Monday, July 6, 2009


One of the problems faced by entrepreneurs in the fast paced business world today is selecting the proper technology foundation to secure their business transaction in open network communication. Having the proper "implementing technology" in place can make a difference between failure and incredible success.


To secure their business transaction, they need the third party certification for security purpose. Third parties who issue digital certificates are also known as certification authorities (CAs). A digital certificate contains the holder’s name, validity period, public key information, and a signed hash of the certificate data.



Besides that, the users will be able to make transaction on the internet without fear of having the personal data being stolen, information contaminated by third parties, and the transacting party denying any commercial commitment with the users by using the digital certificate.


MSC Trustgate.com


MSC Trustgate.com Sdn. Bhd. is Malaysia affiliate of VeriSign and it is a licensed Certification Authority (CA) operating since 1999. They offer complete security solutions and leading trust services that are needed by individuals, enterprises, government, and e-commerce service providers using digital certificates, digital signatures, encryption and decryption. They are committed to provide the finest Public Key Infrastructure (PKI) to assist all types of companies and institutions conducting their business over the Internet.



DIGICERT


Digicert is a joint venture company between POS MALAYSIA Berhad and MIMOS Berhad was incorporated in February 1998 with its objective as a premier licensed Certification Authority (CA). As a Certification Authority, DIGICERT is responsible for the creation of digital identities through the use of digital certificates. DIGICERT is in the center of an effective trust model that the government is creating to address the issue of information security and the negative perception that has been painted in association with online transactions. Digital signatures, encryption, and the infrastructures to support their use are becoming essential for further growth of e-business in .Malaysia.

Tuesday, June 30, 2009


Internet is a public network that connecting millions of computers throughout the world. Internet users can share information in a variety of forms through telephone wires and satellite links. Sometimes, we need is to fill in some personal information when we surf the internet or register to become a member. In this case, hackers have the ability to intercept and use our personal information, such as credit card numbers and expiry dates to falsely do the transactions. Therefore, actions must be taken in order to increase the internet security and decrease the data stolen probability.


1. Install and update antivirus of the computer

The first step we must do is installed antivirus software and keep it updated daily as new viruses may occur anytime. Updated version of antivirus able to combat a wide range of threats, including worms, phishing attacks, rootkits, trojan horses and other malware and thus safeguard our personal and financial data.



2. Password protection

After using any of the Financial Data Center or member services, we must remember to log out according proper procedure before leaving the Financial Data Center. Remember to avoid using passwords that are easy for someone to guess, such as the name of your favorite pets or your date of birth and never to write it down on the paper and put inside your wallet or briefcase. Lastly, do not simply reveal any password that related our personal and financial data to anyone.



3. Avoid financial transactions and accessing financial information through public computer

Prevent form logging on to check your bank balance and online transaction such as e-banking when working from a coffee shop that offers wireless access. This is because the process required financial data and those data can be easily tracked in an unsecured computer. Although the systems are convenient but we do not know how powerful their firewalls are.



4. Practice safe ATM use

Pay attention when using an ATM and keep your eyes peeled for anyone who seems a little too interested in your transactions. Use your free hand to shield the keypad when entering your PIN. When your transaction is complete, keep your card and any cash immediately. Do the counting later in the safety of your locked car or home. If you see anyone suspicious around you, please do the transaction later.



5. Match your receipts to your billing statement each month

This action is to make sure you have not been billed for fraudulent purchases. If you spot any suspicious transactions such as charges you don’t recognize, or duplicate charges. Therefore you must contact your card issuer immediately.



6. Don't reply to requests for personal information

Never reply to, or click a link in an unsolicited e-mail. If you received any e-mails from banks regarding changing passwords or personal information, you must contact that particular bank to ask for confirmations. Nor should you give out personal information over the phone if there are any strangers calling you.

Thursday, June 25, 2009

Online security threats are one of the biggest challenges on the Internet nowadays. Security threats seem to be rising almost as quickly as e-shopping revenues. From phishing to pharming to hacking and cracking, electronic fraudsters are stealing identities from customers and credit card processing databases, and all parties are more than a little concerned.


The two types of attacks are non-technical and technical. Non-technical attack is an attack that uses chicanery to trick people into revealing sensitive information or performing actions that compromise the security of network. In contrast, technical attack is using software and systems knowledge to perpetrate an attack.

The following are some major threats of online security:


  1. Phishing

Phishing attack is relying on social engineering where it is a type of non-technical attack. It uses some ruse to trick users into revealing information or performing an action that compromises a computer or network in order to gain unauthorized access to systems or information.


