Showing posts with label week4. Show all posts
Showing posts with label week4. Show all posts

Friday, June 26, 2009

Phishing:Examples and its prevention methods

Phishing is an online fraud technique used by criminals to entice the people to share their confidential information such as account passwords, credit-card numbers or other information. It is also known as “carding” and “spoofing”. Phishing is the most powerful online crime method used by criminal for stealing personal finance information and perpetrating identifies theft.

Normally, Phishing is happens from social networking website, a fake website that accepts donation for charity and etc. It is normally carried out by e-mail messages, instant message program, spam and etc.


The following are some of the examples of Phishing:
1.
This is an example of what a phishing scam in an e-mail message might look like.


Phishing (email scams) always includes official-looking logo and it will try to convince you to divulge the details about your confidential information on to their fraudulent websites.

2. This is an example of what a phishing website might look like.


How do we know if this is a legitimate bank website or fake website? The first indication is the slightly illogical problem that they are trying to persuade you to solve the problem: “some of our members no longer have access to their email addresses and we must verify it”. The second tip-off is that the address is supposedly secure (using the https:// notation), but there is no padlock icon in the bottom right hand corner of the browser window. Finally, the Address Bar is a fake. The website operator has turned off the address bar. Turning it back on using View, Toolbars, Address Bar reveals the proper address like this:




How can you protect yourself from Phishing:
1. Never reply to e-mail messages that request your personal information
Be aware of the e-mail message from the person that asks for your confidential information- or one that asks you to send your confidential information for updating.

2. Make sure the Website uses encryption
The Web address should be preceded by https:// instead of the usual http:// in the browser's Address bar. Before submitting financial information through a Website, you must look for the "lock" icon on the browser's status bar. It means your information is secure during transmission.

3. Don't click links in suspicious e-mail
Don't click a link contained in a suspicious message because the link might not be trustworthy.

4. Use strong passwords and change them often
Use the strong passwords combine uppercase and lowercase letters, numbers, and symbols, which make the criminals difficult to guess. Besides, also can use different password for each of your accounts and change them frequently.

5. Do business only with companies you know and trust
Use well-known or established companies with a good reputation for quality service. A business Website should always have a privacy statement that specifically states that the business won't pass your name and information to other people.

6.
Help protect your PC
Keep your PC updated & use antivirus software and firewall.


7.
Monitor your transactions
You might use just one credit card for online purchases to makes it easier to track your transactions.

8.
Use credit cards for transactions on the internet instead of debit cards to avoid the big credit limit from your bank account.


9. If you are uncertain about the information, contact the company through an address or telephone number you know to be genuine.

10.
If you unknowingly supplied personal or financial information, contact your bank and credit card company immediately.







How to safeguard personal and financial data??


Nowadays, computer has become an integral part of our life. We depend a lot on computer for both personal and official works. As network crime is increasingly spreading like a wild fire, most of the users start to worry about their personal and financial. There are hackers who keep looking for vulnerable computers so that they can hack in and steal confidential data such as log in id, password and etc. So, safeguard of personal and financial data is needed to prevent or mitigate the attacks.

The following are the tips to protect your personal data:

(I) Make your password hard to guess
You can use combination of words, numbers and punctuation to form your password and change them frequently (at least twice a year). You should prevent from using any single word or easy number combination such as your birthday or your pet’s name that make the criminal easy to guess your password.

(II) Back up your personal finance information
Creating a copy or back up of personal data is a sensible as it is the easier way to help you to recover your information if a virus destroys your computer. You shall back up all the important data on your computer and keep it in a secure place.

(III) Avoid disclosing confidential or finance information to scam perpetrators
Confidential and finance information is valuable. You shall not give out confidential information through the email or over the internet, unless you know with whom you are dealing with.



(IV) Biometric System
Biometric system refers to automatic identification based on their fingerprint. Biometric authentication can provide stronger personal binding of access rights to confidential information over the traditional method. It can ensure personal or confidential data linked exclusively to the right person.

(V) Make sure the website is secure
If you have launched the website that require you to provide personal information, you must check the details in the address bar of the browser start with ‘https’ (the ‘s’ stands for ‘secure’).


(VI) Make sure anti-virus and anti-spyware are installed and up-to-date
These software can protect your computer against the viruses. You can either buy excellent anti virus software like Kaspersky Anti Virus or free anti-virus like AVG to install in your computer to avoid being detected.
Besides, anti-spyware helps to protect your computer against pop-ups, slow performance and security threats caused by spyware. So you must ensure your anti-spyware updated and keep up with the latest forms of spyware. Some popular anti-spyware are SpySweeper, Adware and etc.

