SlideShare a Scribd company logo
1 of 23
Cyber Security Issues in 
South Korea and 
CSIRTs Cooperation 
September 17, 2014 
Eunju Pak 
first-team@krcert.or.kr 
eunjupak@krcert.or.kr 
beunju@kisa.or.kr
AGENDA 
01 
LATEST NEWS 
02 
PHARMING 
03 
SMS PHISHING 
04 
CONCLUSION
01 
Latest News
01. Latest News 
2014-09-17 
A GROUP OF CYBER FRAUD 
CRIMINALS WAS ARRESTED 
Unfair Profits 1 Billion KRW 
Victims’ financial information stolen 
Money withdrawn money from their bank accounts 
Cased by Phishing site, Pharming site and SMS Phishing 
4
02 
Pharming Case
02. Pharming Case 
Constant increase in the number of 
Phishing/Pharming Sites in South Korea 
1,000 
800 
600 
400 
200 
0 
2014-09-17 
Phishing/Pharming Sites in South Korea 
Public Banking Others 
Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May 
2013 Y 2014 Y 
100% 
80% 
60% 
40% 
20% 
0% 
Types of Malwares in South Korea 
Jan Feb Mar Apr May 
2014 Y 
Dropper Pharming Steal Infected PC's info Others 
6
02. Pharming Case 
Pharming Incident? 
Infection Web defacement 
2014-09-17 
7
02. Pharming Case 
Pharming Incident? 
Falsification hosts.ics falsified 
2014-09-17 
8
02. Pharming Case 
Pharming Incident? 
Information Leak Victims’ bank account information leaked 
2014-09-17 
9
02. Pharming Case 
JPCERT/CC’s ASSISTANCE NEEDED! 
2014-09-17 
Statistics of Japanese IP misused Japanese IPs misused by Korean Pharming cases 
2011 2012 2013 1H 2014 
SOS to JPCERT/CC 
What JPCERT/CC is Doing: 
Analyzing malwares 
Monitoring servers distributing hosts.ics 
Discussing with relevant ISP (i.e Blocking sites) 10
03 
SMS Phishing Case
03. SMS Phishing Case 
The more smartphone users are, 
2014-09-17 
the more SMS Phishing damages increase 
23,763,087 
39,046,720 
2012Y 
Jan 
2012Y 
Jun 
2012Y 
Dec 
2013Y 
Mar 
2013Y 
Jun 
2013Y 
Dec 
2014Y 
Mar 
2014Y 
Jun 
The number of Smart Phone users in South Korea 
Damaged Amount of SMS Phishing in South Korea 
569M 
5,733M 
Source : NPA 
Unit : KRW 
330M 
2012Y 2013Y FH. 2014Y 
12
03. SMS Phishing Case 
SMS Phishing Incident? 
Text Message Received 
2014-09-17 
Promotion Coupon(for free) 
Link to the URL 
Add bookmark 
Copy the text 
Downloading Do you want to install? 
13
03. SMS Phishing Case 
SMS Phishing Incident? 
Malicious Application Installed 
① Check Normal Banking Apps 
2014-09-17 
14
03. SMS Phishing Case 
SMS Phishing Incident? 
Malicious Application Installed 
② Download the Additional Malicious Application 
2014-09-17 
15
03. SMS Phishing Case 
SMS Phishing Incident? 
Malicious Application Installed 
③ Require Financial Information 
2014-09-17 
16
03. SMS Phishing Case 
17 
SMS Phishing Incident? 
Malicious Application Installed 
④ Send away PKI folder, financial Information to specific email address 
2014-09-17
CNCERT/CC’s ASSISTANCE NEEDED! 
Chinese Famous Portal E-mail addresses are misused for Korean SMS Phishing incidents 
2014-09-17 
03. SMS Phishing Case 
What KrCERT/CC is Doing: 
Providing CNCERT/CC with email addresses, related evidences, samples 
Requesting takedown of related email addresses 
What CNCERT/CC is Doing: 
Analyzing and Verifying malware samples 
Coordinating with relevant service provider to takedown the misused 
email addresses 
18
What KrCERT/CC is doing for Global Collaboration: 
2014-09-17 
04. Cooperation 
Web Browser Notification to Infected PC Users : 
Received infected IP list from trusted organization and partners 
Web browser notification to infected PC users 
Respond CVE-2014-0515(Adobe Flash Player) : 
Received malware distributing URLs, suspicious URLs 
Request for proper actions to the distributing URLs 
Support technical measures, extract & analyze logs 
Web browser notification to infected PC users 
WAIT!!! 
Remove malware 
from your PC 
19
04 
Conclusion
Each CSIRT team’s circumstances to be explored 
2014-09-17 
04. Conclusion 
Actions Required 
Each CSIRT has different capacities, rules,… 
Seek Ways to collaborate to 
Support Incident Handling 
Develop Information Sharing Protocol 
21
04. Conclusion 
Asia Pacific Computer Emergency Response Team 
Forum of CSIRTs/CERTs in Asia Pacific region since 2003 
To help create a SAFE, CLEAN and RELIABLE cyber space 
in the Asia Pacific region through global collaboration 
APCERT will maintain a trusted contact network of computer security experts 
in Asia Pacific region to improve the region’s awareness competency in 
relation to computer security incidents 
2014-09-17 22
감사합니다 
THANK YOU

More Related Content

Viewers also liked

Published patent and design registration information july 13th, 2012
Published patent and design registration information   july 13th, 2012Published patent and design registration information   july 13th, 2012
Published patent and design registration information july 13th, 2012
InvnTree IP Services Pvt. Ltd.
 
Governing Knowledge for Development: Knowledge Clusters in Brunei Darussalam ...
Governing Knowledge for Development: Knowledge Clusters in Brunei Darussalam ...Governing Knowledge for Development: Knowledge Clusters in Brunei Darussalam ...
Governing Knowledge for Development: Knowledge Clusters in Brunei Darussalam ...
Hans-Dieter Evers
 
18052015_ALQAEDA_IM_SIMI_ISIS_TERRORIST_RiyadRasheed_RBM_RADAR
18052015_ALQAEDA_IM_SIMI_ISIS_TERRORIST_RiyadRasheed_RBM_RADAR18052015_ALQAEDA_IM_SIMI_ISIS_TERRORIST_RiyadRasheed_RBM_RADAR
18052015_ALQAEDA_IM_SIMI_ISIS_TERRORIST_RiyadRasheed_RBM_RADAR
SUPRATIK SAHA
 
M05-06MAR2011 Organización Torneo Cisneros
M05-06MAR2011 Organización Torneo CisnerosM05-06MAR2011 Organización Torneo Cisneros
M05-06MAR2011 Organización Torneo Cisneros
lacucarachachamiza
 

Viewers also liked (20)

Presentaciòn paoma pretzel sa spptx
Presentaciòn paoma pretzel sa spptxPresentaciòn paoma pretzel sa spptx
Presentaciòn paoma pretzel sa spptx
 
Rete Europa 2020
Rete Europa 2020Rete Europa 2020
Rete Europa 2020
 
Naturopatia
NaturopatiaNaturopatia
Naturopatia
 
Leading the Lean Enterprise
Leading the Lean EnterpriseLeading the Lean Enterprise
Leading the Lean Enterprise
 
NephOS Product Datasheet
NephOS Product DatasheetNephOS Product Datasheet
NephOS Product Datasheet
 
Published patent and design registration information july 13th, 2012
Published patent and design registration information   july 13th, 2012Published patent and design registration information   july 13th, 2012
Published patent and design registration information july 13th, 2012
 
Governing Knowledge for Development: Knowledge Clusters in Brunei Darussalam ...
Governing Knowledge for Development: Knowledge Clusters in Brunei Darussalam ...Governing Knowledge for Development: Knowledge Clusters in Brunei Darussalam ...
Governing Knowledge for Development: Knowledge Clusters in Brunei Darussalam ...
 
Amerika Birleşik Devletleri ulke raporu_2013
Amerika Birleşik Devletleri ulke raporu_2013Amerika Birleşik Devletleri ulke raporu_2013
Amerika Birleşik Devletleri ulke raporu_2013
 
Catalogo Interacoustic Fonoaudiología Chile
Catalogo Interacoustic Fonoaudiología ChileCatalogo Interacoustic Fonoaudiología Chile
Catalogo Interacoustic Fonoaudiología Chile
 
Tema 8 el proceso contencioso administrativo laboral
Tema 8   el proceso contencioso administrativo laboralTema 8   el proceso contencioso administrativo laboral
Tema 8 el proceso contencioso administrativo laboral
 
Habilidades PokéMon
Habilidades PokéMonHabilidades PokéMon
Habilidades PokéMon
 
How Cool Brands Stay Hot @ForzaRetail
How Cool Brands Stay Hot @ForzaRetailHow Cool Brands Stay Hot @ForzaRetail
How Cool Brands Stay Hot @ForzaRetail
 
18052015_ALQAEDA_IM_SIMI_ISIS_TERRORIST_RiyadRasheed_RBM_RADAR
18052015_ALQAEDA_IM_SIMI_ISIS_TERRORIST_RiyadRasheed_RBM_RADAR18052015_ALQAEDA_IM_SIMI_ISIS_TERRORIST_RiyadRasheed_RBM_RADAR
18052015_ALQAEDA_IM_SIMI_ISIS_TERRORIST_RiyadRasheed_RBM_RADAR
 
Hector Robles: Los 5 superpoderes de diseño
Hector Robles: Los 5 superpoderes de diseñoHector Robles: Los 5 superpoderes de diseño
Hector Robles: Los 5 superpoderes de diseño
 
John Lewis Case Study - How does a company's brand communication strategy per...
John Lewis Case Study - How does a company's brand communication strategy per...John Lewis Case Study - How does a company's brand communication strategy per...
John Lewis Case Study - How does a company's brand communication strategy per...
 
Cuadro de Dosis de tóxicos volátiles, minerales, ácidos y álcalis.
Cuadro de Dosis de tóxicos volátiles, minerales, ácidos y álcalis. Cuadro de Dosis de tóxicos volátiles, minerales, ácidos y álcalis.
Cuadro de Dosis de tóxicos volátiles, minerales, ácidos y álcalis.
 
M05-06MAR2011 Organización Torneo Cisneros
M05-06MAR2011 Organización Torneo CisnerosM05-06MAR2011 Organización Torneo Cisneros
M05-06MAR2011 Organización Torneo Cisneros
 
CATALOGO DE RECURSOS TIC - 2012
CATALOGO DE RECURSOS TIC - 2012CATALOGO DE RECURSOS TIC - 2012
CATALOGO DE RECURSOS TIC - 2012
 
An Introduction to Online Advertising
An Introduction to Online AdvertisingAn Introduction to Online Advertising
An Introduction to Online Advertising
 
Obra (Torre Altus)
Obra (Torre Altus)Obra (Torre Altus)
Obra (Torre Altus)
 

Similar to Cyber Security Issues in South Korea and CSIRTs Cooperation, by Eunju Pak [APNIC 38]

CYREN 2013년 인터넷 위협 보고서_영문
CYREN 2013년 인터넷 위협 보고서_영문CYREN 2013년 인터넷 위협 보고서_영문
CYREN 2013년 인터넷 위협 보고서_영문
Jiransoft Korea
 
Customer Involvement in Phishing Defence
Customer Involvement in Phishing DefenceCustomer Involvement in Phishing Defence
Customer Involvement in Phishing Defence
Jordan Schroeder
 
Phishing exposed
Phishing exposedPhishing exposed
Phishing exposed
tamfin
 

Similar to Cyber Security Issues in South Korea and CSIRTs Cooperation, by Eunju Pak [APNIC 38] (20)

IRJET- A Survey on Automatic Phishing Email Detection using Natural Langu...
IRJET-  	  A Survey on Automatic Phishing Email Detection using Natural Langu...IRJET-  	  A Survey on Automatic Phishing Email Detection using Natural Langu...
IRJET- A Survey on Automatic Phishing Email Detection using Natural Langu...
 
CYREN 2013년 인터넷 위협 보고서_영문
CYREN 2013년 인터넷 위협 보고서_영문CYREN 2013년 인터넷 위협 보고서_영문
CYREN 2013년 인터넷 위협 보고서_영문
 
How to build a highly secure fin tech application
How to build a highly secure fin tech applicationHow to build a highly secure fin tech application
How to build a highly secure fin tech application
 
RSA Online Fraud Report - August 2014
RSA Online Fraud Report - August 2014RSA Online Fraud Report - August 2014
RSA Online Fraud Report - August 2014
 
Detecting malicious URLs using binary classification through ada boost algori...
Detecting malicious URLs using binary classification through ada boost algori...Detecting malicious URLs using binary classification through ada boost algori...
Detecting malicious URLs using binary classification through ada boost algori...
 
Cyber security meetup from Nepal
Cyber security meetup from NepalCyber security meetup from Nepal
Cyber security meetup from Nepal
 
CERT STRATEGY TO DEAL WITH PHISHING ATTACKS
CERT STRATEGY TO DEAL WITH PHISHING ATTACKSCERT STRATEGY TO DEAL WITH PHISHING ATTACKS
CERT STRATEGY TO DEAL WITH PHISHING ATTACKS
 
Customer Involvement in Phishing Defence
Customer Involvement in Phishing DefenceCustomer Involvement in Phishing Defence
Customer Involvement in Phishing Defence
 
Phishing exposed
Phishing exposedPhishing exposed
Phishing exposed
 
Awareness of Sim Swap Attack
Awareness of Sim Swap AttackAwareness of Sim Swap Attack
Awareness of Sim Swap Attack
 
Symantec Website Security Threats: March 2014 update.
Symantec Website Security Threats: March 2014 update.Symantec Website Security Threats: March 2014 update.
Symantec Website Security Threats: March 2014 update.
 
PROTECTING YOUR BUSINESS AND CLIENT INFORMATION IN A DIGITAL WORLD - Mitch Ta...
PROTECTING YOUR BUSINESS AND CLIENT INFORMATION IN A DIGITAL WORLD - Mitch Ta...PROTECTING YOUR BUSINESS AND CLIENT INFORMATION IN A DIGITAL WORLD - Mitch Ta...
PROTECTING YOUR BUSINESS AND CLIENT INFORMATION IN A DIGITAL WORLD - Mitch Ta...
 
Past paper of e-commerce 2018-2017-2015
Past paper of e-commerce 2018-2017-2015Past paper of e-commerce 2018-2017-2015
Past paper of e-commerce 2018-2017-2015
 
Android mobile platform security and malware
Android mobile platform security and malwareAndroid mobile platform security and malware
Android mobile platform security and malware
 
Android mobile platform security and malware survey
Android mobile platform security and malware surveyAndroid mobile platform security and malware survey
Android mobile platform security and malware survey
 
Keeping up with the Revolution in IT Security
Keeping up with the Revolution in IT SecurityKeeping up with the Revolution in IT Security
Keeping up with the Revolution in IT Security
 
Cyber Landscape in the Philippines.pptx
Cyber Landscape in the Philippines.pptxCyber Landscape in the Philippines.pptx
Cyber Landscape in the Philippines.pptx
 
Webinar: Is There A Blind Spot In Your Cyberthreat Vision?
Webinar: Is There A Blind Spot In Your Cyberthreat Vision?Webinar: Is There A Blind Spot In Your Cyberthreat Vision?
Webinar: Is There A Blind Spot In Your Cyberthreat Vision?
 
Application security meetup data privacy_27052021
Application security meetup data privacy_27052021Application security meetup data privacy_27052021
Application security meetup data privacy_27052021
 
The Current State of Cybercrime 2014
The Current State of Cybercrime 2014The Current State of Cybercrime 2014
The Current State of Cybercrime 2014
 

More from APNIC

More from APNIC (20)

APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff Huston
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet development
 
AFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment Status
 

Recently uploaded

valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
soniya singh
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
ellan12
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
sexy call girls service in goa
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
imonikaupta
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
Diya Sharma
 

Recently uploaded (20)

Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Model Towh Delhi 💯Call Us 🔝8264348440🔝
 
Trump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts SweatshirtTrump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts Sweatshirt
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
 
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
 
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
 
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
 

Cyber Security Issues in South Korea and CSIRTs Cooperation, by Eunju Pak [APNIC 38]

  • 1. Cyber Security Issues in South Korea and CSIRTs Cooperation September 17, 2014 Eunju Pak first-team@krcert.or.kr eunjupak@krcert.or.kr beunju@kisa.or.kr
  • 2. AGENDA 01 LATEST NEWS 02 PHARMING 03 SMS PHISHING 04 CONCLUSION
  • 4. 01. Latest News 2014-09-17 A GROUP OF CYBER FRAUD CRIMINALS WAS ARRESTED Unfair Profits 1 Billion KRW Victims’ financial information stolen Money withdrawn money from their bank accounts Cased by Phishing site, Pharming site and SMS Phishing 4
  • 6. 02. Pharming Case Constant increase in the number of Phishing/Pharming Sites in South Korea 1,000 800 600 400 200 0 2014-09-17 Phishing/Pharming Sites in South Korea Public Banking Others Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May 2013 Y 2014 Y 100% 80% 60% 40% 20% 0% Types of Malwares in South Korea Jan Feb Mar Apr May 2014 Y Dropper Pharming Steal Infected PC's info Others 6
  • 7. 02. Pharming Case Pharming Incident? Infection Web defacement 2014-09-17 7
  • 8. 02. Pharming Case Pharming Incident? Falsification hosts.ics falsified 2014-09-17 8
  • 9. 02. Pharming Case Pharming Incident? Information Leak Victims’ bank account information leaked 2014-09-17 9
  • 10. 02. Pharming Case JPCERT/CC’s ASSISTANCE NEEDED! 2014-09-17 Statistics of Japanese IP misused Japanese IPs misused by Korean Pharming cases 2011 2012 2013 1H 2014 SOS to JPCERT/CC What JPCERT/CC is Doing: Analyzing malwares Monitoring servers distributing hosts.ics Discussing with relevant ISP (i.e Blocking sites) 10
  • 12. 03. SMS Phishing Case The more smartphone users are, 2014-09-17 the more SMS Phishing damages increase 23,763,087 39,046,720 2012Y Jan 2012Y Jun 2012Y Dec 2013Y Mar 2013Y Jun 2013Y Dec 2014Y Mar 2014Y Jun The number of Smart Phone users in South Korea Damaged Amount of SMS Phishing in South Korea 569M 5,733M Source : NPA Unit : KRW 330M 2012Y 2013Y FH. 2014Y 12
  • 13. 03. SMS Phishing Case SMS Phishing Incident? Text Message Received 2014-09-17 Promotion Coupon(for free) Link to the URL Add bookmark Copy the text Downloading Do you want to install? 13
  • 14. 03. SMS Phishing Case SMS Phishing Incident? Malicious Application Installed ① Check Normal Banking Apps 2014-09-17 14
  • 15. 03. SMS Phishing Case SMS Phishing Incident? Malicious Application Installed ② Download the Additional Malicious Application 2014-09-17 15
  • 16. 03. SMS Phishing Case SMS Phishing Incident? Malicious Application Installed ③ Require Financial Information 2014-09-17 16
  • 17. 03. SMS Phishing Case 17 SMS Phishing Incident? Malicious Application Installed ④ Send away PKI folder, financial Information to specific email address 2014-09-17
  • 18. CNCERT/CC’s ASSISTANCE NEEDED! Chinese Famous Portal E-mail addresses are misused for Korean SMS Phishing incidents 2014-09-17 03. SMS Phishing Case What KrCERT/CC is Doing: Providing CNCERT/CC with email addresses, related evidences, samples Requesting takedown of related email addresses What CNCERT/CC is Doing: Analyzing and Verifying malware samples Coordinating with relevant service provider to takedown the misused email addresses 18
  • 19. What KrCERT/CC is doing for Global Collaboration: 2014-09-17 04. Cooperation Web Browser Notification to Infected PC Users : Received infected IP list from trusted organization and partners Web browser notification to infected PC users Respond CVE-2014-0515(Adobe Flash Player) : Received malware distributing URLs, suspicious URLs Request for proper actions to the distributing URLs Support technical measures, extract & analyze logs Web browser notification to infected PC users WAIT!!! Remove malware from your PC 19
  • 21. Each CSIRT team’s circumstances to be explored 2014-09-17 04. Conclusion Actions Required Each CSIRT has different capacities, rules,… Seek Ways to collaborate to Support Incident Handling Develop Information Sharing Protocol 21
  • 22. 04. Conclusion Asia Pacific Computer Emergency Response Team Forum of CSIRTs/CERTs in Asia Pacific region since 2003 To help create a SAFE, CLEAN and RELIABLE cyber space in the Asia Pacific region through global collaboration APCERT will maintain a trusted contact network of computer security experts in Asia Pacific region to improve the region’s awareness competency in relation to computer security incidents 2014-09-17 22