  1. Accidental Actions

Accidental actions contain the problems arising from lack of basic knowledge about online security concepts and it does contribute to a large number of computer security risks. Insecure information transfer may leads to the security products and information leakage. Poor password choices,

accidental or erroneous business transactions, accidental disclosure, and erroneous or outdated software are examples for accidental actions.


  1. Malicious Attacks

Malicious attacks refer to the attacks that specifically aim to harm by malicious code, also known as premeditated. It includes the computer viruses, denial of service attack and distributed denial of service attack.


    • Computer viruses

Viruses


Virus is a piece of software code that inserts itself into a host, including the operations systems. The virus is activated once its host program be executed and attempts to copy itself into

more program. Viruses may simply infect and spread; others do substantial damage such as deleting files or corrupting the hard drive. For example, "I LOVE YOU" virus caused over $100 million in United States damages and over $1 billion in worldwide losses.

Worms

Worm is a self-replicating software program, consuming the resources of its host in order to maintain its capable of propagating a complete working version of itself onto another machine. It uses networks to spread itself or spread through instant messages; it does infect a computer or handheld device without human intervention. Macro virus or macro worm is executed when the application object that contains the macro is opened or a particular procedure is executed. Examples of worms include

Trojan horses

A program that appears to have useful function but contains a hidden function which presents a security risk is known as Trojan horse. Trojan horse is unlike a worm, it requires user cooperation. Once on your machine, Trojans then function as independent programs that operate secretly. Commonly, Trojans steal passwords or perform "denial of service" attacks. Examples of Trojans include Backdoor and Nuker.


    • Denial of service (DOS) and distributed denial of services (DDOS)

DOS refers to an attack on a web site in which an attacker uses specialized software to send a flood of data packets to the targeted computer with the aim of overloading its resources.


Online threats also include the identity theft and data theft. Personal identity theft on the Internet is the newest form. In the online world, electronic commerce information can be intercepted as a result of vulnerabilities in computer security. Thieves can then take this information and do with it what they will. Data theft is the term used to describe not only the theft of information but also unauthorized perusal or manipulation of private data.

There is variety of solutions to protect our online data such as password protection, trusted anti-spyware or anti-virus program and the list goes on. If you know how you become vulnerable, you will be able to protect yourself better and get surf net without constantly worrying about online the security threats.


Related Articles:

What Is a Virus? How Do I Defend Against Viruses?

What are the main Online Security Threats?

Tuesday, June 23, 2009

What is Phishing?

Phishing referred as brand spoofing or carding, is a variation on ‘fishing’, the idea being that bait is thrown out with the hopes that while most will ignore the bait, some will be tempted into biting. It is one of the greatest security problems that you face today while using your email account. In fact, phishing is a much more serious threat than the commonly heard about problems like spyware and viruses. If you are tangled in the network of fake links set by phishers, you can have severe financial loses. So, before anything of that sort happens, be on your guard and learn how to prevent phishing.

Examples of Phishing

1. Link Manipulation
Links are internet addresses that direct one to a specific website. We usually give out links to our personal blogs or digital album sites to our friends and family via emails or instant messages.
In phishing, these links are usually misspelled. One or two letters make a big difference and it will lead you to a different, and often fake, website or page. It is a form of technical deception. Phishers use sub domains. For example, a link appears to take you to an article entitled "Genuine"; clicking on it will in fact take you to the article entitled "Deception".

2. Filter Evation
This is the use of images instead of texts. Through this, anti phishing filters will find a hard time to detect the emails.

3. Website Forger
There are some phishing scams that use JavaScript commands to alter an address bar. This directs the user to sign in at a bank or service of the phisher. This is where he will extract information from you. An attacker can even use flaws in a trusted website's own scripts against the victim. These types of attacks (known as cross-site scripting) are particularly problematic, because they direct the user to sign in at their bank or service's own web page. The Flash-based websites avoid anti phishing techniques. This hides the text to a multimedia object.

4. Phone Phishing
This is done by using a fake caller ID data to make it appear that the call came from a trusted organization. The operator of the phone who answered your call will ask you to give your account numbers and passwords. There are many other phishing techniques. Some have developed counter-phishing techniques already but scammers continue to invent still newer tricks. Always be alert and never trust to give your most private details easily.

How to prevent phishing? One of the easiest ways to prevent phishing is to install up-to-date antivirus software, such as Anti-Virus PLUS. Provide your email account with a phishing protection program, such as Spam Controls to keep away possible phishing emails. Even after applying such phishing filter, you cannot stop such spam. In that case, use your brain to be convinced that your bank already has that information and would not request you to confirm them over emails. The other thing that you can do in place of phishing software is to contact the company in question and crosscheck the authenticity of the mail.














;;