iGuRu.gr spoke with Vitaly Kamluk, Principal Security Researcher at Kaspersky Lab. The aim of the following interview is to provide our readers with a mapping of online security in Greece. Mr.Vitaly Kamluk, in addition to an extensive description with data on the online security landscape in Greece, will give you very interesting advice for your personal security.
1) iGuRu.gr Are there any recorded attacks by Kaspersky Lab in Greece?
Digital attacks with malicious codes are a global phenomenon and are usually carried out using the same methods. The most dangerous and at the same time the most common attack vector is the so-called “drive-by download”, which exploits vulnerabilities in browsers and their plug-ins, in order to place malicious software on the victim’s computer, without the user’s intervention and without being visible to him. Attacks of this type correspond to more than 68% of all malicious attacks in Greece. In the first quarter of 2014, Greece was ranked 18th worldwide in the ranking of countries at greatest risk of malware attack. At a rate of 30.65%, our Greek customers participating in our cloud network (Kaspersky Security Network) faced at least one attempted malware attack.
Few types of attacks are tailored to specific country data. For example, malware attacks targeting online banking transactions are among them, as the attack method must be adapted to specific banking websites and the corresponding transaction authorization processes.
Furthermore, in the first half of 2014, the percentage of phishing attacks using search engines and email services reached its highest level, reaching 44.47%. These portals are very popular among phishers, as they offer direct access to all services, especially email services.
The category "online financial transactions" was in second place with 25%. It concerns phishing attacks using payment systems (8.56%), and attacks against banks and e-shops. Social networks and blogs are another popular target among phishers in Greece (21.24%), while online games are not a common target of phishing, as they received only 5% of the attacks.
The table below includes data on the services/companies that were the target of phishing in Greece in the first half of 2014. The relevant percentages are based on data from Kaspersky Lab's anti-phishing tools, which identify all phishing links that users attempted to follow (whether included in a spam e-mail or found on the Internet).
2) iGuRu.gr: What is your opinion on cyber security and infrastructure (State and corporate mechanisms) in Greece?
Windows XP remains a very popular operating system in Greece. The fact that Microsoft has ended support for this operating system will affect both businesses and government organizations.
In many cases, IT departments don't have the budget to upgrade hardware, so companies and government organizations are stuck with an operating system that is 13 years old and no longer receiving security updates.
3) iGuRu.gr: Can we say with certainty that there is security on the Internet?
Most people believe that the Internet is generally a fairly secure platform. We use the Internet for very personal things, such as dating, shopping, communicating, managing finances, etc. The problem with the Internet is that when something goes wrong, things can go very badly, very quickly. A big problem is that the Internet is extremely fragmented. Some online resources have extremely high levels of security and a very strong infrastructure, while others have been forgotten and remain extremely vulnerable. There are also sites that we consider very secure and strong, but which tend to become vulnerable, due to the excessive number of interdependencies between systems. It is impossible to protect every single piece of our information systems.
When we use the Internet, we should keep in mind that the worst can happen and that we need to be properly prepared. The problem is that we also use some resources that are outside the Internet world that we trust, such as medical systems, government agencies, etc., which also use the Internet. So when a serious incident occurs – like the Heartbleed vulnerability, the eBay hack, etc. – the consequences are huge.
I can give you some basic tips that can help a user stay safe:
1. When sending personal data or confidential information to someone, make sure that the person is who they say they are.
2. Be suspicious of spam offers. Do not believe in a windfall win or that they are offering you goods or medicines for free.
3. Do not follow links found in messages from unknown senders.
4. Check the authenticity of the URL when entering personal data. Be careful and check if the website addresses contain extra letters or symbols, as this is one of the favorite tricks of scammers targeting unwary users.
5. When typing passwords, use only secure https links (an extended http protocol standard, which supports encryption).
6. Limit the amount of your personal information that is publicly accessible.
7. Use only complex passwords. Use different passwords for different accounts and services. Using only one simple password for your email and social media accounts is like using a small key to lock the main entrance to your house. To avoid torturing yourself trying to remember so many passwords, you can use solutions such as Kaspersky Password Manager, a security system that remembers and protects passwords.
