<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Silver Tail Blog &#187; efraudnetwork</title>
	<atom:link href="http://silvertailsystems.wordpress.com/tag/efraudnetwork/feed/" rel="self" type="application/rss+xml" />
	<link>http://silvertailsystems.wordpress.com</link>
	<description>Fighting against business logic abuse.</description>
	<lastBuildDate>Fri, 18 Dec 2009 12:11:53 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='silvertailsystems.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/577fb613fda4531b5f1cbba10427b2bb?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Silver Tail Blog &#187; efraudnetwork</title>
		<link>http://silvertailsystems.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://silvertailsystems.wordpress.com/osd.xml" title="Silver Tail Blog" />
		<item>
		<title>Business Logic Abuse &#8211; a recognized threat</title>
		<link>http://silvertailsystems.wordpress.com/2009/04/26/business-logic-abuse-a-recognized-threat/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/04/26/business-logic-abuse-a-recognized-threat/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 01:54:19 +0000</pubDate>
		<dc:creator>Laura Mather</dc:creator>
				<category><![CDATA[Online Fraud]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[business logic abuse]]></category>
		<category><![CDATA[efraudnetwork]]></category>
		<category><![CDATA[rsa conference]]></category>
		<category><![CDATA[survey]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=532</guid>
		<description><![CDATA[The eFraudNetwork published a survey last week as part of the RSA conference.  The purpose of the survey was to &#8220;&#8230;try and understand how online fraud and data breaches are impacting multiple industries and organizations.&#8221; 
The survey covered many topics including data breaches, cross-industry information sharing, the Heartland breach, and spending to prevent fraud.
One the topics near [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=532&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><img class="alignleft size-thumbnail wp-image-533" title="rsa_conference_365" src="http://silvertailsystems.files.wordpress.com/2009/04/rsa_conference_365.jpg?w=150&#038;h=55" alt="rsa_conference_365" width="150" height="55" />The eFraudNetwork published a <a href="https://365.rsaconference.com/docs/DOC-1895">survey</a> last week as part of the RSA conference.  The purpose of the survey was to &#8220;&#8230;try and understand how online fraud and data breaches are impacting multiple industries and organizations.&#8221; </p>
<p>The survey covered many topics including data breaches, cross-industry information sharing, the Heartland breach, and spending to prevent fraud.</p>
<p>One the topics near and dear to my heart was the question that asked about attack types.  The answers to this question showed that malware and viruses are at the top of people&#8217;s minds &#8211; which was to be expected.  What I didn&#8217;t expect, though, was the percent of people who said that they have seen attacks against the business logic of their website.</p>
<p>Almost 20% of people said they had seen attacks against the business logic of their site.  While this may seem like a small number to some of you, it is bigger than I was expecting.  Attacks against business logic have been going on for years, but it has only been in the last year or so that the industry is recognizing them for what they are and taking notice of them. </p>
<p>I was thrilled to see that 20% of people understand that it is the business logic of their website that is allowing attacks.  I&#8217;ll be very curious to see how this number changes when the eFN does a similar study next year, especially since it was made clear in the study that business logic attacks are one of the most dangerous attacks against a website.</p>
<p>Is anyone else surprised the number is so high?</p>
 Tagged: business logic abuse, efraudnetwork, Online Fraud, rsa conference, survey <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/532/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=532&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/04/26/business-logic-abuse-a-recognized-threat/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea92b086d3a5647be783f387715694ee?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Laura Mather</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/04/rsa_conference_365.jpg?w=150" medium="image">
			<media:title type="html">rsa_conference_365</media:title>
		</media:content>
	</item>
		<item>
		<title>2009 RSA Conference &#8211; eFraudNetwork</title>
		<link>http://silvertailsystems.wordpress.com/2009/04/20/2009-rsa-conference-efraudnetwork/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/04/20/2009-rsa-conference-efraudnetwork/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 19:26:29 +0000</pubDate>
		<dc:creator>Laura Mather</dc:creator>
				<category><![CDATA[business logic abuse]]></category>
		<category><![CDATA[application logic attacks]]></category>
		<category><![CDATA[efraudnetwork]]></category>
		<category><![CDATA[rsa conference]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=482</guid>
		<description><![CDATA[I have the privilege of attending the eFraudNetwork day as part of the 2009 RSA security conference.  Prior to the conference, the eFN people had done a survey on the attacks banks and other websites are seeing.  Most of the data wasn&#8217;t surprising: identity theft was a big one.
Something that was surprising, though, was that almost 20% [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=482&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><img class="alignleft size-full wp-image-484" title="rsa" src="http://silvertailsystems.files.wordpress.com/2009/04/rsa.jpg?w=180&#038;h=59" alt="rsa" width="180" height="59" />I have the privilege of attending the eFraudNetwork day as part of the 2009 RSA security conference.  Prior to the conference, the eFN people had done a survey on the attacks banks and other websites are seeing.  Most of the data wasn&#8217;t surprising: identity theft was a big one.</p>
<p>Something that was surprising, though, was that almost 20% of respondents saw attacks against application logic.  When I saw that question in the survey I was worried that people wouldn&#8217;t know how to define application logic attacks.  It was very interesting that people are definitely seeing this type of attack.</p>
<p>While 20% seems small, my hypothesis is that most people are getting hit by this type of attack, but 1) many of them don&#8217;t know what they are called and 2) many of them don&#8217;t understand yet that their websites are being impacted by this type of attack.</p>
<p>I&#8217;ll be anxious to see the results of this study going forward to see how this number changes.</p>
 Tagged: application logic attacks, efraudnetwork, rsa conference <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/482/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/482/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/482/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/482/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/482/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=482&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/04/20/2009-rsa-conference-efraudnetwork/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea92b086d3a5647be783f387715694ee?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Laura Mather</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/04/rsa.jpg" medium="image">
			<media:title type="html">rsa</media:title>
		</media:content>
	</item>
	</channel>
</rss>