iTnews
  • Home
  • News
  • Technology
  • Security

Merchants blind to data breaches

By Darren Pauli
May 19 2011 4:05PM
Follow google news

You can catch most hackers by reviewing logs.

Merchants were responsible for detecting fraud-related data breaches in only seven percent of cases, according to numbers crunched by digital forensics company Klein and Co.

Acquiring banks discovered the lion's share data breaches, which equated to about 40 percent of the total reported incidents.

About a quarter of the breaches were noticed and reported by rival banks.

The low detection rate of merchants was due to both the sophisticated fraud detection systems in place at banks, and often shonky security practices in the breached organisations.

"Many businesses don't check their logs or traffic," director Nick Klein said. "Much of the threat is from insiders, and even big businesses will have bad security and their sensitive information will be sold elsewhere."

Many external attacks can be detected by abnomalities in traffic, but this requires an understanding of regular traffic flows.

Administrators should know where vistors came from and what areas of a web site they accessed.

"Know your customer, know your logs," Klein said. "The kinds of activity visitors are doing should be consistent with what a site does."

Logs would reveal IP addresses from locations that do not match the demongraphic of visitors, and this should be taken as a red flag, Klein said.

"Almost all of the attacks come from overseas. You'll get a feel for it and you'll see the patterns of activity in your logs."

Merchants blind to data breaches

Klein said attackers typically do not cover their tracks.

One flag to look for is automated script, a potential sign of attack that runs faster than script inputted by a user. The two are often used in concert.

Of external attacks that resulted in data breaches, SQL injection was responsible for 31 percent of cases. Malware was fingered in 23 percent of the breaches and stolen adminstrative credentials were identitfied in 18 percent of cases.

Broadly, the detection of breaches was more difficult in rarer attack vectors.

SQL injection was also the most popular method of exfiltrating data. The methods could not be unconfirmed in about a quarter of cases, and access to administrative functions was blamed for 10 percent of breaches.

"In an office, only a few people would normally have admin rights, so you should give them their own unique access IDs and lock the accounts down," Klein said.

Klien said there was "no clear pattern" to determine what businesses are the most vulnerable, however fraudsters tended to target less high-profile businesses.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:
auscertauscert 2011forensicshackerslogsnetworkssecurity

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Intelligence × Trust: the equation that will decide Australia's AI winners
Promoted Content Intelligence × Trust: the equation that will decide Australia's AI winners
Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Apple bumps up security in fresh operating system releases

Apple bumps up security in fresh operating system releases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.