[00:00.000 --> 00:19.220] Individuals may or may not need, like, avatar creation, different artistic services, stuff that might not be illegal but could have some illicit application, and 10% sold ICQ numbers, which is odd given that ICQ is free, but lots of people sold numbers of different width and length and number combinations, etc. [00:19.900 --> 00:21.680] So if you... Yes, sir. [00:21.680 --> 00:22.800] Time on botnets? [00:25.580 --> 00:30.240] So, in other words, leasing out a botnet for, say, DDoS, we listed that under cybercrime services. [00:30.540 --> 00:40.460] So, if you're leasing for DDoS, if you're selling spam services, anything that is directly related to the facilitation of types of cybercrime, we list it there. [00:41.640 --> 00:49.760] In terms of web hosting and otherwise, that falls under cybercrime services when they specifically state this is for spam or malware or child porn or something like that. [00:49.760 --> 01:03.520] On malware, most of the common resources that were available were Trojans, cryptors, joiners, polymorphic tools, things to help facilitate or spread malware through different markets were also available. [01:03.700 --> 01:06.680] And these were the cheapest things that we found within the marketplace. [01:07.020 --> 01:08.680] People also sold iframes. [01:08.840 --> 01:17.080] We listed iframe traffic under malware services, given that most of them talked about uploads or downloads of different people's malware. [01:17.080 --> 01:25.380] This could be listed as a service, but we included it under this category, just based on the notion of selling either iframe software or iframe traffic. [01:26.300 --> 01:32.400] In terms of pricing, there was significant variability depending on what individuals asked for. [01:33.780 --> 01:34.940] And this is in U.S. dollars. [01:35.960 --> 01:39.160] Most of the individuals listed pricing based on U.S. currency. [01:39.860 --> 01:43.880] A limited number based information on rubles or web money. [01:43.880 --> 01:47.420] If they listed web money U.S., we just went with that as a U.S. currency. [01:48.260 --> 01:51.800] The average price for bots here being $322. [01:52.260 --> 01:59.740] Whether you were buying a custom bot at $2,000 or getting someone else's existing botnet that they just no longer wanted for $30. [02:00.240 --> 02:05.020] With bugs, we saw a limited number of people selling actual new exploits. [02:05.020 --> 02:10.420] The price being $40 there for the one that actually listed how much it was. [02:10.940 --> 02:14.960] With cryptors, joiners, polymorphic engines, anywhere from $0.20 to $49. [02:15.440 --> 02:17.260] So, significant variability there. [02:17.400 --> 02:18.580] The average being about $13. [02:19.460 --> 02:22.340] FTP resources, whether for infection or otherwise. [02:23.020 --> 02:25.260] Iframe tools, traffic within iframes. [02:25.700 --> 02:27.360] And Trojans finally at the bottom. [02:27.360 --> 02:31.760] The max price for a Trojan was $5,000 for a custom build. [02:32.520 --> 02:34.980] For as little as $2 depending on what you wanted. [02:35.340 --> 02:39.860] And in terms of Trojans, the most common thing that we saw being offered was Pinch. [02:40.040 --> 02:43.840] If you're familiar at all with the Russian community, Pinch is a pretty common Trojan there. [02:44.340 --> 02:46.880] For different types of theft of information. [02:47.320 --> 02:50.800] It's advertised as being able to steal 30 different passwords from different programs. [02:50.800 --> 02:53.180] The most common ones being Mozilla. [02:53.480 --> 02:56.540] All the Internet Explorer or Microsoft products. [02:56.960 --> 03:01.520] As well as different functions including the BAT and a few other programs. [03:02.100 --> 03:05.640] So, within this particular build of Pinch, you could steal a lot of information. [03:05.840 --> 03:08.000] Get different resources very easily. [03:08.720 --> 03:11.840] In terms of polymorphic engines and cryptors. [03:12.040 --> 03:14.300] This is an ad for something called Polaris Crypt. [03:14.700 --> 03:18.600] It binds the executable and can be used for different types of attacks. [03:18.600 --> 03:21.480] There's a naturally occurring encryption signature. [03:21.700 --> 03:25.560] You can see after crypting the file can't be burned or detected by antivirus. [03:25.740 --> 03:28.240] And it's a well executed design that's nice to look at. [03:28.380 --> 03:29.940] So, the price of the cryptor is $20. [03:30.300 --> 03:31.260] Web money U.S. [03:31.640 --> 03:34.660] These little kinds of comments like well executed design. [03:34.860 --> 03:35.700] Nice to look at. [03:35.840 --> 03:37.700] Were part of the sales process. [03:37.920 --> 03:41.700] And it helped to ensure individuals who might not be computer savvy. [03:42.540 --> 03:44.360] Or the most technically skilled hacker. [03:44.520 --> 03:48.560] If it had an easy to use GUI, you could probably get a little bit more for it on the market. [03:48.600 --> 03:50.500] Because someone could use it quite quickly. [03:51.160 --> 03:54.660] Thunder Joiner was another binder tool that was out there. [03:55.000 --> 03:57.980] For $15 you could actually get it pretty cheaply. [03:58.160 --> 04:01.240] It included 42 of the most popular icons. [04:01.520 --> 04:05.700] So, whether you wanted to send something as a GIF or a GIF or whatever the case might be. [04:05.860 --> 04:06.920] Pretty easy to use. [04:07.320 --> 04:13.140] On the iframe side, we saw individuals selling both iframe traffic and actual iframe malware. [04:13.140 --> 04:15.580] This is an ad for the genome iframer. [04:15.720 --> 04:16.860] Has anyone heard of genome before? [04:18.000 --> 04:21.300] It's somewhat popular within the iframe community. [04:21.420 --> 04:23.040] Although there are other ones that are out there. [04:23.620 --> 04:26.500] You can edit and delete different resources with this. [04:26.660 --> 04:27.960] There's different types of encryption. [04:28.160 --> 04:29.620] This one had its own built-in kit. [04:30.060 --> 04:35.260] And for $20 U.S., through Web money, you could get access to this particular iframe script. [04:36.240 --> 04:43.120] And if you chose not to actually buy an iframe malware kit, you could instead