Google Search

Showing posts with label experts. Show all posts
Showing posts with label experts. Show all posts

Wednesday, August 22, 2012

Security risk: Sensitive data can be harvested from a PC even if it is in standby mode, experts say

ScienceDaily (Aug. 10, 2012) — When you switch off your computer any passwords you used to login to web pages, your bank or other financial account evaporate into the digital ether, right? Not so fast! Researchers in Greece have discovered a security loophole that exploits the way computer memory works and could be used to harvest passwords and other sensitive data from a PC even if it is in standby mode.

Writing in a forthcoming issue of the International Journal of Electronic Security and Digital Forensics, Christos Georgiadis of the University of Macedonia in Thessaloniki and colleagues Stavroula Karayianni and Vasilios Katos at the Democritus University of Thrace in Xanthi explain how their discovery could be used by information specialists in forensic science for retrieving incriminating evidence from computers as well as exploited by criminals to obtain personal data and bank details.

The researchers point out that most computer users assume that switching off their machine removes any data held in random access memory (RAM), this type of fast memory is used by the computer to temporarily hold data currently used by a given application. RAM is often referred to as volatile memory, because anything contained in RAM is considered lost when a computer is switched off. Indeed, all data is lost from RAM when the power supply is disconnected; so it is volatile in this context.

However, Georgiadis and colleagues have now shown that data held in RAM is not lost if the computer is switched off but the mains electricity supply not interrupted. They suggest that forensics experts and criminals might thus be able to access data from the most recently used applications. They point out that starting a new memory-intensive application will overwrite data in RAM while a computer is being used, but simply powering off the machine leaves users vulnerable in terms of security and privacy.

"The need to capture and analyse the RAM contents of a suspect PC grows constantly as remote and distributed applications have become popular, and RAM is an important source of evidence," the team explains, as it can contain telltale traces of networks accessed and the unencrypted forms of passwords sent to login boxes and online forms.

The team tested their approach to retrieving data from RAM after a computer had been switched off following a general and common usage scenario involving accessing Facebook, Gmail, Microsoft Network (MSN) and Skype. They carried out RAM dumps immediately after switch off at 5, 15 and 60 minutes. They then used well-known forensic repair tools to piece together the various fragments of data retrieved from the memory dumps.

The team was able to reconstruct login details from the memory dumps for several popular services being used in the Firefox web browser including Google Mail (GMail), Facebook, Hotmail, and the WinRar file compression application. "We can conclude that volatile memory loses data under certain conditions and in a forensic investigation such memory can be a valuable source of evidence," the team says.

Share this story on Facebook, Twitter, and Google:

Other social bookmarking and sharing tools:

Story Source:

The above story is reprinted from materials provided by Inderscience, via AlphaGalileo.

Note: Materials may be edited for content and length. For further information, please contact the source cited above.

Journal Reference:

Christos Georgiadis, Stavroula Karayianni and Vasilios Katos. A framework for password harvesting from volatile memory. International Journal of Electronic Security and Digital Forensics, 2012

Note: If no author is given, the source is cited instead.

Disclaimer: Views expressed in this article do not necessarily reflect those of ScienceDaily or its staff.


View the original article here

Friday, June 22, 2012

To combat identity theft, protect computer, experts say

ScienceDaily (Mar. 19, 2012) — Having a triple-threat combination of protective software on your computer greatly reduces your chances of identity theft, according to a study led by a Michigan State University criminologist.

In a survey of more than 600 people, the researchers found that computer users who were running antivirus, anti-adware and anti-spyware software were 50 percent less likely to have their credit card information stolen.

The study appears in the research journal Deviant Behavior.

"When you think about antivirus software protecting you, you might think about it keeping your files safe and not losing your music and photos," said Thomas Holt, MSU associate professor of criminal justice and lead researcher on the project. "The important thing we're finding here is that it's not just about protecting your files, but also about protecting you economically -- about reducing your chances of being a victim of identity theft."

Holt's co-investigator was Michael Turner, associate professor at the University of North Carolina-Charlotte.

According to the study, about 15 percent of respondents said they had experienced computer-related identity theft in the past year. Males were more likely to be victims, Holt said.

"We're not sure what this might be a consequence of," he said. "Is it that males are less careful about what they do online? Is it a difference in how they shop online or conduct online commerce?"

Those who engaged in "computer-related deviance" -- such as downloading pirated music or pornographic images -- were more likely to be victims of identity theft, the study found. This is a large risk for users because pirated movies and music may contain malware and place users at risk for harm.

But the most practical news for computer users was the combined protective factor of the antivirus, anti-spyware and anti-adware software, each of which has a different function for keeping a computer safe, Holt said.

Antivirus software detects and removes malicious software programs such as viruses and worms that can corrupt a computer, delete data and spread to other computers. Anti-spyware and anti-adware programs, meanwhile, are designed to protect against software that either self-installs without the user's knowledge or is installed by the user and enables information to be gathered covertly about a person's Internet use, passwords and so on.

"You have a much better chance of not getting your credit card number stolen if you have all three forms of protective software," Holt said.

Share this story on Facebook, Twitter, and Google:

Other social bookmarking and sharing tools:

Story Source:

The above story is reprinted from materials provided by Michigan State University.

Note: Materials may be edited for content and length. For further information, please contact the source cited above.

Journal Reference:

Thomas J. Holt, Michael G. Turner. Examining Risks and Protective Factors of On-Line Identity Theft. Deviant Behavior, 2012; 33 (4): 308 DOI: 10.1080/01639625.2011.584050

Note: If no author is given, the source is cited instead.

Disclaimer: Views expressed in this article do not necessarily reflect those of ScienceDaily or its staff.


View the original article here