Closing the phishing hole: fraud, risk, and nonbanks

Closing the phishing hole: fraud, risk, and nonbanks
复制标题

堵住网络钓鱼漏洞:欺诈、风险和非银行机构

DOI:
--
复制
发表时间:
2007
期刊:
影响因子:
--
通讯作者:
Ross J. Anderson
Ross J. Anderson
中科院分区:
--
文献类型:
--
作者:
Ross J. Anderson

文献摘要

被引文献

相似文献

网络诈骗者使用各种非银行支付服务来清洗犯罪所得。人们认为可追溯性是关键。然而,调查表明,可撤销性更为重要。可以追查银行系统内的欺诈性付款,并在合理的成功概率下追回;但一旦被盗资金被用于购买黄金等可转让金融资产,追回资金就变得困难得多。这表明,通过提高交易对手风险的透明度,可以从更密切地监管非银行机构中获得很多好处。我也关注更广泛的问题;正如受到充分监管的离岸金融中心可以通过提供竞争而使全球金融体系受益一样,非银行支付系统也可以发挥有益的竞争作用。另一个问题是,自9/11以来,身份与可追溯性之间的混淆已悄悄进入合规程序;我认为,人们过于强调前者,而忽略了后者。目前的金融行动特别工作组规则给穷人带来了不必要的负担,同时在促进迅速追回被盗资产方面做得不够。未来对非银行支付服务的监管必须考虑到这一点。只要被盗资金能够被迅速追踪和追回,匿名或未经验证的支付机制是可以容忍的,特别是对于低价值的工具。人们还必须对责任保持谨慎。许多非银行支付系统使用合同,试图让他们在与客户的纠纷中担任法官和陪审团——冒着竞相降低消费者保护的风险,以及加剧运营风险的道德风险。只有支付服务提供商才能有效地打击欺诈,因为只有他们才能访问所有数据,并有能力改进他们的系统。因此,消费者保护在支付系统弹性中不容忽视。自2000年以来,人们越来越认识到信息安全风险的管理跨越了技术和政策的界限。系统的失败往往不是因为技术原因,而是因为激励机制错误;通常,操作系统的人并不是承担故障全部成本的人。(事实上,系统的设计往往有意将风险外部化。)这导致了安全经济学这一新学科的发展,目前有100多名活跃的研究人员和两次年度会议。美联储邀请我做这次演讲时提出的一个问题是:在非银行支付服务的背景下,安全经济学家可能会对在线欺诈及其相关的操作风险说些什么?大约从2004年开始,网络犯罪已经成为一门大生意。在此之前,典型的“黑客”是一群十几岁的恶作剧者,他们试图感染机器或破坏网络,以打动同龄人;虽然也有一些网络诈骗,但它们往往是零星的、不连贯的。现在情况发生了变化。现在人们编写电脑病毒不是为了好玩,而是为了赚钱。数千台受感染的机器被组织成僵尸网络,这些僵尸网络被出租来发送垃圾邮件、进行拒绝服务攻击和托管欺诈性网站。关键的变化是黑社会经济的出现,这样恶棍们就可以专业化并相互交易。增长最快的网络犯罪似乎是网络钓鱼,受害者被一封电子邮件引诱登录到一个看似真实但实际上窃取了他们密码的网站。它始于2003年,当时有6起袭击事件报道。这些人既粗鲁又贪婪;攻击者要求提供各种各样的个人信息,甚至是ATM密码,这让许多客户感到不对劲。到2004年,钓鱼者利用真实的银行电子邮件和网站的副本,以及更好的心理手段,提高了他们的游戏水平。到2006年,英国的损失已攀升至3500万英镑,美国则高达9位数。增长速度惊人,现在不仅包括大型银行,还包括PayPal等非银行支付服务和亚马逊等大型零售商。虽然对骗子来说,建立一个银行网站的副本比在购物中心建立一个假冒的银行分行要容易得多,但成功实施网络钓鱼攻击所需的基础设施仍然不是微不足道的。但这正是不断增长的地下经济开始崭露头角的地方。一名美国软件工程师现在可能编写恶意软件,被罗马尼亚僵尸网络牧人用来控制数千台机器;然后,他把它们租给一个俄罗斯钓鱼者,后者建立了一个虚假的网站,向银行的客户发送垃圾邮件。随之而来的是一场追逐,资金从受损账户中转移出来。这些账户是可交易的;还有一些组织会招募“骡子”。因此,一些犯罪团伙从受感染的账户中取出资金,通过其他受感染的账户或骡子转移资金,最后通过非银行机构转移资金,如1 .最近的一篇调查文章见“信息安全经济学——调查和开放问题”,Ross Anderson, Tyler Moore, Softint 2007(1月19日至20日,图卢兹);另一个问题是“在线赌博会成为让非银行支付流行起来的杀手级应用吗?”然而,赌博正在向“第二人生”转移,以至于美国联邦调查局(FBI)对其进行了突击搜查:http://www.reuters.com/article/technologyNews/idUSN0327865820070404?4骡子通常是受教育程度较低的老年人,被“在家工作”广告招募,他们相信通过将银行账户中的资金汇给海外的“出口商”黄金或西联汇款,他们可以诚实地赚取10%的收入。最后,偷来的钱被专门的提现经营者从支付系统中拿走,他们可能完全属于另一个团伙。就像亚当•斯密的大头针工厂一样,专业化给犯罪分子带来了巨大的生产力收益。还有一些变体,如“pharming”,其中欺骗不是直接对客户进行,而是对基础设施进行;例如,家庭路由器可能被接管并配置为将银行客户定向到恶意网页而不是真实网页。最近,针对网络钓鱼和钓鱼的技术防御已经做了很多工作,但越来越多的人意识到,技术只能做这么多。首先,有一个经典的安全经济学问题:每个人都希望别人来解决问题;在最近的一次英国会议上,政府希望公民对自己的网络安全承担更多责任,而银行则指责政府和互联网服务提供商,而其他所有人都渴望以其他方式与这个问题保持距离。这种责任倾销是地方性的;Hirshleifer和Varian对系统的安全性是否取决于防御者努力的总和进行了建模,是他们中的任何一个人付出的最大努力,还是他们中的任何一个人付出的最小努力。在最后一种情况下,实际的防御努力可能远远达不到社会最优水平。其次,商用pc附带的标准安全机制并不真正适合使用。SSL/TLS协议是在90年代中期设计的,目的是将遵从性成本转嫁给用户,再一次,潜在的原因是经济上的——在具有强大网络效应的市场中争夺主导地位的公司(正如微软和网景当时在浏览器市场中所做的那样)被激励着将其互补者的便利置于客户的安全之上。另一个对网络钓鱼更有抵抗力的协议——SET——也受到了银行业的抵制,因为它的基础设施成本更高,而消费者也因为它消除了退款和免除了责任而抵制
Online fraudsters use a variety of nonbank payment services to launder the proceeds of crime. People had assumed that traceability was the key. However, investigation reveals that revocability is more important. Fraudulent payments within the banking system can be pursued and recovered with a reasonable probability of success; but once stolen funds are used to buy transferable financial assets such as eGold, recovery becomes much harder. This suggests that much of the benefit that could be obtained from regulating nonbanks more closely can be got by greater transparency about counterparty risks. I also look at broader issues; just as adequately regulated offshore financial centres can benefit the global financial system by providing competition, so also nonbank payment systems can play a useful