Where am I?

HOME
  • COMMENT Blogs
Mousetrap technology blog

Mousetrap Technology - Times Online - WBLG

Offbeat analysis of the world of high technology. Subscribe to a feed of this Times Online blog at http://timesonline.typepad.com/technology/rss.xml

« Exposed! Facebook outrivals HMRC as privacy villain | All Posts | Facebook fraud fears »

November 22, 2007

Cyber-crime's latest menace

The vocabulary of cyber-crime has always been colourful. From the discourse that brought us 'evil twin' attacks, the Love Bug and the notorious Silver Lords gang comes a new threat: fast flux, or what in some circles is called 'dynamic website repositioning'. Fast Flux is a technology that enables criminals to constantly shift the locations of websites from which they launch their operations - in some cases, after a site has existed for only a matter of seconds. In the time that a user has clicked around 5 pages on a website, they may unknowingly have been bounced between servers in Eastern Europe, China, Brazil and the US, leaving law enforcement with almost no way to trace the origin of the malicious software, experts said. "It's like chasing shadows," said Nick McGrath, a director of security at Microsoft, adding that the number of fraudsters using fast flux had increased dramatically in recent months following the technology's emergence nearly a year ago.

According to Trend Micro, the security firm, fast flux was the basis of a series of attacks on the social networking site MySpace in July, where users would get a 'friend request' that, when they clicked on it, directed them to another site which tried to infect their machine. "It's a bit like constantly unhooking one site and hooking up another - a kind of website round robin," said David Perry, a security consultant at Trend Micro. "The problem is that a lot of security products use 'static lists' of websites known to be responsible for malware when they do their blocking. Constantly changing the URL is a way of getting round that." Fast flux can be used as a technique in any type of cybercrime attack from spam to viruses, phishing, 'keyword logging' - where a user's password is captured, and attacks on corporate networks. Experts said that although it was possible to trace the existence of such sites after they had disappeared - "There's always a fingerprint", Mr McGrath said - it was much more difficult than if operations were concentrated on one server.

Police said that the ability to track such activity also depended to a much greater degree on co-operation from foreign Governments, which was not always forthcoming. Garreth Griffith, head of risk at PayPal, the online payment service, said: "A couple of years ago fraudsters were picking the low lying fruity - now as we get better at chasing them, their methods are getting more sophisticated." Fast flux is expected to be high on the agenda at a meeting of cybercrime experts in Romania next week.

Posted by Jonathan Richards on November 22, 2007 at 04:30 PM | Permalink

Comments

Post a comment

Comments are moderated, and will not appear on this weblog until the author has approved them.

If you have a TypeKey or TypePad account, please Sign In

You are currently signed in as (nobody). Sign Out

Your Writers


  • Holden Frith, Technology Editor, Times Online

    Jonathan Richards, Technology Reporter, Times Online

    Michael Moran, Web Correspondent, Times Online

    Bernhard Warner, Freelance Technology Journalist

    David Hutchinson, Times Online Designer

    Send us an Email

RSS Feeds

  • Click for an RSS 2.0 feed

three random posts

Recent Comments

  • on Are online ID cards the answer to forgotten passwords?
  • Alan Curtis Montgomery, Mesa AZ on Is multitasking turning us into unproductive dolts?
  • Charles on Will eBay's new fees please?
  • Conrad on A glimmer of hope for the UK music industry?
  • Allen A on After seeing off HD-DVD, Blu-ray outpaces DVD sales

Links

  • Business - Technology Sector
  • The Web
  • Times Online Tech Homepage
  • Slashdot
  • Gizmodo
  • Lockergnome- IT Professionals
  • Wired
  • Boing Boing
  • CNET.co.uk
  • Technorati

Categories

  • Apple
  • Bernhard Warner
  • Broadband
  • Comment
  • David Hutchinson
  • E-government
  • Entertainment
  • Facebook
  • Feature
  • Gadgets
  • Gaming
  • Google
  • Internet governance
  • Jonathan Weber
  • Michael Parsons
  • Microsoft
  • Mobile phones
  • News
  • Piracy and file-sharing
  • Security
  • Spam

Recent Posts

  • A glimmer of hope for the UK music industry?
  • Are online ID cards the answer to forgotten passwords?
  • Is multitasking turning us into unproductive dolts?
  • After seeing off HD-DVD, Blu-ray outpaces DVD sales
  • EU to mobile operators: Two weeks or else!

Archives

  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007

News on Times Online

    • Latest News
    • UK News
    • Crime News
    • Education News
    • Environment News
    • Health News
    • Political News
    • Science News
    • World News
    • Iraq News
    • US News
    • European News
    • Middle East News
    • Asia News
    • Africa News
    • Technology News
    • Business News

Other Times Online Blogs

  • Faith Central

    Urban Dirt

    Alpha Mummy

    BabyBarista

    Ariel Leve

    Big Brother Celebrity Hijack

    Charles Bremner

    Comment Central

    Cricket

    Eco Worrier

    Formula One

    India Knight

    Inside Iraq

    Irwin Stelzer

    Lord Rees-Mogg

    Mary Beard (TLS)

    Money Central

    News

    Sports Commentary

    Peter Stothard (TLS)

    Richard Lloyd Parry

    Ruth Gledhill

    Surf Nation

    Technology

    The Click