News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Network Security
Average Rating:
Rate this article:  
More Than 75 Percent of Bank Sites at Risk, Study Says More Than 75 Percent of Bank Sites at Risk, Study Says
By Jennifer LeClaire
July 24, 2008 9:43AM

    Bookmark and Share
A study by the University of Michigan says more than 75 percent of banks are vulnerable to cybercriminals because of design flaws. Professor Atul Prakash said the bank sites included some of the largest in the country and aren't bugs that could be fixed with a patch. The FDIC says hackers got nearly $16 million from banks in the second quarter.
 



More than 75 percent of bank Web sites have at least one design flaw that could make customers vulnerable to cybercriminals after their money or even their identity, a University of Michigan study says.

Atul Prakash, a professor in the Department of Electrical Engineering and Computer Science, said some banks may have taken steps to resolve these problems since the data Relevant Products/Services was gathered, but overall he still sees a need for improvement.

"To our surprise, design flaws that could compromise security were widespread and included some of the largest banks in the country," Prakash said. "Our focus was on users who try to be careful, but unfortunately some bank sites make it hard for customers to make the right security decisions when doing online banking."

Pinpointing the Flaws

These design flaws aren't bugs that could be fixed with a patch. They stem from the flow and layout of these Web sites, according to the study. The flaws include placing log-in boxes and contact information on insecure Web pages and failing to keep users on the site they initially visited.

The flaws leave cracks in security that hackers could exploit to gain access to private information and accounts. The Federal Deposit Insurance Corporation says computer intrusion, while relatively rare compared with financial crimes like mortgage fraud and check fraud, is a growing problem for banks and their customers.

A recent FDIC Technology Incident Report, compiled from suspicious activity reports banks file quarterly, lists 536 cases of computer intrusion, with an average loss per incident of $30,000. That adds up to a nearly $16 million loss in the second quarter of 2007. Computer intrusions increased 150 percent between the first quarter of 2007 and the second. In 80 percent of the cases, the source of the intrusion is unknown but it occurred during online banking, the report says.

Protection from Financial Phishing

It's no surprise to security researchers that many corporate computers are vulnerable to attacks. In June, Sophos released research that revealed 81 percent of corporate computers tested did not have the latest Microsoft Relevant Products/Services security patches installed, had their firewall disabled, or were missing security software updates.

"It's important to remember that there are risks with any kind of banking. Online banking isn't inherently unsafe, but the way in which you bank online (and the care which you take when you do so) will be instrumental in determining if you are likely to fall victim to a cybercriminal," said Graham Cluley, a senior technology consultant at Sophos.

Banks would be wise to look at Prakash's study and determine if there is more they can do to make their Web sites more secure, Cluley said. More banks could also look at providing authentication tokens to users, which can help fight some of the phishing problem.

Phishing tokens are small hardware Relevant Products/Services devices that produce a one-time six-digit number that can be entered at log-in alongside the user's regular username and password. Even if keyboard logging spyware has infected the PC and can grab the username and password, it won't find the random number very useful since it expires within a couple of minutes.

"It's not a complete solution -- and there are ways for cybercriminals to still steal from your bank account -- but it can help combat some of the more common attacks and make life for the hackers more tricky," Cluley said.
 

Tell Us What You Think
Your Comment:



Advertisement


 Network Security
1.   China Cyberattacks: Pervasive Threat
2.   Patch Tuesday Will Tie MS Record
3.   Cybersecurity Appears Hot for 2010
4.   EPIC Objects To Google-NSA Ties
5.   Torrent Traps Used To Harvest Logins


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.