2009 RSA Conference – eFraudNetwork
I have the privilege of attending the eFraudNetwork day as part of the 2009 RSA security conference. Prior to the conference, the eFN people had done a survey on the attacks banks and other websites are seeing. Most of the data wasn’t surprising: identity theft was a big one.
Something that was surprising, though, was that almost 20% of respondents saw attacks against application logic. When I saw that question in the survey I was worried that people wouldn’t know how to define application logic attacks. It was very interesting that people are definitely seeing this type of attack.
While 20% seems small, my hypothesis is that most people are getting hit by this type of attack, but 1) many of them don’t know what they are called and 2) many of them don’t understand yet that their websites are being impacted by this type of attack.
I’ll be anxious to see the results of this study going forward to see how this number changes.
No comments yet.
Leave a comment
-
Archives
- January 2010 (1)
- December 2009 (6)
- November 2009 (7)
- October 2009 (8)
- September 2009 (7)
- August 2009 (8)
- July 2009 (7)
- June 2009 (6)
- May 2009 (6)
- April 2009 (14)
- March 2009 (8)
- February 2009 (5)
-
Categories
- behavior analysis
- business logic abuse
- Business Logic Flaw
- Business Process Abuse
- Compliance
- Cost of fraud
- Data Loss
- Detection
- education
- Fraud
- Gaming
- General
- information security
- Investigation
- Man-in-the-Browser
- Online Fraud
- Payment
- Phishing
- Prevention
- risk management
- Social engineering
- Social Networks
- Trust
- Uncategorized
- web logic abuse
- Zeus
-
RSS
Entries RSS
Comments RSS
