Latest news
Authors: Markus Jakobsson and Zulfikar RamzanPages: 582
Publisher: Addison-Wesley Professional
ISBN: 0321501950


Introduction
Even as the security industry celebrates solid sales thanks to compliance laws, the last few years have not been characterized by a state of growing security. In fact, evolving attacks have fueled a strong underground economy and malware authors now have a solid cash incentive to make sure their malicious code infects as many computers as possible and avoids detection.
Two well-known security researchers and several contributors are the authors behind "Crimeware", a book that promises to deliver information about new attacks and provide advice when it comes to defenses. Read on to find out what it offers.
About the authors
Markus Jakobsson, Ph.D., is the principal scientist at Palo Alto Research Center and an adjunct associate professor at Indiana University. The coauthor of more than one hundred peer-reviewed articles and co-inventor of more than fifty patents, Markus studies the human factor of security and cryptographic protocols with an emphasis on privacy.
Zulfikar Ramzan, Ph.D., is a senior principal researcher with Symantec Security Response. Coauthor of more than fifty technical articles and one other book, Zulfikar is a frequent speaker on his areas of expertise: theoretical and practical aspects of information security and cryptography.
Inside the book
Despite not having the weight of a telephone book, this title contains a significant amount of information. There's enough background to get you into the topic but the most interesting parts are naturally those dedicated to the illustration of current threats and how the work. Gary McGraw writes about coding errors, a group of authors discuss crimeware and peer-to-peer networks and there are also details on crimeware in firmware and small devices.
Although short, the chapter dedicated to virtual worlds and fraud can be considered a look into the future as it provides details on threats that are certainly going to become bigger as more people discover these computer-generated worlds. Both gamers and security professionals would benefit in learning what threats exist in massively multiplayer online games (MMOGs). I suspect that the second edition of this book will have a significantly larger chapter about the topic.
Online advertising fraud is a significant problem and "Crimeware" presents a chapter with compelling data written by several authors and the Google Ad Traffic Quality Team. Also a hot topic - cybercrime and politics - gets its own share with an illustration of domain name abuse, phishing, malicious code, and more.
When it comes to technical defense techniques, you discover details about crimeware-resistant authentication and there's also a case study dedicated to an in-depth defense against spyware.
Final thoughts
"Crimeware" is an eye-opening book that shows you what the bad guys are doing, it teaches you defensive techniques, and even offers a glimpse of what the future might bring.A very informative read that will kickstart your interest to discover more information about the topic.
Spotlight

The security of WordPress plugins
Posted on 18 June 2013. | Checkmarx’s research lab identified that more than 20% of the 50 most popular WordPress plugins are vulnerable to common Web attacks, such as SQL Injection.

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.







