Click here to receive your FREE subscription to Campus Technology
Home > CMU Research Team Analyzes Internet 'Miscreants'
News
CMU Research Team Analyzes Internet 'Miscreants'
11/9/2007
By Paul McCloskey
A team lead by Carnegie Mellon computer science researchers has developed computer tools capable of following the operations of electronic black markets for viruses, stolen data, and attack services.
Adrian Perrig, a CMU associate professor of electrical and computer engineering and public policy has led a team that developed the automated techniques to measure activities of spammers, virus writers, and identity thieves. In addition to Perrig, the team included Jason Franklin, a Ph.D. student in computer science, Vern Paxon of the International Computer Science Institute, and Stefan Savage of the University of California, San Diego.
The researchers estimated that more than $37 million in software tools for malicious programming were available for sale during their seven-month study period. During that time, more than 80,000 potential credit card numbers were available through "illicit underground Web economies," Franklin told the CMU press office.
The researchers found that buyers of malicious software tools and services would normally contact black market vendors using e-mail or instant messaging. Money generally changed hands through non-bank payment services such as e-gold, making the criminals difficult to track.
"These troublesome entrepreneurs even offer tech support and free updates for their malicious creations that run the gamut from denial of service attacks designed to overwhelm Web sites and servers to data stealing Trojan viruses," said Perrig.
The researchers proposed approaches to thwart black marketers, including slander attacks designed to undercut a vendor's reputation in the black market. "Just like you need to verify that individuals are honest on eBay, online criminals need to verify that they are dealing with 'honest' criminals," Franklin said.
In a slander attack, an attacker discounts the verified status of a buyer or seller through false defamation. "By eliminating the verified status of the honest individuals, an attacker establishes a 'lemon' market where buyers are unable to distinguish the quality of the goods or services," Franklin said.
Perrig's team also developed a technique to establish fake verified-status identities that are difficult to distinguish from other verified-status sellers, which makes it hard for buyers to identify honest verified-status sellers from dishonest verified-status sellers.
"So, when the unwary buyer tries to collect the goods and services promised, the seller fails to provide the goods and services. Such behavior is known as 'ripping.' And it is the goal of all black market site's verification systems to minimize such behavior," said Franklin.
"We believe these black markets are growing, so we will have even more incidents to monitor and study in the future," Perrig said.
Read More:
Paul McCloskey is a contributing editor for the Campus Technology group of publications.
Cite this Site
Paul McCloskey, "CMU Research Team Analyzes Internet 'Miscreants'," Campus Technology, 11/9/2007, http://www.campustechnology.com/article.aspx?aid=52727
copy text (above) for proper citation
Recommended Reading
- Microsoft Mends Breach in Open Source Sandcastle
Microsoft has released all of the source code used in its Sandcastle project, which is now published at the CodePlex open source developer's Web site, according to a blog. Sandcastle helps developers of managed class libraries create uniform documentation on their projects, using MSDN style.
- Lumens Debuts SXGA Document Camera
Lumens Integration this week debuted a new document camera and presentation system called the DC260 SXGA Digital Visual Presenter. The new gooseneck-style system is the first in Lumens' document camera lineup to support HD output via HDMI.
- U Liverpool Deploys iSCSI in Virtualized SAN
The University of Liverpool Department of Computer Science is moving away from direct-attached RAIDs to a virtualized SAN environment using StorMagic's SM Series iSCSI Storage Area Network.
- Indiana U, Wayne State Teams Capture Wins in Imagine Cup 2008
Winners of the 2008 Imagine Cup technology competition were announced Tuesday in Paris. Student teams from American universities took top honors in two categories and earned achievement awards in other areas. Microsoft, which hosted the event, said it was the most successful run for American teams in the Cup's six-year history.
- IE Is Least-Patched Browser, Report Says
According to a report released last Tuesday, more than 40 percent of Internet surfers don't use browsers with up-to-date security patches--and Internet Explorer users are the biggest culprits.
- Ballmer Wants Board Change at Yahoo
Microsoft's executives have been talking with investor and corporate raider Carl Icahn about renewed plans for Microsoft to acquire part or all of Yahoo, provided that Yahoo's board is replaced. The details were described in an open letter issued Monday by Icahn, which is addressed to Yahoo's shareholders.