access services through another provider. [04:43.320 --> 04:50.320] So, if you already had an iframe setup in place, an iframe infection, you could rent out or lease that particular individual's traffic. [04:50.680 --> 04:54.680] So, this ad, we sell an upload of all countries that are included on the list. [04:54.700 --> 04:56.860] In other words, where we have infections for $25. [04:57.360 --> 05:00.460] You can choose what countries you want traffic to come from. [05:00.460 --> 05:02.120] You get real-time updates. [05:02.380 --> 05:05.340] You can test the item for free with 50 uploads. [05:05.860 --> 05:08.380] You can see this bullet point here. [05:08.580 --> 05:09.380] Friendly service. [05:09.620 --> 05:12.540] A sweet and smart girl is always glad to assist you. [05:13.520 --> 05:15.060] A money-back approach. [05:15.960 --> 05:17.400] A money-back guaranteed. [05:17.540 --> 05:21.900] The service is under a regular quality check in order to find any mistakes in the work. [05:22.040 --> 05:23.760] And to guarantee the quality of the system. [05:23.920 --> 05:25.860] So, there's this reference to quality. [05:25.980 --> 05:27.340] To the value of what you're purchasing. [05:27.340 --> 05:31.060] With such an approach, we can guarantee 99.9% validity. [05:31.320 --> 05:33.360] And of course, with a stable working contract. [05:34.080 --> 05:35.600] And this last bullet point here. [05:35.800 --> 05:37.360] Information for traffic loaders. [05:37.480 --> 05:38.460] If you have traffic. [05:38.640 --> 05:40.380] If you have an iframe setup in place. [05:40.380 --> 05:42.320] We can offer a partnership program. [05:42.620 --> 05:44.560] We pay for successful installations. [05:44.920 --> 05:46.000] $80 for the U.S. [05:46.180 --> 05:47.340] Up to 1k of traffic. [05:47.560 --> 05:48.740] Other countries $25. [05:49.320 --> 05:50.740] Everything is done honestly. [05:51.020 --> 05:52.640] The average envelope mix is $4. [05:53.080 --> 05:54.920] This whole notion of honesty, trust. [05:55.040 --> 05:56.060] I know it sounds odd. [05:56.060 --> 05:59.420] We're talking about individuals engaging in some illicit activities. [05:59.700 --> 06:01.480] They don't know one another face to face. [06:01.640 --> 06:04.380] It's all incumbent upon whether you're going to deliver goods or not. [06:04.560 --> 06:08.420] So, trust is a very important mechanism for these individuals. [06:09.140 --> 06:10.900] In terms of bots. [06:11.120 --> 06:15.000] This is an ad for an individual leasing out their botnet for $100 a month. [06:15.460 --> 06:17.200] 300 nodes within the botnet. [06:18.360 --> 06:21.360] They say that there are 9,000 bots within the network. [06:21.560 --> 06:24.200] Although 200 to 1500 are online regularly. [06:24.200 --> 06:26.000] You can see the country mix here. [06:26.520 --> 06:27.680] And this price here. [06:28.060 --> 06:28.540] Super price. [06:28.760 --> 06:31.880] 100 WMZ web money U.S. a month. [06:32.120 --> 06:34.320] Spammers are in shock over such an offer. [06:34.680 --> 06:37.260] In other words, you want to work with us, we're going to give it to you cheap. [06:37.460 --> 06:40.480] We also make networks for individual requests or orders. [06:40.700 --> 06:41.060] Yes, sir. [06:41.120 --> 06:41.660] Question in the back. [06:50.260 --> 06:54.500] So, the question is, do they actually talk about specifics of the infrastructure or how it works? [06:54.960 --> 06:55.480] Mm-hmm. [06:55.940 --> 06:57.880] Some of the individual advertisers did. [06:58.160 --> 07:01.460] This was just a generic kind of post to elicit questions. [07:01.640 --> 07:04.460] Some of those were in the deeper part of the conversation here. [07:04.600 --> 07:06.140] And I don't remember this one in specific. [07:06.140 --> 07:09.580] But initially, this is more like a taste, trying to get people interested. [07:10.000 --> 07:12.160] They would sometimes say, knock me in ICQ. [07:12.240 --> 07:13.180] I'll tell you all the specifics. [07:13.420 --> 07:14.400] So, sometimes you'd get it. [07:14.440 --> 07:15.180] Sometimes you wouldn't. [07:15.280 --> 07:19.320] But those who provide more clarity in their ads would definitely get more business. [07:19.500 --> 07:23.000] Because the more specificity you can provide, the more we can likely trust you. [07:23.700 --> 07:25.560] Did they ever use... [07:25.560 --> 07:29.220] Good point. [07:29.460 --> 07:29.760] Yes, sir. [07:29.780 --> 07:31.480] Did they ever list the bot name they were using? [07:31.740 --> 07:33.700] Did they list the name of the bot that they were using? [07:33.700 --> 07:34.640] Primarily, no. [07:34.760 --> 07:37.400] Most of them would not say how their infrastructure was being run. [07:37.540 --> 07:39.400] They would instead say that they had a bot set up. [07:40.000 --> 07:46.460] If you were selling a particular make of a botnet, like Suicide or one of the other ones, they would sometimes mention it. [07:46.560 --> 07:51.280] But in individuals who were just leasing out their services for spam or otherwise, they would just say, no, we have a botnet. [07:51.620 --> 07:54.980] But it's a good question because it would help to further the information that we have. [07:55.280 --> 07:55.920] Question in the back? [08:01.080 --> 08:02.520] Did the forum include what? [08:04.460 --> 08:05.180] Hidden services. [08:05.180 --> 08:09.440] So, in other words, I'm not quite sure what you mean. [08:09.580 --> 08:09.880] Like Tor? [08:10.140 --> 08:12.600] Were the forums themselves... [08:13.420 --> 08:15.500] Oh, were the websites anonymous? [08:15.720 --> 08:17.960] Were the forums where they were hosted hard to access? [08:18.480 --> 08:23.760] These were all the publicly accessible portions of the forum, not the closed buy-in parts of the board. [08:24.040 --> 08:30.480] But the actual forums that we drew from are those with relatively large reputations within the community like Expolate and Mazzafaka. [08:30.480 --> 08:33.940] So, no, these are not the closed forums. [08:34.140 --> 08:37.040] But these are at least insights into what is publicly accessible. [08:37.280 --> 08:41.120] That does raise some questions about what we're actually talking about here. [08:41.360 --> 08:45.380] Because if we were talking about the closed boards, there might be different resources accessible or available. [08:45.660 --> 08:52.040] But at least from a publicly accessible front, those who don't require registration or paid access to get in. [08:52.200 --> 08:54.920] So we're at least seeing something about what these forums look like. [08:55.380 --> 08:56.260] Yes, another question? [09:01.950 --> 09:06.170] In terms of who the customers of these individuals are, it's somewhat hard to say. [09:06.170 --> 09:15.870] Since all the posts were in Russian that we analyzed, the assumption would be these are individuals either living in Russia or former Soviet republics or possibly Russians living in the U.S. [09:16.070 --> 09:18.270] We did not see U.S. [09:18.730 --> 09:20.410] posts, or at least posts in English. [09:20.410 --> 09:25.590] If one were made, they were either directed to the English subsection or their comments were ignored. [09:25.810 --> 09:34.810] So my supposition would be these might be Russian citizens living in the U.S., but at least based on the discussions, unless we were working with a forensic linguist, it would be somewhat hard to ferret out. [09:37.350 --> 09:46.250] Moving beyond the malware side, in terms of services, the most common thing that we saw were DDoS services, followed up by spam and proxies. [09:46.510 --> 09:49.870] And the pricing for these items was relatively varied. [09:50.230 --> 10:03.850] Just to give you an example of what we saw in terms of spam, good day to the visitors of the forum, price for a million delivered mails starting at $100 and the price drops real fast, practically to $10 for regular clients. [10:04.070 --> 10:05.530] Selection of countries is free. [10:05.730 --> 10:08.590] That issue of regular clients is something that came up quite a bit. [10:08.730 --> 10:13.630] The more often you work with an individual, the more likely they were to give you some kind of bulk rate discount. [10:14.050 --> 10:17.190] So trust helps to drive much cheaper prices. [10:17.410 --> 10:19.970] This is another example of a spam advertisement. [10:20.390 --> 10:22.390] In the middle of it, you'll see the pricing. [10:22.390 --> 10:24.450] 120 for 1 million inboxes. [10:25.290 --> 10:29.250] 150 if you want it broken out by certain countries, the U.S., Australia, etc. [10:29.790 --> 10:31.690] They could do job spam. [10:31.950 --> 10:37.370] They could do dating spam, depending on what you want, from 1000K with daily database updates. [10:37.550 --> 10:42.870] So there's some variety here in different resources at your disposal in terms of spam. [10:43.130 --> 10:50.330] On the web hosting side, this individual was posting an advertisement for their own IP space in Hong Kong. [10:50.810 --> 10:53.050] They talked about the access that you could get. [10:53.330 --> 10:58.030] Their services were available in Moscow, Hong Kong, the U.S., Malaysia. [10:58.570 --> 11:05.790] And this bottom line here, money back for dedicated servers is only possible if there's unavailability of the server by our fault. [11:05.870 --> 11:08.170] In other words, if this is our problem, we'll give you your money back. [11:08.350 --> 11:10.590] If you screw up somehow, that's your own problem. [11:10.950 --> 11:19.150] When it comes to web hosting, this is the one thing where individuals were relatively specific about the illegality of their products. [11:19.150 --> 11:32.050] So this top post here, it's categorically prohibited to use our resources for child porn, zoophilia, sites that promote violence, projects aimed at breaking into government organizations and executive branch bodies. [11:32.470 --> 11:39.050] But the individual below says, I'd like to offer your attention for our hosting services for resources with non-standard content. [11:39.290 --> 11:44.370] So logs, exploits, Trojans, wares, adults, drop products, botnets, spam, and others. [11:44.570 --> 11:45.890] We'll take whatever you want. [11:46.030 --> 11:47.370] You just let us know what you need. [11:47.370 --> 11:50.950] So there's some variability in terms of these different web hosters. [11:51.190 --> 11:56.790] If you want someone who's going to help you engage in something that's particularly illicit, you can find them within the marketplace. [11:58.230 --> 12:06.730] Some individuals offered hacking services, and these were primarily geared toward breaking into email or in some cases doing some sort of web-based attack. [12:06.730 --> 12:10.110] But in terms of overall hacking services, they were somewhat limited. [12:10.390 --> 12:14.430] Since I'm kind of brushing up against the time, I'm going to skip to this DDoS ad. [12:14.750 --> 12:15.550] Which is nice. [12:15.690 --> 12:16.790] We've got another 15 messages. [12:17.250 --> 12:17.890] Another 15? [12:18.110 --> 12:18.250] Yeah. [12:18.410 --> 12:18.590] Okay. [12:18.890 --> 12:21.950] I've got about another 30 slides, so I'm going to try to flow pretty quick. [12:22.970 --> 12:28.050] In terms of this DDoS ad, this is just a nice example of what I was talking about earlier. [12:29.390 --> 12:32.670] The pricing is based on how long you want the attack to take place. [12:32.670 --> 12:33.910] So for an hour, it's $15. [12:34.250 --> 12:35.710] 48 hours, it's $180. [12:36.610 --> 12:40.090] Difficult projects are negotiable, and our DDoS is organized using bots. [12:40.250 --> 12:43.770] And this is where they talked about botnets undergirding the infrastructure pretty heavily. [12:43.970 --> 12:47.610] This quote at the bottom, large quantity of bots online, quantity grows every day. [12:47.730 --> 12:51.870] Bots are located in different time belts, which allows the DDoS to work 24 hours a day. [12:51.990 --> 12:55.810] Here we see some specificity about the bot structure and what all goes on. [12:56.970 --> 13:05.730] In terms of the economics of an attack, let's just say for the sake of argument, we wanted to buy access from one of these DDoS providers. [13:06.070 --> 13:12.430] The average for a DDoS was $14.26 per hour. [13:12.610 --> 13:16.510] So if we base that on a 24-hour attack, it's $342 a day. [13:16.790 --> 13:21.410] So if we wanted to do a three-day attack, we're talking about $1,000 of our outlay. [13:21.710 --> 13:31.330] If you look at DDoS loss