Man-in-the-middle attacks on the rise
By Miya Knights,
Users are increasingly aware of the dangers of identity theft inherent in phishing attacks, where the user is duped into inadvertently revealing sensitive personal or financial data about themselves, which can then be used to steal the identity of the victim.
However, authentication experts at online security vendor, TriCipher are claiming that "man-in-the-middle" attacks are increasingly being used to intercept secure communications between an organisation and end user.
These phishing attacks trick the user into clicking on a link to login to an online banking or e-commerce website through a proxy site. Unlike traditional phishing techniques, the user is actually passed through to the authentic website, making it virtually impossible for even savvy users to tell that they are being scammed.
David Franklin, vice president for the Europe, Middle East and Africa told IT PRO that these sites are proliferating because they are actually easier for hackers to set up than traditional 'fake' phishing sites because they don't even have to maintain a fake website. He also said man-in-the-middle attacks defeat weak authentication methods including passwords, internet protocol (IP) geolocation, device fingerprinting, cookies and personal security images and tokens, for example.
"A lot of the attacks you hear about are just the tip of the iceberg. Banks often won't even tell an affected customer that they have been a victim of these man-in-the-middle attacks," said Franklin, adding that kits that guide cybercriminals through setting up a man-in-the-middle attack are now so popular they can be bought for as little as $500 (£250) on the black market now.
He also said "man-in-the-browser" attacks are emerging to compete in popularity with middleman threat. These attacks can even defeat the most stringent two-factor authentication measures by modifying the transaction in the browser after user authentication has taken place. He said this type of attack is set to have a dramatic impact on retailers and large and medium-sized banks in future. "Even charities are being targeted now," added Franklin.
He suggested organisations take steps to strengthen their security provision to assure two-way authentication of internet browser transactions between it and the user. The TriCipher Armored Credential System prevents criminals from stealing the user's credentials, like passwords, session cookies, passcodes. He claimed an attacker attempting to proxy traffic from someone using the system would cause the user's login to fail - and the attacker would have no access to sensitive information.
advertisement
Latest Security Features
Who should be Britain’s cyber security czar?
Experts reveal what a UK head of cyber security would need to do, while we put forward possible candidates for the role.
- The reality of movie technology
- Do smartphones need security software?
- Protecting the London 2012 Olympic Games
- Focus on... Flexible working
- Cyber policing and surveillance in Britain today
- How an FBI agent transformed Microsoft security
- Can security concerns kill cloud computing?
- GhostNet: Did the Chinese government hack the world?
- How poor web security nearly lead to a jail term
Latest Security Reviews
HP BladeSystem c3000 review: blade server
Rating: ![]()
- CA ARCserve Backup r12.5 review
- FaceTime Communications USG530 - web filtering appliance review
- Guardium 7 – database security review
- Google Apps Premier Edition
- SmoothWall UTM-1000 review
- Lenovo ThinkPad USB Portable Secure Hard Drive
- LogRhythm LR-500-XM review
- EXCLUSIVE - eSoft ThreatWall 250
- Zebra RZ400 - RFID Printer
advertisement
Latest News Videos in Security
Video: Mobile security threats and Mac complacency
Part two: Eugene Kaspersky, chief executive and founder of Kaspersky Lab, talks about the increasing security threats mobile users are facing.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?