<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The New New Internet &#187; WEIS 2010</title>
	<atom:link href="http://www.thenewnewinternet.com/tag/weis-2010/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thenewnewinternet.com</link>
	<description>The Latest News in Cybersecurity</description>
	<lastBuildDate>Fri, 10 Feb 2012 18:32:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Simple Economics is the Answer to Cyber Attacks</title>
		<link>http://www.thenewnewinternet.com/2010/06/09/simple-economics-is-the-answer-to-cyber-attacks/</link>
		<comments>http://www.thenewnewinternet.com/2010/06/09/simple-economics-is-the-answer-to-cyber-attacks/#comments</comments>
		<pubDate>Wed, 09 Jun 2010 13:51:43 +0000</pubDate>
		<dc:creator>Michael W. Cheek</dc:creator>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[WEIS 2010]]></category>

		<guid isPermaLink="false">http://www.thenewnewinternet.com/?p=6269</guid>
		<description><![CDATA[Carefully crafted targeted attacks using social engineering can be extremely difficult for users to detect. However, despite the rise in the use of social engineering, most people are still receiving generic spam campaigns instead. Why? Economics provides the answer, according to a Microsoft researcher speaking at the at the WEIS 2010 workshop. &#8220;The profit is [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.thenewnewinternet.com/wp-content/uploads/money.jpg"><img class="alignright size-thumbnail wp-image-3868" title="money" src="http://www.thenewnewinternet.com/wp-content/uploads/money-150x150.jpg" alt="" width="150" height="150" /></a>Carefully crafted targeted attacks using social engineering can be extremely difficult for users to detect. However, despite the rise in the use of social engineering, most people are still receiving generic spam campaigns instead. Why? Economics provides the answer, according to a Microsoft researcher speaking at the at the <a href="http://weis2010.econinfosec.org/program.html" target="_blank">WEIS 2010</a> workshop.</p>
<p>&#8220;The profit is far higher for scalable attacks,&#8221; said Cormac Herley of Microsoft Research. &#8220;The rewards  are growing linearly and the costs are growing sub-linearly. In that  case, you attack everyone as often as possible.&#8221;</p>
<p>In a presentation on his paper titled <a href="http://weis2010.econinfosec.org/papers/session5/weis2010_herley.pdf" target="_blank">&#8220;The  Plight of the Targeted Attacker in a World of Scale,&#8221;</a> Herley pointed out that scalable attacks are still relatively successful and do not require as much effort, making them more lucrative for cyber criminals.</p>
<p>&#8220;Non-scalable attacks have to be selective attacks. Every attack costs  you something,&#8221; he said. &#8220;If the non-scalable attacks can&#8217;t match  the return of the scalable attacks, she should change tactics. At equal  costs, she needs a way better yield. But competing on yield makes no  sense because when she extracts the same value per victim, there&#8217;s too  much effort.&#8221;</p>
<p>The cost of creating a target attack dwarfs the gains, according to Herley.</p>
<p>&#8220;Elaborate non-scalable attacks fail to happen because the benefit to  the attacker is far less than the cost we represent to the attacker,&#8221; he  said. &#8220;Most users never see most attacks.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thenewnewinternet.com/2010/06/09/simple-economics-is-the-answer-to-cyber-attacks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