metrics from the CSI-FBI survey, it's around $14,889 per respondent. [13:31.330 --> 13:35.670] Now that's their total divided by the total number of respondents at 194. [13:36.250 --> 13:39.650] That's not to say this is the exact amount, but this is at least an average. [13:40.150 --> 13:46.650] So, if we were to invest $1,000 of our own money to engage in this attack, what would the overall net gain be for us? [13:46.730 --> 13:51.130] We would cause around $13,000 worth of damage within a corporate environment. [13:51.470 --> 13:56.330] Now, as an attacker, do we actually get any kind of value for the attack? [13:56.330 --> 13:58.030] Yes, we disable the attacker. [13:58.250 --> 14:03.310] We're paying somebody else through their botnet, so a botnet owner or herder is going to make a grand. [14:03.550 --> 14:07.150] We're going to get some sort of sense of satisfaction from the course of the attack. [14:07.430 --> 14:11.110] But as the individual ordering the attack, we don't necessarily make a profit. [14:11.670 --> 14:22.350] If we were to blackmail the company, and we were to use the DDoS as a function to actually make cash, the corporate losses that are advertised here are around $824 per respondent. [14:22.870 --> 14:24.410] Now, that seems pretty low. [14:24.730 --> 14:31.930] If they were to pay, we might make a few grand per instance, but it's not necessarily immediately obvious what would happen. [14:32.130 --> 14:36.850] Would our risk of detection increase significantly if we were going to blackmail someone? [14:38.470 --> 14:39.270] Probably, right? [14:39.410 --> 14:44.730] I mean, most of these companies are smart enough to say something to some law enforcement entity that they're being blackmailed. [14:44.750 --> 14:51.070] So, the risk for blackmail might not necessarily be as great for us if we were to try to engage in this type of behavior. [14:51.070 --> 14:57.910] But given that the outlay is pretty low, if we were to actually go forward with the attack, we could at least get a little something worthwhile out of it. [14:58.090 --> 15:13.470] On the spam side, when we think about the overall cost for spam based on the information that we found in these forums, the average cost to send a single spam message from a database and for sending is less than a hundredth of a cent overall. [15:13.470 --> 15:15.950] So, it's very cheap to send out spam. [15:16.210 --> 15:24.490] If we were to send a hundred thousand messages, the average cost would probably be around $20, depending on what we chose to spam and who we chose to spam. [15:24.830 --> 15:27.710] So, for 20 bucks, it's a pretty minimal outlay. [15:28.070 --> 15:39.730] If we were to say, send out a hundred thousand Nigerian spam messages, you know, I'm the prince of or princess of some far-flung country, I need your help to get eight million dollars out of this country. [15:40.290 --> 15:44.250] The average dollar loss as reported by the Internet Crime Complaint Center. [15:44.330 --> 15:50.210] So, this is an individual victim actually reporting to an agency how much they've lost and what happened. [15:50.470 --> 15:56.930] They estimate responses to be around two to three percent overall for the individuals who received these messages. [15:57.130 --> 16:01.710] So, out of everybody in this room, maybe two or three of you might actually respond to one of these emails. [16:03.850 --> 16:13.870] It's a very difficult thing to consider, but let's just say for the sake of argument, we spent 20 bucks and our response rate was a hundred people total out of our 100,000 email campaign. [16:14.190 --> 16:25.410] At that rate, given that the average victim loses $1,922, that's a pretty significant amount of money for responding to what's a pretty naive kind of message. [16:26.010 --> 16:31.310] Net gain, we could make just under $200,000 engaging in that kind of campaign. [16:31.310 --> 16:43.450] Now, even if we only got 20 responses, we could still make at least $50,000, which isn't bad money when you think about the amount of time that one would have to spend overall to engage in this kind of campaign. [16:43.710 --> 16:46.450] You figure a few hours per respondent over time. [16:46.690 --> 16:54.470] The overall amount that you're making per hour could be somewhere around $19,000 an hour, depending on how many respondents you get. [16:54.470 --> 17:01.110] So, when you think about the bulk of messages that go out, this is a pretty sensible thing from an economic point of view. [17:01.310 --> 17:03.530] If I'm an offender, why wouldn't I do this? [17:04.610 --> 17:11.370] In terms of stolen data, since I didn't get much of a chance to talk about this, we did see carding within our forums as well. [17:11.570 --> 17:18.830] And the average cost per stolen card, be it credit card or bank account, was $10.66 per card. [17:18.830 --> 17:28.690] So, for the sake of argument, if we wanted to buy 100 cards from someone within this market and we paid the average, we'd spend a little over $1,000 to buy 100 cards. [17:29.270 --> 17:38.890] If we take the metric from the IC3 again, that individuals lose $298 from credit or debit card fraud within 2007. [17:39.110 --> 17:40.870] So, we do some multiplication here. [17:41.030 --> 17:44.370] Let's assume that 50 of the cards that we buy actually work. [17:44.370 --> 17:49.510] One of the problems with carding markets is that not every single thing that you buy is actually valid. [17:49.830 --> 17:54.390] Some sellers will replace invalid cards, but some say, whatever you buy is what you buy. [17:54.490 --> 17:55.490] I'm not going to help you. [17:55.710 --> 18:00.170] So, let's just go for the sake of argument that 50 of the cards that we buy actually work. [18:00.670 --> 18:12.690] Now, $298 isn't much, but when we think of it like that, our overall profit for buying 100 cards with 50 of them working would be $13,834 of pure profit. [18:12.690 --> 18:13.790] Which isn't bad. [18:14.250 --> 18:14.370] Yes? [18:14.510 --> 18:15.890] Why are cards so cheap? [18:16.270 --> 18:17.730] Why are cards so cheap? [18:17.870 --> 18:19.070] That is an excellent question. [18:19.250 --> 18:24.030] It's not quite clear why they are so cheap, whether it's because of the amount that are available