First White Paper on Business Logic Abuse
The next big thing in website attacks is business logic abuse. This is the use of legitimate business logic (including sound business logic and business logic flaws) to commit online fraud. It’s getting a lot of recognition, from Wikipedia articles (as highlighted in a recent post) to Black Hat presentations like the one from Jeremiah Grossman at Black Hat 2008.
Silver Tail has released the first white paper defining business logic abuse – including methods for detecting, investigating and stopping malicious behavior (including hijack threats, velocity attacks and gaming schemes) as they occur.
Online fraud is on the rise and no one predicts it will decline. The number of fraudsters is increasing and the attacks are evolving from theft through hacking into more sophisticated attacks targeting the business logic of the website itself.
Given that business logic exploits can be live for weeks or months, it is no wonder bad actors are constantly finding new ways to exploit websites. Combine this with the significant income from online fraud and the lack of fear of law enforcement and one can see why this problem is on the rise. The return on investment (ROI) for bad guys is just too compelling! What websites need is a potent response: namely, the same automation and ability to innovate as the bad guys.
Silver Tail has published the first white paper on business logic abuse. The paper defines business logic abuse and the significant impacts it can have on an organization. Definitely comment here or contact us privately with any feedback you have relating to the paper. It would be great to hear your thoughts!
No comments yet.
Leave a comment
-
Archives
- December 2009 (5)
- November 2009 (7)
- October 2009 (8)
- September 2009 (7)
- August 2009 (8)
- July 2009 (7)
- June 2009 (6)
- May 2009 (6)
- April 2009 (14)
- March 2009 (8)
- February 2009 (5)
- January 2009 (8)
-
Categories
- behavior analysis
- business logic abuse
- Business Logic Flaw
- Business Process Abuse
- Compliance
- Cost of fraud
- Data Loss
- Detection
- education
- Fraud
- Gaming
- General
- information security
- Investigation
- Man-in-the-Browser
- Online Fraud
- Payment
- Phishing
- Prevention
- risk management
- Social engineering
- Social Networks
- Trust
- Uncategorized
- web logic abuse
- Zeus
-
RSS
Entries RSS
Comments RSS
