On GameSpot: We try out down the PSP Go
BNET Business Network:
BNET
TechRepublic
ZDNet

April 7th, 2008

The next big thing? Crimeware-as-a-service

Posted by Larry Dignan @ 7:49 am

Categories: Data theft, Exploit code, Hackers, RSA, Vulnerability research, Zero-day attacks

Tags: Finjan Software Inc., CaaS, Security, Productivity, Larry Dignan

Finjan says Crimeware-as-a-Service (CaaS) is becoming an increasing problem and the ability of law enforcement to track malicious hackers will become increasingly hampered.

On Monday, Finjan’s Malicious Code Research Center (MCRC) released its first quarter Web security trends report (registration required) and highlighted CaaS. finjan’s release is timed for the RSA security conference in San Francisco.

The gist: “Criminals have started to use online cybercrime services instead of having to deal themselves with the technical challenges of running their own Crimeware server, installing Crimeware toolkits or compromising legitimate websites,” says Finjan. In other words, it’s point, click and hack.

What makes CaaS a big problem is that the service operators don’t necessarily attack anything. These CaaS operators are basically arms dealers that provide customers with anti-forensic attack techniques and the ability to manage cod networks. Finjan has highlighted this trend before, but its report puts a little more meat on its research.

Finjan argues that CaaS is the latest phase in the commercialization of malicious hacking. Next up: A service for getting stolen data that tailors victims to criminal intent. Here’s how Finjan sees the commericalization of information security crime developing.

crimeware1.png

Finjan in its report notes:

(Cybercrime commercialization) is no longer just the trading of data as we have seen in the past,where criminals would offer sensitive business data to the highest bidder, but providing a service that encapsulates the entire attack and infection process, and provides a distilled feed of data that is being harvested as part of the attack. It not only detaches the criminals from the actual work of exploiting and controlling the attacks, but also allows a bigger “market share” in the business of criminal activities on the web.

And here’s a possible crimeware data trading scheme:

crimeware2.png

Finjan paints a glum law enforcement picture.

A service like this will also be the next logical step in terms of the technical development of Crimeware toolkits. Initially we have seen a simple aggregation of exploits, followed by some reporting capabilities. Next came automatic updates, support, and enhancements (such as integration of code-obfuscation and evasive anti-forensics techniques). Currently, we see the rise of the Crimeware-as-a-Service (CaaS) model in the Crimeware-toolkit market. It enables such a toolkit to gather the data from the victims and sort it according to some rough criteria for the users, since all the data and networking is already built-in and available for the criminals and attackers.

This development will further distant the criminals from the techies – a trend that we have seen evolving over the past couple of years. This trend will get a further boost with the catching on of the CaaS model. Cybercriminals and criminal organizations are getting better and better at protecting themselves from law enforcement by using the Crimeware services, especially since the operator does not necessarily conduct the criminal activities related to the data that is being compromised. Although in theory such an operator could be prosecuted for hosting and operating malicious code (depending on the penal code in the respective country in which it is being prosecuted) the impact that the data itself could have on such a prosecution makes it quite academic.

Comforting eh?

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 7 Talkback(s)
RE: The next big thing? Crimeware-as-a-service
I agree you can't punish the innocent. The criminals would only keep breaking the laws they need to banned the criminals from computers and don't let them use any means of a computer that would includ... (Read the rest)
Posted by: sheymom06 Posted on: 04/20/08 You are currently: a Guest | | Terms of Use
Close to maturity, watch out!  terry flores | 04/07/08
RE: The next big thing? Crimeware-as-a-service  lou_callahan@... | 04/08/08
RE: The next big thing? Crimeware-as-a-service  phatkat | 04/08/08
Thanks, Gonzo and Mukasey  doctordawg | 04/08/08
RE: The next big thing? Crimeware-as-a-service  RevWilliam | 04/08/08
Re: The next big thing? Crimeware-as-a-service  Bobo1111 | 04/09/08
RE: The next big thing? Crimeware-as-a-service  sheymom06 | 04/20/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here