within the marketplace. [18:24.570 --> 18:28.210] It is clear that there is some tiering based on where the cards come from. [18:28.430 --> 18:29.150] So, U.S. [18:29.230 --> 18:31.830] cards are cheaper than those from Europe and Asia. [18:32.010 --> 18:36.490] So, certainly this cost that we're seeing is probably more indicative of U.S. [18:36.590 --> 18:37.270] cards than otherwise. [18:37.270 --> 18:44.470] It could be due in part to lack security, the fact that we have a higher number of credit cards and debit cards compared to other countries. [18:44.690 --> 18:49.470] But the amount of data that's out there is certainly hard to argue against. [18:49.690 --> 18:59.150] When you think about the TJX compromise and some of the other mass compromises where millions of cards go out and are on the market, that's another reason why this cost might be so low. [18:59.510 --> 19:00.370] Was there another question? [19:00.470 --> 19:00.790] Yes, ma'am. [19:00.790 --> 19:03.910] I just want to talk to the victim. [19:04.110 --> 19:07.830] Is that...are we really certain that that's pure profit for the offender? [19:08.110 --> 19:12.010] Or is there any externality there where it's just like lost value that doesn't go anywhere? [19:12.670 --> 19:17.270] When you say this $298, how can we determine if that's pure profit for the offender? [19:18.190 --> 19:25.070] That's a good question because there is some time that they're going to have to spend in terms of checking or validating whether a card is correct or valid. [19:25.770 --> 19:30.870] They might have to run it through some sort of small service provider for, say, a $1 or $4 fee. [19:30.870 --> 19:35.010] So they might try to make purchases through iTunes or some kind of MP3 service. [19:35.210 --> 19:38.710] So this $298 per card is just an estimate. [19:38.990 --> 19:42.510] This is not, by any stretch of the imagination, a hard and fast rule. [19:42.510 --> 19:44.050] But this is at least a baseline. [19:44.330 --> 19:50.650] So we might say that the true value that an individual gains is less than this $13,000, but it's at least a starting metric. [19:51.030 --> 19:51.290] Yes, sir? [19:51.370 --> 19:54.670] The banks will publish this information about damage costs for fraud. [19:54.930 --> 19:58.690] Sometimes it's like a thousand dollars or a thousand euros if it's a European issuer. [19:58.930 --> 20:00.070] That number looks reasonable. [20:00.070 --> 20:04.650] And so if we are to look at different resources, we could probably get a variety of different figures. [20:04.870 --> 20:15.990] If we go back to the spam estimate, for example, we could look at it from the point of view of an actual employer and say if we were to base on the number of spams an individual receives relative to the cost of our spam services. [20:16.170 --> 20:18.710] So there's a number of different ways that we could try to get at this metric. [20:18.950 --> 20:22.390] It's part of the complexity of trying to understand the overall process here. [20:22.390 --> 20:26.970] But some of these figures seem to some degree reasonable, others maybe not so much. [20:27.090 --> 20:28.390] But this is at least a starting point. [20:28.590 --> 20:28.730] Yes, sir? [20:28.890 --> 20:40.630] The question was are there certain merchants or certain processes by which individuals access the money on these cards more so than others, right? [20:40.630 --> 20:50.430] Yes, there are some individuals who would prefer to just buy consumer goods online and have them shipped somewhere else rather than directly exfiltrate funds from an account. [20:51.110 --> 20:55.610] Certainly, Money Mules and other individuals are one way in which individuals can use cards. [20:55.830 --> 21:07.810] So if we bought 100 cards, 50 of them were valid, we could buy, I don't know, say 50 Xbox 360s and a bunch of PlayStation 3s, get them, resell them, or pawn them. [21:08.030 --> 21:11.810] Maybe sell them through eBay, take that cash, and then have it sent to us. [21:11.950 --> 21:15.070] So there's different processes that we could use to actually get this money. [21:15.470 --> 21:19.970] This is, again, another one of the reasons why it's hard and somewhat funky to deal with these numbers. [21:19.970 --> 21:21.390] But it's one potential answer. [21:21.530 --> 21:32.410] Following up on that, can you talk a little bit about the stock process and how they're actually able to get away with the bank of these services and why it's very difficult and not a possible mistake? [21:33.010 --> 21:33.490] Sure. [21:33.610 --> 21:38.470] The question was in terms of drops, how does that actually work and how do individuals do it? [21:38.610 --> 21:44.190] So let's say we bought 100 of these cards, we used 50 of them to actually make purchases. [21:44.430 --> 21:57.310] One of the reasons that it's possible to make those purchases is because if we were able to obtain the CVV, or the three-digit number on the back of the card that allows you to make a purchase without physically being present, when that information is provided, [21:57.310 --> 21:59.570] it's much easier to make purchases online. [21:59.670 --> 22:05.650] So for a drops provider, we could get the card numbers from our person who buys. [22:05.870 --> 22:10.910] The drop would then make the purchases directly and have them shipped to some location. [22:10.910 --> 22:17.170] So the fact that we have multiple individuals involved and multiple participants complicates the process of identification. [22:17.270 --> 22:32.510] So if there's ten participants in a ring of carders where, say, two individuals buy cards, another two make purchases, another two get the goods, pawn them, and then another two go to Western Union or some other resource and have the money sent out of country to another individual. [22:32.510 --> 22:39.210] And then we have, I don't know, say, two individuals in Romania or some part of Europe get the money and then convert it into electronic currency. [22:39.370 --> 22:43.350] The number of steps involved and some of the ways in which we can obfuscate the process. [22:43.350 --> 22:57.510] So having our goods that we purchased sent to somebody's place in Michigan where they don't actually live and another person in Texas who then