competitive role. A further issue is the confusion between identity and traceability that has crept into compliance procedures since 9/11; I argue that there has been too much emphasis on the former at the expense of the latter. The current FATF rules impose unnecessary burdens, particularly on the poor, while not doing enough to facilitate rapid recovery of stolen assets. Future regulation of nonbank payment services must take account of this. Anonymous or unverified payment mechanisms can be tolerated, particularly for low value instruments, so long as stolen funds can be quickly traced and recovered. One must also be cautious about liability. Many nonbank payment systems use contracts that attempt to make them judge and jury in disputes with customers – risking a race to the bottom that would undermine consumer protection, and moral hazard which exacerbates operational risks. Only payment service providers can fight fraud effectively, as only they have access to all the data, and the ability to evolve their systems. Consumer protection thus cannot be ignored in payment system resilience. Introduction – fraud and phishing Since about 2000, there has been a growing realization that the management of information security risks crosses the boundary between technology and policy. Systems often fail not so much for technical reasons, but because incentives were wrong; often the people who operate a system are not the people who suffer the full costs of failure. (Indeed, systems are often designed deliberately to externalise risk.) This has led to the growth of a new discipline of security economics, which now has over 100 active researchers and two annual conferences. One question asked by the Federal Reserve when asking me to give this talk was: what might a security economist say about online fraud and its associated operational risks in the context of nonbank payment services? Since about 2004, online crime has become big business. Before then, a typical ‘hacker’ was a teenage prankster who tried to infect machines or knock out networks to impress his peers; and while there were some online scams, they tended to be sporadic and disconnected. That has now changed. People now write computer viruses not for fun, but for profit. Infected machines are organised by the thousand into botnets that are rented out to send spam, conduct service-denial attacks, and host fraudulent websites. The critical change has been the emergence of an underworld economy, so that villains can specialise and trade with each other. The most rapidly growing online crime appears to be phishing, in which victims are lured by an email to log on to a website that appears genuine but that actually steals their passwords. It started in 2003, with half-a-dozen reported attacks. These were both crude and greedy; the attackers asked for all sorts of personal information, and even for ATM PINs, which made many customers smell a rat. By 2004 the phishermen had raised their game, using copies of genuine bank emails and websites, and better psychology. By 2006, losses had climbed to £35m in the UK, and nine figures in the USA. Growth continues at a phenomenal rate, with the target list now including not just large banks but also nonbank payment services such as PayPal and large retailers like Amazon. Although it is easier for crooks to build a copy of a bank’s website than it is to build a bogus bank branch in a shopping mall, the infrastructure required for a successful phishing attack is still not entirely trivial. But this is where the growing underground economy is coming into its own. An American software engineer may now write malware used by a Romanian botnet herder to take over thousands of machines; he in turn rents them out to a Russian phisherman who sets up the bogus website and spams the bank’s customers. There follows a chase in which money is moved from compromised accounts. These accounts are traded; there are also organisations that recruit ‘mules’. So a number of gangs remove money from compromised accounts, pass them through other compromised accounts or mules, and finally move them through a nonbank such as 1 For a recent survey article see ‘The Economics of Information Security – A Survey and Open Questions’, Ross Anderson, Tyler Moore, Softint 2007 (Jan 19–20, Toulouse); at http://www.cl.cam.ac.uk/~rja14/Papers/toulouse-summary.pdf 2 Another was ‘Will online gambling be the killer app that makes nonbank payments popular?’ However, gambling is moving to Second Life, to the point that the FBI raided it: http://www.reuters.com/article/technologyNews/idUSN0327865820070404? 3 R Clayton, ‘Techno-Risk’, at Cambridge International Symposium on Economic Crime 2003, at http://www.cl.cam.ac.uk/~rnc1/talks/030910-TechnoRisk.pdf 4 Mules are often poorly-educated elderly people, recruited by ‘work from home’ ads, who believe they are earning an honest 10% by remitting funds they receive in their bank accounts onward to an ‘exporter’ overseas eGold or Western Union. Finally the stolen money is taken from the payment system by specialist cashout operators, who may belong to another gang entirely. As with Adam Smith’s pin factory, specialisation brings the criminals great productivity gains. There are variants such as ‘pharming’ in which the deception is not carried out on the customer directly but on the infrastructure; for example, home routers may be taken over and configured to direct bank customers to malicious web pages instead of the real ones. Much work has been done recently on technical defences against phishing and pharming, but there is a growing realisation that technology can only do so much. First, there is the classic security-economics issue that everyone wants someone else to solve the problem; at a recent UK conference, the government wanted citizens to take more responsibility for their own safety online, while banks blamed the government and the ISPs, and everyone else was eager to distance themselves from the problem in other ways. This liability dumping is endemic; it has been modelled by Hirshleifer and Varian in terms of whether the security of a system is determined by the sum of the defenders’ efforts, the maximum effort that any of them makes, or the minimum effort that any of them makes. In the last case the actual defense effort may fall particularly far short of the social optimum. Second, the standard security mechanisms shipped with commodity PCs are not really fit for purpose. The SSL/TLS protocol was designed in the mid-90s to dump compliance costs on users, and again, the underlying reason was economic – companies competing for dominance in markets with strong network effects (as Microsoft and Netscape were in the browser market at the time) are motivated to put their complementers’ convenience above their customers’ security. A competing protocol that would have been more resistant to phishing – SET – was also resisted by the banking industry because of higher infrastructure costs and by consumers as it eliminated chargebacks and dumped liability