|
|
How to Beat KeyloggersZeus is not alone. In fact, the sheer number and insidious nature of the Zeus Trojan and other types of keylogging malware have financial institutions and their customers on high alert for fraud. To help fight fraud, computer scientists from the National Institute of Standards and Technology offer some insight on how to protect commercial and consumer computers from keylogger infection. Keyloggers monitor and record keyboard use, including the information typed into a system, which might include the content of emails, usernames and passwords for local or remote systems and applications, as well as financial information like credit card numbers, Social Security numbers or PINs. Some keystroke loggers require the attacker to retrieve the data from the system, whereas others actively transfer the data to another system through email, file transfer or other means. Tim Grance, program manager of cyber and network security at NIST's Computer Security division, and Murugiah Souppaya, a computer scientist in cyber and metwork Security, say keyloggers go back at least to 1983. Since then, keyloggers have evolved and come in a variety of types: keyboard, software and hardware based. "It is really a moving target, as malware developing today is rapidly changing," Souppaya says, "so it's hard to use signature based detection to stop them." The mutating nature of malware is such that anti-virus signatures can't keep up with the threat even by the hour. Keyloggers: Three Types NIST scientists identify three main types of keyloggers:
In some cases, keyloggers have beneficial uses, Grance says, such as parents monitoring their children's browsing on the Internet or corporate monitoring of employees' productivity levels. But malicious keyloggers, such as the Zeus Trojan are popping up everywhere and are stealing everything from banking credentials to corporate data and highly sensitive research. Defending against Keyloggers There are several kinds of defenses that can be used to spot or prevent keyloggers from embedding on machines: Physical security. The physical protection of the computer must be considered. "Whether the computer is at home, in an office or during traveling, keeping the computer secure and making sure no one has access to it is a primary concern," says Grance. Application whitelisting. This is a way to prevent any software that isn't already approved or on the "white list" from being downloaded on to the computer. This is an emerging approach in combating viruses and malware. Application whitelisting tells the computer a list of software considered safe to run, and the machine is instructed to block all others. Some experts see this approach as superior to the standard signature-based, anti-virus approach of blocking/removing known harmful software (essentially blacklisting), as the traditional approach generally means that exploits are already in the wild. Detection software.For home users, Souppaya offers three additional tips to help prevent infection:
Virtual machines. These are separated into two major categories, based on their use and degree of correspondence to any real machine. A system virtual machine provides a complete system platform that supports the execution of a complete operating system. The other type, a process virtual machine, is designed to run a single program. An essential characteristic of a virtual machine is that the software running inside is limited to the resources and abstractions provided by the virtual machine—it cannot break out of its virtual world. The virtual machine can be cleared off on a regular basis, thus keeping the real computer clean. Viruses and malware then won't be able to install onto the computer's hard drive. Souppaya says one limitation in the use and acceptance of virtual machines is the ability for the regular consumer to understand the technology and how to operate a virtual machine, or have the hardware requirements to run one. Future Trends "Moving forward in the next 12-18 months, the major computer manufacturers will begin offering virtual machine technology," Souppaya says. "We're going to see more consumer-friendly operating systems being designed by vendors that will limit malware by having the user on a virtual machine while on the Internet, and the 'home' environment separate." Cloud-based whitelisting will also become more popular, making whitelisting more available, says Grance. Another advancement in the fight against keyloggers and other types of malware is the move by anti-virus vendors to set up reputation-based systems, which checks programs and tells the user whether it is legitimate or malicious. The addition of a third component in the fight against malware is the use of operating systems and browsers that don't allow the malicious programs to be pushed down in the first place. By isolating and "sandboxing" the user's specific browsing session, Souppaya says, no software is downloaded to the user's computer. He believes this will become more available to consumers in the coming months. Linda McGlasson is the managing editor for CUInfoSecurity (www.CUInfoSecurity.com), an information portal for financial industry professionals who want to learn the latest about banking regulations, industry news, events, and opinions. Reprinted with permission. CommentsPowered by Comment Script
|
|||
|
|
| Membership Application |
| Renew Membership Online |
| Membership Benefits |
| Member Directory |
| Update Member Information |
| Frequently Asked Questions |
| CUNA Councils Connect |
| List Serve |
| File Library |
| Job Center |
| Bookmarks |
| White Papers |
| News Archive |
| Job Center |
| In the Spotlight |
| Web Poll Archive |
| Additional Resources from CUNA |
| 2012 Conference |
| 2011 Conference |
| All Past Conferences |
| Sponsorship Information |
| Webinars/Roundtables |
| Excellence in Technology Awards |
| Scholarships |
| CUNA Council Calendar |
| Speaker Proposal Form |
| Our Mission |
| Bylaws |
| Executive Committee |
| Committees |
| Get Involved |
| Council Staff |