go out and pawn these goods or resell them through eBay to help further shield the participants, that's part of the complexity of this. [22:57.510 --> 23:00.530] So it's somewhat hard to actually discern what all is at play. [23:02.330 --> 23:02.810] Wow. [23:03.090 --> 23:04.210] There's still a lot of slides. [23:04.570 --> 23:05.830] So if you're... [23:05.830 --> 23:06.190] Okay. [23:08.030 --> 23:19.990] In terms of Trojans, if you figure the average cost is $742 to buy a tool, let's say we spend another $13 and get a joiner or binder to help us send it out and we spam it to 20 people. [23:20.130 --> 23:25.910] So what would be the cost to actually set up a small infrastructure of infected boxes? [23:25.910 --> 23:32.450] Based on this data, we would spend $775.80 to get some kind of infrastructure started. [23:32.770 --> 23:38.790] When you look at the dollar losses for virus or worm infections within corporate settings, it's around $43,000. [23:39.410 --> 23:45.030] So, pretty significant loss for the relative amount that we would have to spend to actually get started. [23:45.330 --> 23:54.110] Another thing that we could do if we actually get our infrastructure set up, given the number of people who sell pinch, we could sell the log files from our infections. [23:54.410 --> 23:59.650] So, selling this kind of junk data online, people sell it for around $10 a pop. [23:59.930 --> 24:01.450] So, per megabyte, $10. [24:02.110 --> 24:09.490] Individuals who buy this information hopefully find a little gem in there that might be passwords for different kinds of resources, so that way they can use it. [24:09.590 --> 24:13.410] So, it's another way that we might recoup some of the losses from our initial investment. [24:13.990 --> 24:28.370] Looking at an iframe setup, if we were trying to get ourselves started, we could spend around $600 between buying the most expensive iframe tool that was on the market at that point in time, plus spending $100 to send out spam to try to drive in some traffic to our site. [24:28.810 --> 24:34.410] And, let's just say for the sake of argument, we're lazy and we just want to set something up without having to do the infection ourself. [24:34.750 --> 24:39.410] We could spend $48.89, which is the average to buy third-party hosting. [24:39.410 --> 24:47.930] So, for around $600, we can set up an iframe campaign, and then we can lease out our existing infrastructure to make back some profit through traffic. [24:49.030 --> 25:02.910] If we paid $2,000 and had a custom bot made, looking at some of the different metrics out there, if we wanted to recoup the expense of actually buying the malware, we could engage in a DDoS attack for around five days, charging the average. [25:03.190 --> 25:07.510] We could lease out the botnet for proxies, since that was another thing that was available through the market. [25:07.510 --> 25:11.590] The average being about $5 per lease, so we sell 400 leases. [25:11.910 --> 25:13.750] We can remake our funds pretty quickly. [25:13.950 --> 25:16.370] Or, we can send out 20 million spam messages. [25:16.710 --> 25:21.650] So, there's different ways in which we could actually generate the funds to regain what we've spent. [25:22.410 --> 25:26.250] Since I have one minute left, let me just get to this point. [25:26.430 --> 25:28.210] Is it better to own or is it better to lease? [25:28.430 --> 25:29.950] Kind of thinking about it like a car. [25:30.630 --> 25:32.330] What's the smarter thing to do? [25:32.330 --> 25:42.990] Well, if you want to just do this simply, then looking at the marketplace, it's now very easy for a non-skilled entity to engage in relatively sophisticated forms of attack. [25:43.310 --> 25:46.990] So, for the unskilled individual, it's much smarter to lease. [25:47.150 --> 25:48.790] The profit margin is going to be higher. [25:49.030 --> 25:53.010] There's less likelihood of detection from a law enforcement perspective. [25:53.150 --> 25:54.350] And there's no maintenance. [25:54.530 --> 25:59.630] You don't have to spend any of that time making sure that your nodes are online or that your infections are good or otherwise. [25:59.630 --> 26:10.630] For the long-term profit generator, the person with skill, there's merit in setting up your botnet or your iframe because you can make money over the long haul. [26:10.750 --> 26:12.310] Whether it's through spamming or otherwise. [26:12.910 --> 26:24.210] But, your risk of detection can increase given if you're leasing out your resources, you're probably going to come into contact with someone who might flip on you and say that, you know, you're running a botnet or otherwise. [26:24.210 --> 26:30.530] Plus, you are going to have to spend time making sure that your infrastructure is in place, is working, and is fully functional. [26:30.850 --> 26:34.190] So, it's dependent on skill and it's dependent on what you truly want to do. [26:34.990 --> 26:40.290] Overall, it's clear that we can make a lot of money and that we can gain different resources based on this marketplace. [26:40.710 --> 26:47.730] The profit margin is pretty high for the attacker and it's generally low cost overall to engage in this behavior. [26:47.730 --> 27:06.830] And, looking at it, again, going back to one of those first slides from a burglary point of view, the overall value and the cost that you receive for whatever it is you choose to engage in, whether it's spam or DDoSing or otherwise, is relatively low compared to the overall value of that attack against a different resource. [27:07.030 --> 27:13.210] So, somewhat similar to stealing a TV and then reselling it, you're not getting its overall value, but it's a starting point. [27:13.870 --> 27:21.910] But, the most pertinent thing that I can think to mention, and I'm sure I already have way too much, is that the metrics that we have here are not perfect. [27:22.210 --> 27:28.790] There's a lot more that we can do in order to fully understand and assess the economic impact of these different types of crimes. [27:29.110 --> 27:34.410] There's no true way to get at all this information, but this is at least one initial starting point. [27:34.630 --> 27:38.790] There's a lack of information out there and so this is just one potential