8. Create two email accounts, one strictly private (that you will not use on public sources) for your personal messages and one “public” one for chats, forums, etc.
9. Use only legal software (or open source software from safe sources), as this can guarantee the stable performance of your computer and keep your data safe.
10. Update your software regularly. Also, uninstall programs that you no longer use
11. Use complex security solutions (file/mail/web anti-virus and firewall) with updated anti-virus databases. Be suspicious of files you download from the network. Before opening a file, check it for viruses.
4) iGuRu.gr: How does Kaspersky Lab secure the personal and sensitive data of an ordinary user and a company?
Consumers who use smartphones, PCs and tablets should take the necessary steps to ensure that all their devices are protected with comprehensive security software, such as Kaspersky Internet Security – Multi-Device. Installing an effective solution can give the user the protection they need to avoid any “infection” from digital threats, especially if they use the devices for online payments, visits to social networks and other activities related to personal information.
To mitigate existing and emerging risks, companies must have an effective and easy-to-use security solution, such as Kaspersky Endpoint Security for Business, that covers all potential risks across the entire spectrum of their IT systems and applications. They must also have adequate security policies in place that employees can understand and follow.
Kaspersky Lab has a broad portfolio of solutions for home users and businesses that can help make the Internet a safer place.
6) iGuRu.gr: What is your opinion on "in a short time there will be no anti-viruses"?
Eugene Kaspersky, CEO and President of Kaspersky Lab, has given an excellent answer to this question. Specifically, he stated that: “In recent years, I have heard many times that antivirus solutions are considered dead. However, they are still here with us – and they remain very much alive. I completely agree that single-tier solutions that simply detect viruses based on signatures do not even come close to providing adequate levels of protection – neither for individual users, nor for small or large businesses. This has been the reality for many years. Today, security is a combination of various technologies – heuristics, sandboxing, cloud protection, etc. – which are key elements of any quality security solution, in addition to the classic and proven signature-based virus detection tools.”.
7) iGuRu.gr: After the leaks from Snowden, has Kaspersky Lab taken additional measures to protect consumers?
As for their technical aspects, the information disclosed does not affect our daily work. Kaspersky Lab experts in the Research and Development department, as well as in the Global Research and Analysis Team, constantly monitor and analyze the severity and scope of existing and emerging digital threats. For example, with the research of our experts, we were able to uncover sophisticated campaigns such as Flame, Stuxnet, Mask, etc. This leading-edge threat intelligence is integrated into our award-winning product portfolio, as we are committed to providing security to our customers, regardless of the origin of the threat source. We are constantly improving the functionality of our products and launching new products, according to the plan we have outlined. It is worth mentioning that based on our plans, we will soon introduce the next generation of our consumer solution Kaspersky Internet Security.
8) iGuRu.gr: In 2014 in Greece we observed an increase in the operation of domestic online markets. What risks are there in an online market and how can your company help?
Online shopping can save us a lot of time and make our lives easier. According to a survey (PDF), online shopping is the most popular activity, with 87% of respondents in Europe using these services. However, the same technologies also make life easier for online criminals, offering them new and easy ways to steal users’ money. Using stolen payment data is an effective and popular way to make a quick buck. Although banks are trying to protect their customers, attacks on individual users remain quite common. Hacking a bank takes longer, is more expensive and involves a higher risk for fraudsters. In contrast, many individual users use computers with various vulnerabilities, which makes them easier to breach. By stealing a relatively small amount from each compromised online bank account, a cybercriminal has less chance of being detected.
There are several risks that users should be aware of when making online purchases. Specifically:
• Banking Trojans that can infect devices and collect payment information. Some of them can even perform financial transactions on behalf of users.
• Phishing, or the creation of fake copies of websites in order to obtain confidential user data, is a common digital threat. The main purpose of phishing is to convince victims that they are visiting an authentic site and not a fake one. It can be the website of an online store or a bank. These attempts are often successful. Thus, phishing campaigns are used both as a tool to extract information and as part of a complex attack that lures users to a page, from where malicious software is “downloaded” to their devices.
In addition to the basic security tips we mentioned earlier, when we need to make a purchase, we advise users to use online security solutions, which can stay ahead of developments in the field of "digital crime" and detect attempts to intercept users' sensitive data before their financial details fall into the wrong hands.
This is the principle that characterizes the technologies incorporated into Kaspersky Internet Security – Multi-Device 2014, a comprehensive security solution for devices running Windows, OS X and Android operating systems.
Windows PCs are more frequently targeted by attacks than devices running other operating systems. That's why Kaspersky Lab's solution includes Safe Money for PC. This is a high-level technology developed to protect customers' online financial transactions. This technology combines an impressive range of features, including:
• Automatic verification of security certificates for banking or electronic payment sites
• Scanning function to immediately identify any vulnerability in customers' computers, which could make them vulnerable to an attack
• Activation of two levels of security for data entry – the Secure Keyboard and the Virtual Keyboard – which ensure that passwords and credit card details can be typed without fear of eavesdropping.
Kaspersky Internet Security – Multi-Device 2014 integrates proactive security technologies, aiming to eliminate the main problem – which is none other than financial fraud. At the same time, it multiplies the benefits of online payments.
9) iGuRu.gr: Is Kaspersky considering offering protection to Content Management Platforms (CMS) in the future?
According to our experts’ estimates, the percentage of malicious code entering websites through CMS platforms, such as Joomla, WordPress, and Drupal, is extremely small, especially compared to other known and emerging cyber threats. When it comes to protecting website content, it is best to cover not only several different CMS platforms, but also to check all files and folders at the system level, regardless of the CMS platform. Kaspersky Lab’s portfolio includes suitable security solutions for Microsoft Windows, Microsoft Windows Server Enterprise Edition, and Linux environments. When it comes to collaboration tools, such as Microsoft SharePoint, Kaspersky Lab offers the Safe Collaboration feature as part of the Kaspersky Endpoint Security for Business suite. And of course, it is necessary to regularly update the software of a CMS platform to ensure that your operating system and the installed CMS platform are up-to-date and properly protected against known vulnerabilities.
10) iGuRu.gr: Why Kaspersky?
In today's digital security market, it is difficult to talk about uniqueness in functionality. Differentiation is more about the different technological approaches that solution providers use in their products.
There are a few things that make Kaspersky Lab unique. First of all, we create all of our products ourselves, because we have the vision and the ability to do so. Compared to some of our competitors, Kaspersky Lab rarely buys third-party solutions to integrate into its software. This gives our capabilities much greater integrity and ensures easier management of our security solutions.
Second, we already provide technologies that independent organizations (such as Gartner and Forrester) recognize as representing future trends in the information security space. We also follow a “zero-omission” policy supported by one of the best whitelists (databases of legal software) on the market, which – based on independent testing – includes 97% of corporate software solutions and 96% of consumer software. This is a very big step in the evolution of protection against threats that exploit vulnerabilities that are not already known (zero-day threats). Based on this policy, only software solutions included in the whitelist, which is maintained daily, can “run” on devices. This means that no new malware will be able to “run” on a protected computer. We predicted the success of this technology several years before many of our competitors began to realize it.
Both Kaspersky Lab's consumer and enterprise solutions are consistently among the leaders in their fields. They outperform alternative solutions in several features, as proven by tests conducted by independent laboratories (AV-Comparatives, AV-Test, etc.).
Based on statistics we have gathered from the most authoritative testing organizations, Kaspersky Lab ranks first in the ranking of the top three security solution companies. This ranking is based on whether the solutions have consistently performed well in independent tests throughout 2013. Kaspersky Lab solutions ranked first in 41 out of a total of 79 tests, while in 20 they were in second or third place. Kaspersky Lab was in the top three positions much more often than its competitors. More relevant information can be found at this link..
We would like to thank Mr. Vitaly Kamluk for his very interesting answers, and Kaspersky Lab in general for its work. We also thank our collaborator Mr. Konstantinos Memos.
Source: secnews.gr


