Showing posts with label INTERNET CRIME. Show all posts
Showing posts with label INTERNET CRIME. Show all posts

Monday, November 21, 2011

Making Domain Names Safe and Reliable

Domain Name System Security Extensions (DNSSEC)

As we discussed throughout National Cyber Security Awareness Month, Internet safety is a shared responsibility and each of us has a role to play. The DHS Science and Technology Directorate (S&T) is doing its part to make websites more secure and reliable by enhancing the Domain Name System (DNS), which translates website names like science.com into a network address like 1.2.3.4. Recognizing the Department's role in this effort, the S&T Domain Name System Security Extensions (DNSSEC) project received the National Cybersecurity Innovation Award at the Sans Institute's Second Annual National Cybersecurity Innovation Conference for its innovation in promoting research that "pays off" by focusing on work that can result in real products and real risk reduction.

At the advent of the Internet thirty years ago, the brand new DNS was trusted by everyone. Today, hackers take advantage of our long-standing trust in DNS and work to trick the system by stealing information and redirect-ing our data hundreds, if not thousands, of times every day. S&T and its partners are working to restore trust in the system through the creation and implementation of DNSSEC.

Most websites are not self-contained, but are rather a patchwork of information drawn from scores of sources.  DNSSEC authenticates the existence, ownership, and integrity of data while systematically validating sources including hundreds of servers, or nodes. "The value of DNSSEC reaches far beyond preventing hackers from obtaining login information," said Edward Rhyne, DNSSEC program manager in S&T's Cyber Security Division. "DNSSEC is the foundation for a new trust model for all communications on the Internet, essentially protecting our critical infrastructure."

As governments, banks, Internet service providers, businesses, and other stakeholders increase their awareness of DNS-related threats, DNSSEC adoption is gaining momentum. "Users are starting to understand," said Rhyne. "A hacker may insert a malicious server between a user and their bank, enabling collection of login credentials and account information— essentially allowing the hacker to steal an identity and transfer money as the authorized user."

Since 2004, S&T and its partners, including the National Institute of Standards and Technology and the DNS-SEC Deployment Initiative, have worked to build support for DNSSEC, which has resulted in registrars from all over the world. More than 20 country codes, including .us and .uk, are involved in this effort. In addition, DNSSEC was deployed in the .edu, .gov,.org, .net, and .com zones while top-level domains of the U.S. military's .mil are slated to be DNSSEC-signed in December 2011. Adoption by these most commonly utilized domains paves the way for others, and will ultimately create a complete end-to-end chain. By authenticating and protecting data, DHS is continuously working to build a safer, more secure, and more resilient cyberspace.

Sunday, August 21, 2011

FBI-Related Spam E-Mails

Mollie Halpern: Fraudsters are using a new version of spam e-mails to lure their victims. The threatening e-mails are purportedly from the FBI and its leadership.

Timothy A. Gallagher: FBI executives do not send threatening e-mails to the public.

Halpern: I’m Mollie Halpern of the Bureau, and this is FBI, This Week. The FBI does not send unsolicited e-mails to consumers. The FBI uses the legal process should we want to contact you.

Scammers are also using spam e-mails as fake FBI recruiting pitches, which are actually used to sell training and testing to people interested in law enforcement jobs. Section Chief Timothy Gallagher of the Cyber Division…

Gallagher: We caution that if you receive an unsolicited e-mail, you don’t open it, that you don’t click on it, and if you do click on it that you do not respond.

Halpern: Spam e-mail is usually originated in West Africa.

Gallagher: Many of these individuals are operating from outside the country but they’re not operating from outside the reach of the U.S. law enforcement.

Halpern: The FBI works with its foreign counterparts to bring these fraudsters to America, where they’ll face justice.

If you’re a victim of cyber crime file a complaint at ic3.gov.

Wednesday, March 17, 2010

INTERNET CRIME

Complaints on the Rise

03/17/10 - Internet crime complaints rose 22.3 percent in 2009, according to the latest IC3 report. During 2009, did you receive an e-mail that claimed to be from the FBI and asked for money or personal information?

If you did, you’re not alone—e-mail scams that misused the Bureau’s name represented the highest percentage (16.6) of complaint types submitted last year to the FBI’s Internet Crime Complaint Center (IC3), according to its latest annual report.

All told, IC3 received 336,655 complaints during 2009, a hefty 22.3 percent increase from 2008.

In addition to the fake FBI e-mails, rounding out the top five complaint categories were:

• Non-delivered merchandise and or non-payment, in which either a seller didn’t ship a promised item or a buyer didn’t pay for an item (11.9 percent);
• Advance fee fraud, when a victim was asked to give money upfront, often for goods or services that never materialized (9.8 percent);
• Identity theft, when someone either stole or tried to steal a person’s identity or some kind of identity information (8.2 percent); and
• Overpayment fraud, when a “buyer” sent a victim who was selling something a legitimate-looking check or money order (that turned out to be counterfeit) for an amount greater than the price of an item being sold, and then asked the seller to deposit the payment, deduct the actual sale price, and return the difference (7.3 percent).

Of the 336,655 complaints submitted to IC3 last year, just under half—146,663—were referred to local, state, or federal law enforcement agencies for further action. Most of those cases involved fraud and financial losses by the victims. The losses from the referred cases totaled $559.7 million.

The complaints not referred to law enforcement generally had no financial losses—for example, a victim received a fraudulent unsolicited e-mail but didn’t act on it—or involved victims and perpetrators who both lived outside the United States.

But complaints not directly referred to law enforcement are still valuable—they’re accessible by law enforcement and are used to analyze trends, gather intelligence, and educate the public. So if you feel you’ve been targeted, please submit a complaint to IC3, whether you lost money or not.

Some of the more popular e-mail scams during 2009 (and scams to watch out for during 2010) included:

• A new spin on the “hit-man” scam, in which individuals received an e-mail from an "assassin" who claimed he was going to kill them, but who said they would be spared if they sent money because someone in his organization knew a member of their family and pled for their lives.
• Spam or pop-ups offering free astrological readings, but only after birthdates and birthplaces were provided. Victims were then enticed into purchasing a full-fledged reading with the promise they would find out something favorable was about to happen. Of course, they never received the reading.
• Economic stimulus scams, where victims received a recorded phone message directing them to websites where they could apply for government stimulus money after first entering personal information and paying a small fee. Needless to say, no stimulus money was received.
• Fake pop-up ads for anti-virus software that warned of the existence of computer viruses but actually downloaded malicious code when clicked.