avenue. [27:39.210 --> 27:40.430] I have ten minutes for questions? [27:40.490 --> 27:40.630] Yes. [27:40.690 --> 27:40.930] Okay. [27:41.150 --> 27:41.730] Yes, sir. [27:50.080 --> 27:58.440] So, the question is, do we want to do more dynamic and active research where we're talking to individuals or do we want to take a passive approach where we're just reading? [27:59.240 --> 28:10.120] From an ethics point of view, there's a lot of challenges in terms of saying, hey, we'll buy that piece of malware from you, because we're, in effect, engaging in some type of criminal activity ourselves. [28:10.120 --> 28:16.260] So, taking this kind of passive approach where we read is preferred from an ethical research standpoint. [28:17.060 --> 28:24.600] Now, there's different partnerships and different ways that we could engage in more active kinds of study, but there are also some challenges in terms of identification. [28:24.600 --> 28:33.380] So, if, for example, someone running a malware site realizes that there's lots of traffic or suddenly there's some individual who's from the U.S. [28:33.500 --> 28:39.600] who doesn't speak Russian all that well, who's in our board, that might lead them to close the doors and kind of seal things up pretty tightly. [28:39.600 --> 28:47.880] So, the less that we interact, the smarter, at least from the point of view of diminishing the knowledge of our presence within this marketplace. [28:48.260 --> 28:49.640] Or if you could do it really well? [28:50.560 --> 28:53.360] If we could do it really well, would we do it? [28:55.080 --> 29:01.260] Prospectively, given appropriate authorizations through the University Human Subjects Board, yes, we would certainly try. [29:01.460 --> 29:06.340] But at least at the moment, it's somewhat easier to do passive research from a social science framework. [29:07.440 --> 29:08.060] Yes, ma'am? [29:08.060 --> 29:14.930] Did the forum were very open and anybody could sign up for an account to close? [29:15.170 --> 29:20.730] Or did it seem like there was some kind of, you know, level of sponsorship or paid post or anything like that happen? [29:20.970 --> 29:23.870] At the...so the question is, how was membership structured? [29:24.110 --> 29:27.910] At the time that our data was collected, most of these forums were relatively open. [29:28.030 --> 29:30.070] There was no initial cost to set up an account. [29:30.890 --> 29:35.550] Subsequently, however, most of these forums have changed and now have some tiering in place. [29:35.550 --> 29:38.150] So you can pay to access different parts of the forum. [29:38.150 --> 29:44.090] In fact, one of them is now closed and requires multiple forms of authentication before they'll allow you in. [29:44.090 --> 29:45.350] So the structure... [29:45.350 --> 29:51.370] When you say authentication, if I may interrupt, do you mean just in terms of, like, you don't have to have an S&H leader? [29:51.750 --> 29:56.470] Do you mean, like, sponsorship and vouching from other existing members? [29:56.830 --> 30:02.590] Authorization refers to vouching from active participants within the community and a money buy-in. [30:02.590 --> 30:15.470] Not necessarily any kind of token or sort of software-based authentication, but rather a human point-to-point, yes, this individual knows you and trusts you and is willing to stake their reputation on your access to the forum. [30:15.650 --> 30:16.030] Thank you. [30:16.470 --> 30:17.430] Yes, sir, you in the back. [30:17.850 --> 30:20.970] You mentioned that the state was 2007. [30:21.390 --> 30:23.310] What's your gut saying is going on today? [30:23.590 --> 30:27.910] And these stories about the Russian mafia, they're doing more organized with it, et cetera. [30:28.770 --> 30:32.290] The question is, how does it seem like the marketplace may have changed? [30:32.950 --> 30:41.410] Just looking at some of these same sites on their open section, a lot of the resources are still the same, though the malware portion of it has dropped off. [30:41.590 --> 30:47.170] So a lot of what we see now are just more advertisements for spam or DDoS or basic kinds of service-oriented things. [30:47.350 --> 30:54.110] From an organizational standpoint, some of these sites are becoming more sophisticated and given buy-in and different types of access. [30:54.390 --> 30:56.750] It seems like it's becoming much more structured. [30:57.730 --> 31:07.410] At the same time, however, one of these very structured groups now has a live journal website or a live journal profile, where some of the high-level participants do have profiles within it. [31:07.590 --> 31:13.770] So there seems to be sort of a mixed bag of privacy and public face. [31:14.230 --> 31:25.610] In terms of participation of organized crime groups, I can't really say for sure, but it does seem like the forum management structures could be deemed as sort of an organizational hierarchy or structure. [31:25.830 --> 31:29.430] Because you have one or two guys at the top with multiple people working below them. [31:29.770 --> 31:36.190] Whether that is truly Russian mafia or not, I won't speculate, but there does seem to be some increasing sophistication within the group. [31:37.150 --> 31:38.110] Yes, are you in the way back? [31:54.720 --> 31:59.980] Yeah, so the question is, in terms of looking at the broader academic literature, what's out there from the Russian point of view? [32:00.500 --> 32:02.200] There's not a lot that I have seen. [32:02.240 --> 32:18.940] Most of the research that I've seen in terms of Russian academic research on hacking, I'm going to butcher the names, but I think it's Voyskunski and Smyslova, did some research looking at Russian perspectives toward hacking, so sort of what does the citizenry think about hackers. [32:19.600 --> 32:28.740] There has not been much that I'm aware of looking at these sort of economic issues or a cybercrime perspective from a Russian criminology point of view. [32:28.980 --> 32:30.700] A lot of researchers in the U.S. [32:30.720 --> 32:37.160] are doing this now, whether it's the individuals from Carnegie Mellon or a few other researchers out there. [32:37.300 --> 32:38.240] So the U.S. [32:38.440 --> 32:43.880] seems to be focusing on this a little bit more