Thursday, June 25, 2009

The application of third certification program in Malaysia

Nowadays, many people deliberately limit the online transaction because they do not fully trust the e-commerce process. These people fear that their personal finance information will simply transmitted over the internet when making an online transaction. In order to overcome this problem, the application of third party certification programme is implementing in Malaysia.

Certification Authority (CA) is an entity which issues digital certificate that contain public key and the identity of the owner for use by other parties. It is an example of a trusted third party.


The most famous application third party certification programme in Malaysia is MSC Trustgate.com Sdn Bhd. MSC Trustgate .com Sdn Bhd was incorporated in 1999 and it is a licensed Certification Authority (CA) operating within the Multimedia Super Corridor. The objective of MSC Trustage.com Sdn Bhd is to meet the growing need for secure open network communication from both local and the ASEAN. MSC Trustgate.com Sdn Bhd is licensed under the Digital Signature Act 1997 (DSA). It offers complete security solutions for individuals, organizations, government, and e-commerce service providers by digital certificates, digital signatures, encryption and decryption.

Here are some of the examples of products and services provide by MSC Trustgate.com Sdn Bhd:

(I) MyTRUST for mobile signature
By using MyTRUST, you can turn a SIM card into a Mobile Digital Identity for secure mobile banking and other finance services. Under Digital Signature Act 1997, Mobil digital signature provides non-repudiation on transaction. Users are able to digitally sign any transaction with ease and convenience through their mobile phone.

(II) MyKad PKI ( My Key)
Government has put in place a smart National Identity Card (“MyKad”) for every citizen in Malaysia. MyKey, is the MyKad PKI solution. It is works with MyKad that allow the people to authenticate themselves online and to digitally sign documents or transactions and it is accepted by Government Malaysia.

(III) Managed PKI for Enterprise Trust Services
Managed Public Key Infrastructure (MPKI) is a service with a fully integrated enterprise platform designed to secure intranet, extranet and internet applications by combining maximum flexibility, performance and scalability with high availability and security.
(IV) SSL VPN for Remote Access Services
Secure Sockets Layer Virtual Private Network (SSL VPN) os a type of VPN that runs on Secure Socket Layers technology and its accessible through https over web










Wednesday, June 24, 2009

The threat of online security: How safe is our data?

The threat of online security
Nowadays,
individuals and organizations can easily access the internet with a computer and network connection. Along with the involvement of network and easy access to information, the threat of online security is increasing. Online threat include the risks that valuable or confidential information will be lost, stolen, corrupted, or misused and that particular computer systems will be corrupted also. The information is more vulnerable to record electronically and is available on network.

Types of Threats and Attacks
(i)Denial-of-service (Dos) attack or Distributed denial-of-services (DDos)
is an attack that attempt to make a computer resource unavailable to its intended users.


(ii)Phishing is a technique used to obtain personal information such as user's id, password, and etc for purpose of identity theft. An email may be send to unsuspecting customers to trick them into providing their personal information in fate website.

Malware is software used to infiltrate or damage a computer system. It takes a variety of forms-both pure and hybrid such as:

(iii)Virus: A program that can copy itself and infect a computer by insert itself into a host to propagate without the permission or knowledge of the owner. A virus can simply infect and spread over the operating system and cause the collapse in the server system. Today's viruses can spread via the network services such as
e-mail, Instant Messaging, and file sharing systems.




(iv)Worm: A self-replicating program and consume the resources of its host and is capable of propagating a complete working version of itself into another machine by network. No human intervention is required to spread a worm across a network.
(v)Trojan Horse: A program that seem to have a useful function but have a hidden function that having a security risk. Trojan horses require interaction with a hacker to propagate. Trojan Horse will be installed when the unsuspected user runs the program. It enable the perpetrator to capture user's id and passwords, display messages on the affected computer, delete and upload files, modify existing operating system software and so on.

(vi)Macro virus and marco worm: A virus or worm that is executed when the application object that contains the macro is opened or a particular procedur is executed. Eg: Melissa and I Love U.





Nowadays, cybercrimes like to take advantage via some popular website such as Facebook, myspace and etc. The factor that cause the success of those attacks is the users are always caught off the guard while they receive a threat from their friends. Althought many users have affected by the threats, there are still many users that not so understand about the dangerous of messages received. The network forecast to be bleak in future.