Internet Eavesdropping
The problems associated with Internet Eavesdropping are many and although the perpetrators motives can vary from the curious to the malicious it matters not. They must be stopped.
As with most things in life and the world of computers, networking and communications in general intrusions and disruptions of all manner and form are pretty much a well an accepted fact of life.
The exponential growth of shared and publically accessible wireless networks such as Wi-Fi networks, wireless WANs, wireless LANs along with the numerous other types of wireless computer networks have markedly increased the risk potential and likelihood of eavesdropping on Internet communications.
Wireless LANs for example include both an organization’s internally accessible wireless network segments which may become accessible only after passing the relevant user authentication processes as well as an organization’s locally accessible internal anonymous and general public accessible segments.
With or without specialty security technologies these networks/systems are still exposed to a multitude of attack scenarios. Man-in-the-Middle attacks are but one of the many ways by which an attacker can ply their trade. Because they are so simple to instigate Man-in-the-Middle attacks tend to be quite prevalent on the Internet more or less perpetually.
Man-in-the-Middle Attacks
Man-in-the-Middle Attacks occur when an attacker tricks a computer user into believing that the user has established a secure link with a target site, such as a bank. In actuality, the computer user is communicating with the attacker's computer, which can eavesdrop as it relays communications between the user and the target site.
For example: A user who thinks he is linked to an airport or coffee shop "hot spot," might actually be linked to a laptop of someone just a few seats away. Most users are totally oblivious to the fact that they have been attacked.
Inherently Unsecure Protocol
The vast majority of Internet communications are unsecured. This includes all conversations between private and business parties as well as websites that use only the standard Hypertext Transfer Protocol (HTTP) fall into this category. Note that sites using bi-lateral encryption (e.g. HTTPS) are considerably more secure.
Unfortunately this alone does not mean that your conversation is confidential. Hijackers can implement a Man in the Middle type of attack whereby they the attacker intercepts your communication and stores it for later use. They also pass on the captured data to its intended destination. This makes it very hard for users to get any form of inkling that they have been attacked.
Securing Conversations
Using encryption over a Secured Socket Layer (SSL) and/or Secure Shell technologies that require user login authentication credentials and requires the website to which you are connecting to authenticate itself with a digital certificate that contains a public key, which is used for encryption.
It is important to note that the exchange of this security information typically occurs transparently (without the computer user being aware of it). Only when suspicious activity is detected the user is notified by a popup notice that says something like “Unable to verify the identity of anysite.com as a trusted site" This notice is generally displayed within the web browser.
Finding Solutions
The truth however; is that this sorry state of affairs need not be totally unavoidable. Growth sectors and industries have always been a favorite target with wrong doers and the Internet is no different. Nor does it come with a built-in remedy by default.
It is up to us; the users, that the responsibility for attending to this matter falls. We users need to be aware of the dangers that exist out there on the Internet and to seek out the possibilities and implement our own immunization programs.
Possible solutions might include antivirus software, firewalls of varying types, capabilities and placement as well as intrusion detection and prevention systems. Don’t forget countermeasures to combat spam, spyware, adware, hacking/cracking and a host of numerous additional threats, threat sources and thread types.
Due to the expansive nature of this component of Information Technology most of us opt to install our defenses as a suite of software modules and generally all are from the same vendor.
A free to download program that addresses these issues can be obtained from the Carnegie Mellon University's School of Computer Science and College of Engineering. This software has been named “Perspectives” and can be deployed as an extension for the popular Mozilla Firefox v3and above browser.
Here is where you can get your own free copy of the “Perspectives” software: http://www.cs.cmu.edu/~perspectives/firefox.html
Perspectives
Carnegie Mellon’s Perspectives system employs a set of friendly sites, or "notaries," that aid in Website authentication and focuses on website transactions that typically require secure communications channels such as: financial services, online retailers, ecommerce, banks and other financial institutions, medical facilities as well as any site that asks for your personal information for whatever reason.
Perspectives works by independently querying the desired target site, the notaries can check whether each is receiving the same authentication information, called a digital certificate, in response. Whenever any of the notaries report authentication information that is different to that received by the browser or other notaries, it is fairly safe to assume that the particular connection in question has become compromised.
In fact Perspectives can detect when other websites and ISPs have fallen victim to an attack. This is because even if a client's ISP has fallen victim to the attack, the client will be able to detect that the public key received from the fake site is inconsistent with the results returned from the notaries.
By compromising an ISP an attacker can cause the ISP to connect unwitting users to a malicious site instead of the intended legitimate site. The attacker may also use these compromised machines to initiate a Denial of Service (DoS) upon another party.
Certification Authority Generated Certificates
The Perspectives system provides an extra measure of security in those cases where a website is already using a digital certificate provided by approved certification authorities such as: Thwart, VeriSign, Comodo and GoDaddy.
Self-Signed Certificates
It is when we get to websites that do not use a signed digital certificate produced by a recognized certification authority that the “Perspective” system really comes into its own. “Perspective” allows the website in question to use the much less expensive "self-signed" certificates alternative instead.
-
Conficker computer worm will attack this April Fools Day?
| By Vinson | in Safety
The fast-moving Conficker computer worm, a scourge of the Internet that has infected at least 3 million PCs, is set...
-
How to protect from the worm: Tweak in Conficker sparks fears
| By netxpert | in Safety
The worm's alarming outbreak entered a new phase Wednesday as clocks around the world ticked into the first day of ...
-
New Web address endings could be start of turf wars
| By hexcrass | in Computers
A sea change may be coming to cyberspace with Web addresses ending in anything from .a to .z. That has businesses i...
-
How to Shop Online & Use Your Credit Card for Purchases Virtually
| By amandalyn | in Safety
Knowing and protecting yourself from the risks involved with online shopping....
-
Ways parents can help their children safely use Facebook | By RenaS | in Safety
You found out that your son is one of the million under-aged users of Facebook; the new social networking madness t...
-
Computer Crime | By lynn5991 | in Safety
Computer crime has been defined broadly to include any violation of criminal law that involves the use of computer ...
-
Phishing : An Introduction | By Shailesh | in Safety
n simple words, phishing refers to steal of some one's personal information like e mail id and password, credit car...
-
How to Monitor Your Child's Internet Usage | By TeresaFarmer | in Safety
The internet can be very good to use for business, school, games, fun, finding friend and lots of other good things...
-
Are You Being Scammed by Online Surveys | By ja_schmidt | in Safety
One of the popular ways to earn money from the Internet is by way of taking online surveys. A lot of people attest ...
-
Cream Cheese and Egg Dip | By techdoc | in Appetizers
Cream cheese and egg dip is one of the simpler party favorites to prepare and its popularity can be measured by the...
-
Savory Mince | By techdoc | in Recipes
Savory mince can be used in so many different recipes that it is essential to have your own custom base recipe from...
-
Super Succotash | By techdoc | in Recipes
This budget friendly easy recipe is nearly as old as the human race and yet it never fails to titillate and tantali...
-
Southern Style Chicken Seasoning | By techdoc | in American Cooking
Here is how to make a wonderful Southern Style Chicken Seasoning that has KFC in its sights....
-
About War Driving | By techdoc | in Computers
Discuss war driving and wireless networking hacking, their differences and countermeasures....








No comments yet.