heavily than at least what I'm aware of our Russian counterparts in academia. [32:45.140 --> 32:46.380] Any other questions? [32:47.400 --> 32:48.380] Yes, are you in the hat? [32:49.480 --> 32:52.420] What is then the total amount of dollar volume? [32:56.540 --> 32:57.380] What's the... [33:00.520 --> 33:07.940] Sure, so the question is, what's the total dollar figure that we might ascribe to these forums in terms of their overall damage or their economic impact? [33:07.940 --> 33:23.720] Based on what we're seeing here, at least in the hundred thousands, if not the millions, if we were to parse this out and look at it over time, if we were to take the metrics from some of the existing busts that have taken place, like Operation Firewall in 2004 took down a group called the Shadow Crew. [33:24.120 --> 33:25.080] And the U.S. [33:25.200 --> 33:35.200] government has argued that they trafficked in 1.4 million credit cards with so many millions of dollars of damage caused as a direct result of sale and resale of stolen information. [33:35.200 --> 33:42.960] So I think it's relatively safe to argue that there's at least a million dollars' worth of harm here if we take some of the economic figures that have been presented. [33:44.680 --> 33:45.180] Yes, sir? [33:48.940 --> 33:49.660] Gross profit? [33:50.160 --> 33:57.260] Hard to say, but taking some of this data at face value, or at least some of these economic analyses that I presented here, probably the same. [33:57.780 --> 34:04.680] Profit's probably pretty high, at least in the hundreds of thousands, if not the millions, for certain participants overall when we look at the total forums. [34:05.540 --> 34:06.300] Yes, are you in the back? [34:10.590 --> 34:13.970] Are they using any kind of insurance or guarantees for their own transactions? [34:14.430 --> 34:14.850] Yes. [34:14.910 --> 34:21.490] That would be where the grantor system comes in, or the escrow payment system, where one or two forum members take money on behalf of others. [34:21.730 --> 34:25.730] That seems to be one of the only ways in which they insure actual participation. [34:26.010 --> 34:35.550] Otherwise, they depend a lot on individual reputation, so your status as a verified member of the forum, someone whose products have been tested, and we know that we can trust you. [34:35.870 --> 34:49.030] Otherwise, over time, if you seem to be ripping people off, not providing product, or providing bad products, you'll be labeled as a ripper or a cheater, and that kind of label within the marketplace leads to you being blackballed or completely banned, [34:49.230 --> 34:50.890] and then you might have to find some other ways in. [34:51.030 --> 34:53.950] So that seems to be the only ways that they're actually ensuring participation. [34:54.470 --> 34:54.870] Yes, sir? [34:54.870 --> 35:00.710] You preface this with a comparison of comparing things to real-world crimes such as [35:06.570 --> 35:12.510] research as to whether it's correlated to digital crime and street crime. [35:13.110 --> 35:13.550] Sure. [35:13.770 --> 35:19.830] So the question is, given that we might try to compare this against burglary, at least that's how it was framed out initially, how does it sync up? [35:20.110 --> 35:24.090] That's something that we are starting to look at now, so I don't have any hard numbers for you. [35:24.090 --> 35:35.450] But there is some growing research to suggest, at least with different types of small forms of cyber crime, participation in, say, bullying, for example, is correlated with real-world bullying behavior as well. [35:35.630 --> 35:43.850] So there is some prospective data to suggest there's a relationship between on- and offline behavior, but we don't have it from this particular dynamic yet. [35:43.850 --> 35:45.890] But that's something that people are beginning to look at. [35:46.110 --> 35:46.950] What about economically? [35:47.890 --> 35:48.690] Economically, no. [35:48.850 --> 35:50.830] But that is something that we're going to try to do with this data. [35:51.090 --> 35:51.650] Yes, ma'am. [36:04.230 --> 36:04.670] Yes. [36:04.950 --> 36:08.790] So the question is, in terms of the corporate data, how did it get there? [36:08.810 --> 36:11.490] And did we try to validate it by any particular metric? [36:11.870 --> 36:16.690] We took the CSI-FBI report data here, and that is self-reported. [36:17.030 --> 36:20.650] In terms of validating that data, no, we have not attempted to do so. [36:20.890 --> 36:22.770] But that is something that we might try. [36:22.770 --> 36:27.990] However, given that the respondents are anonymous, they don't specify who that entity is, it would be somewhat hard to do. [36:28.810 --> 36:29.430] Yes, ma'am. [36:29.490 --> 36:29.890] You in the back. [36:30.090 --> 36:30.470] Someone had a question? [36:30.650 --> 36:31.050] The last question. [36:31.330 --> 36:31.570] Okay. [36:32.190 --> 36:32.590] Yes. [36:37.840 --> 36:38.740] Do you want to ask? [36:38.960 --> 36:39.420] As well. [36:39.740 --> 36:48.120] In the real world, we spend, or in the I-World, we spend a lot of time kind of like trying to contribute more of the profit you get out of your email campaign. [36:48.360 --> 36:52.700] So it's interesting, and that's how you say you're applying to kind of value the general behavior. [37:13.460 --> 37:20.160] Yeah, so the question is, have we tried to compare this sort of method against other types of email campaigns or otherwise? [37:20.400 --> 37:22.760] No, not yet, but that's a very good question. [37:22.800 --> 37:31.740] In fact, we're sort of in the infancy of this economic analysis, and that would be nice to do some comparisons against, say, communications data or otherwise to see what these things are like. [37:32.060 --> 37:36.220] Since that was the last question, if you have any further questions for me or want to get ahold of me, this is my email address. [37:36.380 --> 37:37.660] Feel free to contact me whenever. [37:37.900 --> 37:38.840] And thank you for coming. [37:38.960 --> 37:39.500] I appreciate it. [37:46.180 --> 37:46.720] Thank you. [37:47.640 --> 37:53.300] I have to say, this is the kind of talk, that's the reason I come to HOPE, this kind of meat and potatoes overview of everything that's...