Why ALL Why ALL Why ALL Social Why ALL Social ocial Media ocial - - PowerPoint PPT Presentation

why all why all why all social why all social ocial media
SMART_READER_LITE
LIVE PREVIEW

Why ALL Why ALL Why ALL Social Why ALL Social ocial Media ocial - - PowerPoint PPT Presentation

Why ALL Why ALL Why ALL Social Why ALL Social ocial Media ocial Media edia Are edia Are Are Security Are Security ecurity Nightmares ecurity Nightmares ightmares! ightmares! Myspace is linked to your Facebook and its Twitterific!


slide-1
SLIDE 1

Why ALL Why ALL Social

  • cial Media

edia Are Are Security ecurity Nightmares ightmares! Why ALL Why ALL Social

  • cial Media

edia Are Are Security ecurity Nightmares ightmares!

Myspace is linked to your Facebook and its Twitterific!

David Jacoby Senior Security Researcher

slide-2
SLIDE 2

About Da

  • ut David Jacob

vid Jacoby About Da

  • ut David Jacob

vid Jacoby

  • Senior Security Researcher
  • Global Research and Analysis Team
  • Vulnerability and Threat Management
  • Spokesperson
  • Web Application Security
  • Web Application Security
  • Alternative Operating Systems
  • Read about security!
  • Write about security!
  • Talk about security!
  • Work with security!

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-3
SLIDE 3

What What We We Kno now What What We We Kno now

  • What we already know about social media and security
  • Koobface
  • Phishing attacks
  • Clickjacking
  • Malicious applications
  • Malvertising
  • Used for C&C servers
  • Used for C&C servers
  • Malicious links
  • Extreme information exposure
  • Client vulnerabilities

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-4
SLIDE 4

KoobF

  • obFace

ce KoobF

  • obFace

ce

  • KoobF
  • obFace

ce

  • Facebook
  • MySpace

MySpace

  • Twitter
  • Friendster
  • and others...
  • Multi-platform
  • Microsoft Windows
  • Mac OS X
  • Linux
  • Two social engineering attacks
  • Tricked users to visit a link
  • Tricked users to update Adobe Flash

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-5
SLIDE 5

Link LinkedIn Phishing A edIn Phishing Attempt Link LinkedIn Phishing A edIn Phishing Attempt

  • Collects username / passwords
  • Looks VERY authentic

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-6
SLIDE 6

Twitt itter Bo Botne tnet Twitt itter Bo Botne tnet

  • Twitter used as C&C Server
  • Encrypted (HTTPS)

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-7
SLIDE 7

Social Social Media Media Are re Here Here to to Sta Stay Social Social Media Media Are re Here Here to to Sta Stay

  • Total Facebook users
  • About 50% of the population in the United States and United Kingdom

p p g

Sep 22, 2011 The Kaspersky Security Symposium, Munich

source: SocialBakers

slide-8
SLIDE 8

Social Social Media Media Are re Here ere to to Sta Stay Social Social Media Media Are re Here ere to to Sta Stay

  • Total Facebook users in Europe
  • 211 512 380 users - 26.6% of the population

p p

Sep 22, 2011 The Kaspersky Security Symposium, Munich

source: SocialBakers

slide-9
SLIDE 9

Social Social Media Media Are re Here ere to to Sta Stay Social Social Media Media Are re Here ere to to Sta Stay

  • Facebook vs. LinkedIn

source: SocialBakers source: SocialBakers source: SocialBakers

Sep 22, 2011 The Kaspersky Security Symposium, Munich

source: SocialBakers

slide-10
SLIDE 10

What What Can Can We Expect xpect fr from

  • m Vendors

ndors? What What Can Can We Expect xpect fr from

  • m Vendors

ndors?

  • Who is responsible for „security“?
  • People don‘t really understand that WE are responsible

p y p

  • What type of „security“ can we expect?
  • Vendors handle security for their property

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-11
SLIDE 11

The Ne The New w Era ra of Social

  • f Social Media

Media The Ne The New w Era ra of Social

  • f Social Media

Media

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-12
SLIDE 12

What What Are Are the the Real eal Threats hreats? What What Are Are the the Real eal Threats hreats?

  • Attacks exploit trust
  • This makes social engineering attacks very powerful!

g g y p

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-13
SLIDE 13

What What Are Are the the Real eal Threats hreats? What What Are Are the the Real eal Threats hreats?

  • Attacks exploit ignorance
  • We are willing to take risks just to get connected even we know its a

g j g risk!

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-14
SLIDE 14

What What Are re the the Real eal Threats hreats? What What Are re the the Real eal Threats hreats?

  • „ Leapfrog attacks“
  • We re-use information (accounts, passwords), which can lead to other

( p ) systems

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-15
SLIDE 15

What What Are Are the the Real eal Threats hreats? What What Are Are the the Real eal Threats hreats?

You can u can pr protect ect yo yourself against against technical vulnerabilities chnical vulnerabilities You can u can pr protect ect yo yourself against against technical vulnerabilities chnical vulnerabilities, but ho but how do y w do you secure a mindse u secure a mindset? t?

Sep 22, 2011 The Kaspersky Security Symposium, Munich

slide-16
SLIDE 16
  • D

id J b

  • David Jacoby

david.jacoby@kaspersky.com 46 707 359001 +46-707-359001 http://www.securelist.com

slide-17
SLIDE 17

Summar Summary Summar Summary

  • We already know a lot about social network platforms
  • Social media are a part of our life; therefore very hard to

Social media are a part of our life; therefore, very hard to limit

  • We can protect ourselves against technical

We can protect ourselves against technical vulnerabilities, but not social vulnerabilities

  • Social media are exploiting ignorance and trust

Social media are exploiting ignorance and trust

  • We expect more attacks for social media platforms
  • Att

k d l l tt k t t d

  • Attackers need only a very low attack rate to succeed
  • We are now facing „user-generated attacks“

Sep 22, 2011 The Kaspersky Security Symposium, Munich