, for a moment, hypothesized that the takedown becomes very, very efficient and fast, then what will happen? That means that phishers will not be able to keep their sites up for very long, and so most of their potential victims who do click on the link will be taken to the site that no longer exists, and of course, that is a great disadvantage to the phisher, and they wouldn't want that to happen. So the natural reaction to this would be for the phishers to have many sites. For an attack with a million potential victims, the phisher actually could have a million different sites, and each person who gets an e-mail would be taken to a new site, especially designed for them. Of course, this is not difficult, if you have the machines, you just zap the material on there. But what it would mean is that when the financial institution initiates the takedown, that takedown of the site that they are aware of, whether it is from the honey pot or from the bank, or one of their clients, they are not doing a takedown of any of the others, because these would be unrelated domains and sites.
Also, you would have to be afraid that keyloggers would become more common, and this is a threat that becomes very viable through games and what is called mods and screensavers, and other user-installed material. It's also called metamorphic viruses. These are just viruses that are difficult for anti-virus software to detect because it changes shape all of the time, and so the signature files that the anti-virus companies produce aren't likely to actually defend very well against it. Also, you can see as a third approach, if takedown becomes very fast, is that the phisher will just say, "Well, I'll do it through the phone, instead. I'll do phone phishing," or what some people refer to as Vhishing that comes from voice mail. And that is also the likely reaction if phishing becomes spectacularly successful, well, they just avoid e-mail.
Q: Do you recommend financial institutions also take the domain names that match existing or future potential services or features of the institution or its competitors? And how should they should handle institutions that are merging and possible misuse of domain names in that case?
JAKOBSSON: This is a good question. Let me answer this by two examples. Some time ago, Bank One was acquired by Chase. And this became a very vulnerable time to clients of Bank One, because they weren't quite aware of what Chase looked like and what the form of logging into Chase was. They weren't so sure about the URLs and all other aspects of online banking, either. So, say that a phisher would register a domain like bankonebecomeschase.com. Most people would find that rather plausible, I would argue. And so, then you take advantage of the fact that people are vulnerable, at the same time as you have an opening to use a new domain name that wasn't very meaningful before. Another thing that you could do is, if you are a bank, apart from registering these in advance, would be to look at attacks that are occurring and targeting other financial institutions. For example, there was an attack that many refer to as the Chase Rewards attack last spring, in which a lot of people got e-mails, saying "Dear Chase customer, we would like to know how you like our services, and please fill this survey, and you'll get $20 for the effort," and then it was increased to $50, and yet later to $100. And if the user took time to answer the survey, which was not of any interest at all to the phisher, they would get this reward. And of course, the way in which they would get the reward would be to log in. So, this was just a psychologically complicated way of getting to the user credentials.
Q: Going on to another question. It's been estimated that more than 10% of all networked computers run botnet software. An even larger number are still affected by various forms of malware. What would you recommend to institutions on how to battle these things that are happening?
JAKOBSSON: Well, first of all botnet is a type of malware that is remotely controlled by an attacker. When I spoke of the attacks that could be used, that could be performed, using consumer access points and routers, what I really described was a botnet. It's a large number of machines that are controlled by the attacker and which perform tasks on behalf of the attacker. And these are also used for what is called distributed denial of service and they are used for spam, but they could also be used be used to host phishing pages and other things. And, so more than 10% of all computers, it has been estimated, do have botnet software. And that is, of course, quite worrisome. What we need to do is to notice if any one particular computer does, or, not only with botnet software, but with malware in general. And one good way of knowing that is, of course, if you make everybody use anti-virus software, then the anti-virus software will catch this, but not everybody does use anti-virus software, and it's sometimes misconfigured and it's not bulletproof. It only takes care of known threats, and it can't take care of threats that just started to occur until the anti-virus company updates what's called the signature files.
So, there is one way in which you could counter this threat. It's referred to as remote harm detection. It's a way to remotely, from the financial institution, scan the machine of a person who comes there. It doesn't need executables, and you certainly don't want your clients to have to download executables, because it trains them to do very dangerous things. But just by arriving at your webpage, being there, we will scan certain aspects of your computer, and in particular, the browser history of the client to see if they have been to bad places or places that signify having been corrupted. That is one way of detecting whether a machine has been compromised. And if you know that it has, then you know, of course, not to trust anything that comes from that machine. It could also host a keylogger, and it is a machine that is dangerous, in some sense, and you need to flag it.
Q: How can banks and credit unions anticipate threats from strengths and weaknesses? And, do you have any examples that you can give to illustrate this?
JAKOBSSON: I'll give you a couple of examples. One is to say that there is better detection of spoof messages. Say that software in general, or people in general, become better at detecting if it's spoofed or not. You'll see more similar name attacks. These are attacks that rely on names that somehow, mentally to the user, relates to the brand that is being impersonated. For example, I mentioned the potential phishing attack in which it could say, "Switch to Citibank, and you'll get $50," or something like that. An attack that would relate to this would, might correspond to a domain name which is switched to citi.com. And so, if you have better detection of these, these types of attacks are probably going to increase. When people become aware of IP addresses more, and get more afraid of them, you will see this. Also, if I register a domain like organchase, it sounds like a ridiculous domain. I could actually use what's called a subdomain, this is the text that comes before the domain name on the webpage. If I use JPM as a subdomain, what it would look like when you look at the URL is jpm.organchase.com, which most people will read like, "jpmorganchase," and it could look legitimate. So, you get these wacko looking domains that are effective.
Q: Finally, do you have any best practices that you would like to share with all the financial institutions out there, that they should be following, to fight the phishers?
JAKOBSSON: Yes. Not only to focus on the technical aspects, like SSL and takedown, but to consider the human factor, too, both when you are designing e-mail templates and when you design the sites. You must track vulnerabilities among clients. For example, using what is called takehome. Takehome is an alternative to takedown. Takedown, of course, blocks the site. Takehome redirects traffic to a given URL, to a site controlled by the legitimate brand. So, if, instead of blocking access to a phishing site, the financial institution could just demand that the ISP forwards traffic. And so anybody who is a potential victim and comes to the site could be taken to the financial institution, where, first of all, the financial institution, if they use cookies, or something like that, would be able to determine who was it, so they get the demographics.
And this is not to punish people, this is to understand the risks. Second, they could display educational material there. They could say, "You have arrived at this site, because of the following actions. You clicked on an e-mail that looked like such and such." And then they could show something, for example, like the comic I described, that describes, what do phishers do? How do you avoid phishing? And so you turn defeat into educational opportunity. And most of all, if you do educate users, you must do that in a way that does not intimidate them. First of all, you don't want to scare them away, of course, but you also don't want to make them turn the other way, and say, "This is just too creepy to be true."











