| Main Archive Page > Month Archives > full-disclosure-uk archives |
BLUE TEAM: anti-phishing blacklist
RED TEAM: phish
GREEN TEAM: end-users
starting degree of obfuscation: 0% (none) starting number of blocked domains: 0
round 1:
action: RED sends billions of phish
consequence: 5% of GREEN members are suckered and lose some cash
action: BLUE blocks the top 20 phished domains using the FROM field consequence: 80% of RED members are forced to make new sites and find new victims
current degree of obfuscation: 0%
current number of blocked domains: 20
round 2:
action: RED obfuscates their FROM fields by 20% and resends billions
of phish
consequence: 4% of GREEN members are suckered and lose some cash
action: BLUE blocks the next top 20 phished domains using the FROM
field
consequence: 80% of RED members are forced to make new sites and find
new victims
current degree of obfuscation: 20%
current number of blocked domains: 40
round 3:
action: RED obfuscates their FROM fields by 20% and resends billions
of phish
consequence: 3% of GREEN members are suckered and lose some cash
action: BLUE blocks the next top 20 phished domains using the FROM
field
consequence: 80% of RED members are forced to make new sites and find
new victims
current degree of obfuscation: 24%
current number of blocked domains: 60
round 4:
action: RED obfuscates their FROM fields by 20% and resends billions
of phish
consequence: 2% of GREEN members are suckered and lose some cash
action: BLUE blocks the next top 20 phished domains using the FROM
field
consequence: 80% of RED members are forced to make new sites and find
new victims
current degree of obfuscation: 28.8%
current number of blocked domains: 80
round 5:
action: RED obfuscates their FROM fields by 20% and resends billions
of phish
consequence: 1% of GREEN members are suckered and lose some cash
action: BLUE blocks the next top 20 phished domains using the FROM
field
consequence: 80% of RED members are forced to make new sites and find
new victims
current degree of obfuscation: 34.56%
current number of blocked domains: 100
round 6:
action: RED obfuscates their FROM fields by 20% and resends billions
of phish
consequence: 0% of GREEN members are suckered and lose some cash
GAME OVER: RED loses at round 6, as 0% of GREEN members are suckered, due to over-obfuscation.
final degree of obfuscation: 41.47%
final number of blocked domains: 100
observations:
links:
(...)
http://en.wikipedia.org/wiki/Business_War_Games
(this is a sales brochure, however it describes a war game a bit nicer than wiki, it's got diagrams, for a start) http://www.coleago.co.uk/uploads/Training/War%20Gaming.pdf
(this isn't relevant to a war game, it might be something like what's happening when the top 20 phished domains are used to select the items to blacklist, OTOH, it might not, I don't know, I'm not a statistician. I'd love to know the name of the technique, I use something similar to optimise my spam rules...) http://en.wikipedia.org/wiki/Monte_Carlo_method
(this was mentioned in one of the papers I quoted previously) http://en.wikipedia.org/wiki/Pareto_principle
---
Stuart Udall
stuart at_at_cyberdelix.dot net - http://www.cyberdelix.net/
---