Maltego ® -- a New Threat of Privacy Disclosure

21
Maltego® -- a New Threat of Privacy Disclosure Jingjing Gao Department of Computer Science and Engineering April 16 th ,2014 1

description

Maltego ® -- a New Threat of Privacy Disclosure. Jingjing Gao Department of Computer Science and Engineering April 16 th ,2014. Outline. Introduction of Maltego ® Maltego ® in Information Warfare Threats caused by Maltego ® Accountability. Introduction of Maltego ® . - PowerPoint PPT Presentation

Transcript of Maltego ® -- a New Threat of Privacy Disclosure

Page 1: Maltego ® -- a New Threat of  Privacy Disclosure

1

Maltego® -- a New Threat of Privacy Disclosure

Jingjing GaoDepartment of Computer Science and Engineering

April 16th,2014

Page 2: Maltego ® -- a New Threat of  Privacy Disclosure

2

Outline

Introduction of Maltego®

Maltego® in Information Warfare

Threats caused by Maltego®

Accountability

Page 3: Maltego ® -- a New Threat of  Privacy Disclosure

3

Introduction of Maltego® Maltego® is a kind of software which gathers open sources information online and analyzes them intellectually with an outcome of a graphical way.

Page 4: Maltego ® -- a New Threat of  Privacy Disclosure

4

Introduction of Maltego®Gathering a bunch of data with regard to:

PeopleGroups of people (social networks)CompaniesOrganizationsWeb sitesInternet infrastructure such as: Domains, DNS names,

Netblocks and IP address.AffiliationsDocuments and files

Page 5: Maltego ® -- a New Threat of  Privacy Disclosure

5

Outline

Introduction of Maltego®

Maltego® in Information Warfare

Threats caused by Maltego®

Accountability

Page 6: Maltego ® -- a New Threat of  Privacy Disclosure

6

Maltego® in Information Warfare

National Security Defensive Operation

Commercial Competitive Application

Social Engineering and Forensic

Application toward Individuals

Page 7: Maltego ® -- a New Threat of  Privacy Disclosure

7

Maltego® in Information WarfareNational Security Defensive Operation

“Who is tweeting from NSA’s parking lot?” [1]

Figure 1: Twitter[2]

Page 8: Maltego ® -- a New Threat of  Privacy Disclosure

8

Maltego® in Information WarfareCommercial Competitive Application

Figure 2. Graph of BOA Location[3] Figure 3. Graph of BOA Department[3]

Page 9: Maltego ® -- a New Threat of  Privacy Disclosure

9

Maltego® in Information WarfareSocial Engineering and Forensic Application toward IndividualsProvide context for social Engineering e.g. the language the target person use.Forensic application Show internal relations between different persons and different organizaitons.

Page 10: Maltego ® -- a New Threat of  Privacy Disclosure

10

Outline

Introduction of Maltego®

Maltego® in Information Warfare

Threats caused by Maltego®

Accountability

Page 11: Maltego ® -- a New Threat of  Privacy Disclosure

11

Threats Result from Maltego®

Violation of Privacy

Reliability of Maltego® as a Forensic Application

Page 12: Maltego ® -- a New Threat of  Privacy Disclosure

12

Violation of Privacy

Threats Result from Maltego®

Page 13: Maltego ® -- a New Threat of  Privacy Disclosure

13

Threats Result from Maltego® Violation of Privacy

Page 14: Maltego ® -- a New Threat of  Privacy Disclosure

14

Threats Result from Maltego® Violation of Privacy

Easy and convenient for malicious social engineering attack, e.g. Phishing Emails, account guessingOpen type Mailing lists are vulnerable target’s interests, concerns

Page 15: Maltego ® -- a New Threat of  Privacy Disclosure

15

Threats Result from Maltego® Reliability of Maltego® as a Forensic Application

Unreliable Twitter Geo-location

Mislead

Page 16: Maltego ® -- a New Threat of  Privacy Disclosure

16

Threats Result from Maltego® Reliability of Maltego® as a Forensic ApplicationUnreliable Twitter Geo-location

Various of app especially for Android system

Not authorized officially

Page 17: Maltego ® -- a New Threat of  Privacy Disclosure

17

Threats Result from Maltego® Reliability of Maltego® as a Forensic ApplicationMislead

Page 18: Maltego ® -- a New Threat of  Privacy Disclosure

18

Outline

Introduction of Maltego®

Maltego® in Information Warfare

Threats caused by Maltego®

Accountability

Page 19: Maltego ® -- a New Threat of  Privacy Disclosure

19

AccountabilityGovernment and Organization Accountability• Need new regulations for collections of integrated personal information• Specify the usage of different part of personal information• Appeal to whole society to protect privacyIndividual Accountability• Be aware of innocuous information may lead to privacy disclosure• Pay attention to privacy settings of the app in your smart phone and PC• Form good use habit e.g. When leave the local wifi connection, click “forget this network”

Page 20: Maltego ® -- a New Threat of  Privacy Disclosure

20

References[1] Jeremy Kirk, (2014, March 11), “Who is tweeting from NSA’s parking lot?” Computer World, [Online], Available: http://www.computerworld.com/s/article/9232476/Who_is_tweeting_from_the_NSA_39_s_parking_lot[2] video-gillen-twitter-articleLarge.jpg, https://www.google.com/search?q=twitter&espv=2&es_sm=93&source=lnms&tbm=isch&sa=X&ei=mLlOU_2zHYq-sQS7poLgCQ&ved=0CAkQ_AUoAg&biw=1366&bih=600#facrc=_&imgdii=_&imgrc=pZeQN_7zq2lhOM%253A%3BUIvMeomJTRpZYM%3Bhttp%253A%252F%252Fgraphics8.nytimes.com%252Fimages%252F2013%252F10%252F28%252Fbusiness%252Fvideo-gillen-twitter%252Fvideo-gillen-twitter-articleLarge.jpg%3Bhttp%253A%252F%252Fwww.nytimes.com%252F2013%252F11%252F07%252Ftechnology%252Ftwitter-prices-ipo-at-26-a-share.html%3B600%3B338[3] Csitech, (2014, March 8), “Mapping Corporate infrastructure with open source data”, CSITECH, [Online], Available: http://www.csitech.co.uk/mapping-corporate-infrastructure-with-open-source-data/

Page 21: Maltego ® -- a New Threat of  Privacy Disclosure

21

Thank You!