You are here: silicon.com > Software > Malware

Malware

Phishing - can software stop it?

eBay among those already using anti-fraud tools

Tags: phishing, wholesecurity, ebay

By Alorie Gilbert

Published: 17 August 2004 08:05 BST

A new programme to help companies combat the growing form of online fraud known as 'phishing' has been created by US internet security firm WholeSecurity.

Phishing starts with a forged email apparently from a legitimate company, such as eBay or Citibank, telling the recipient that his or her account information has expired - or something of the sort. The recipient is instructed to click on a link that leads to a fake website. The site asks for confidential data such as credit card numbers.

WholeSecurity is among a number of companies developing technology to alert consumers to phishing fraud. Its program, called Web Caller-ID, is already in use at eBay. The online auctioneer has incorporated the technology into its internet toolbar with a feature called Account Guard. It detects fraud sites purporting to be connected to eBay and its PayPal subsidiary with 98 per cent accuracy, according to WholeSecurity. The tool notifies users if they enter such a site.

Hundreds of thousands of eBay members have downloaded the free program since the company launched it in February, an eBay representative said.

Now WholeSecurity is trying to license the software to other companies doing business online, allowing them to incorporate it into their toolbars or distribute to their customers as a web browser plug-in. Scott Olson, WholeSecurity's senior vice president of marketing, said banks and other financial institutions are one of WholeSecurity's target markets for the product.

The program analyzes web addresses for clues that might lead to fraudulent sites. For instance, if the URL is long and convoluted, or if it consists of a long string of numbers separated by periods - an IP address - there's a good chance it's a false site, Olson said. The program also checks whether the domain name was registered recently or its operator is using a free web hosting service - all tell-tale signs of phishing activity, Olson said.

Other companies that offer antiphishing products include EarthLink, Webroot Software and PostX. Microsoft and Yahoo are also working on such programs.

Alorie Gilbert writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
ASP.NET C# Web Developer

Simunix Ltd, established 1998, is the owner of various websites, including www.ukphonebook.coma UK telephone numbers directory, development of the ...

Systems Administrator - ITIL, Linux, Hosting - Relocaters welcome

My client is an expanding hosting solutions company currently offering several positions created by this successful growth.They require Systems ...

Risk Manager (fraud/operational) - UK (permanent)

Risk Manager (fraud/operational) - UK (permanent) We are currently looking for a Risk Manager with fraud and operational experience for our client ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: