Advertisement
Promo

Security threats Toolkit

Anti-phishing software detects fraudulent lures

Alorie Gilbert CNET News

Published: 17 Aug 2004 12:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

WholeSecurity, an Internet security firm in Austin, Texas, has released a program to help companies combat a growing form of online fraud known as "phishing," the company said on Monday.

Phishing starts with a forged email apparently from a legitimate company, such as eBay or Citibank, telling the recipient that his or her account information has expired -- or something of the sort. The recipient is instructed to click on a link that leads to a fake Web site. The site asks for confidential data such as credit card numbers.

WholeSecurity is among a number of companies developing technology to alert consumers to phishing fraud. Its program, called Web Caller-ID, is already in use at eBay. The online auctioneer has incorporated the technology into its Internet toolbar with a feature called Account Guard. It detects fraud sites purporting to be connected to eBay and its PayPal subsidiary with 98 percent accuracy, according to WholeSecurity. The tool notifies users if they enter such a site.

Hundreds of thousands of eBay members have downloaded the free program since the company launched it in February, an eBay representative said.

Now WholeSecurity is trying to license the software to other companies doing business online, allowing them to incorporate it into their toolbars or distribute to their customers as a Web browser plug-in. Banks and other financial institutions are one of WholeSecurity's target markets for the product, said Scott Olson, WholeSecurity's senior vice president of marketing.

The program analyses Web addresses for clues that might lead to fraudulent sites. For instance, if the URL is long and convoluted, or if it consists of a long string of numbers separated by periods -- an IP address -- there's a good chance it's a false site, Olson said. The program also checks whether the domain name was registered recently or its operator is using a free Web hosting service -- all tell-tale signs of phishing activity, Olson said.

Other companies that offer anti-phishing products include EarthLink, Webroot Software and PostX. Microsoft and Yahoo are also working on such programs.

Millions of people have fallen prey to phishing fraud, and the number of spoof emails and Web sites in circulation has grown exponentially over the last 12 months, according to numerous experts.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
82 out of 170 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters