"It's when all the effective Internet attack elements come together to potentially steal a lot of money," said Jay Heiser, a vice president and research director at Gartner said Tuesday. "'Slurpware' requires a community of trusted users, phishing mail, password slurping malware, and sponsorship of the Russia Mafia," he added.
"This is indicative of a certain level of attack sophistication, and it's unreasonable to think that there won't be further convergence [of techniques]," he said.
By combining the automated properties of massive e-mail campaigns and keylogger-style spyware, the bad guys have the upper hand at the moment. "The criminals figured out how to automate their offense before we automated our defense," said Heiser.
The answer, he predicted, will have to be stronger authentication that goes beyond the simple usernames and passwords that most e-commerce or e-banking sites now use. "The viability of simple passwords on e-commerce sites won't be viable much longer."
Among the defenses being tried, said Heiser, are hardware-based tokens required to access confidential sites, such as banks and credit card companies. While the "U.S. is way behind on this," he said, other regions are moving fast. "Brazil is, and it's not because it's a hotbed of technology, but because there's been a lot of [online] theft there." Other areas with a head start on America include Western European countries like the Netherlands and the Scandinavian nations.
But unlike some prognosticators, Heiser doesn't' fear for the viability of online commerce. "The online market is too appealing to both buyers and sellers," he said. "They'll solve the problems as they come up, or maybe after they appear, but generally it will work its way out."
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.