Home > Security News > Hackers costing enterprises billions
Security News:
EMAIL THIS

Hackers costing enterprises billions

By Mark Baard, Contributing Writer
20 Sep 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Hackers continued adding billions to the cost of doing business on the Internet in the first half of 2004, despite security executives' efforts to prevent malicious attacks.

Motivated increasingly by money, the hackers are amassing legions of unwitting bot computers for distributed denial-of-service (DDoS) attacks. They are also exploiting Web applications and mobile devices to steal identities through e-commerce scams, including phishing.

These are some of the worrisome conclusions drawn by the Cupertino, Calif.-based security vendor Symantec Corp. in its semi-annual Internet Security Threat Report released today.

The report finds that -- among the computers monitored by Symantec -- the number of monitored bot computers rose from less than 2,000 to more than 30,000 between January and June 2004.

Attackers use remotely controlled "bot" (also known as "zombie") networks to scan for vulnerable systems and to maximize the impact of DDoS attacks. Organized crime syndicates use the threat of bot attacks to extort money from business owners.

In fact, of the targeted attacks Symantec detected in the last six months, the majority were against e-commerce companies, including financial institutions. Small business received the second highest number of attacks.

"We're no longer talking strictly about the male teenager with the low moral compass, or the hactivist, who defaces sites or uses malicious code or worms against those on one side in a political conflict," said Vincent Weafer, senior director of Symantec Security Response. "These people are targeting e-commerce, and they are often backed by organized crime."

The Symantec report is based on data gathered from 20,000 devices that are a part of the company's DeepSight security alert system. The report also relies on information from Symantec's BugTraq malicious code submissions program, which receives 250,000 samples monthly from computer users who believe they have received malicious code.

Symantec was also able to incorporate data gathered by the spam-filtering service Brightmail, which it acquired in June. "Brightmail probes one-quarter of all e-mail traffic in the world," said Weafer.

The news in the Internet Security Threat Report is not entirely bad. The daily volume of Internet-based worm attacks decreased in the first half of the year, according to Symantec. The Slammer worm was the most likely to have attacked computers.

But another trend is more disturbing: The average time period between the disclosure of a vulnerability and its first exploit by hackers collapsed from several weeks in past reports to less than six days in the first half of 2004.

"In some cases, we saw global exploits in less than two days," said Weafer. The current report finds that the vast majority of those vulnerabilities were moderately to highly severe and nearly 40% were associated with Web applications.

The Symantec report also predicted trouble ahead for users of P2P software and mobile devices, which it calls "popular propagation vectors for worms and other malicious code."

The report noted that 2004 saw the first malicious worm for mobile devices, Cabir, which attacks Bluetooth devices.

That means security execs will have even more assets to watch over in the coming years. "You will want to make sure you have policies in place for the use of new technologies, and have a means for making sure users comply with them," said Weafer.

Tags: Malware, Viruses, Trojans and SpywareSecurity Awareness Training and Internal ThreatsHacker Tools and Techniques: Underground Sites and Hacking GroupsEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Malware, Viruses, Trojans and Spyware
Malware in Google attacks uses spaghetti code
Preparing for future security threats, evolving malware
Facebook attacks prompt investments in social networking security
Another PDF attack targets Adobe zero-day vulnerability
Security report finds rise in banking Trojans, adware, fewer viruses
How to prevent rogue antivirus programs in the enterprise
How to stop keylogging malware with more than basic antivirus software, firewalls
Conficker-infected machines now number 7 million, Shadowserver finds
FBI estimates rogue antivirus losses exceeding $150 million
Security researchers continue hunt for Conficker authors

Security Awareness Training and Internal Threats
CISOs take measured steps to reduce social media risks
Information security book excerpts and reviews
Schneier-Ranum face-off, part 2: Social networking
Health Net breach failure of security policy, technology
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Secure your remote users in 2010
Layoffs prompt insider threat fears, cybersecurity survey finds
How to use Internet security threat reports
Creating a HIPAA employee training program

Hacker Tools and Techniques: Underground Sites and Hacking Groups
Chinese hacker says most are not skilled coders
Security researchers continue hunt for Conficker authors
Verizon report goes deep inside data breach investigations
Russian cybercriminals target H1N1 Swine Flu fears
Metasploit Project acquisition ups ante for penetration testing market
Successful rogue antivirus hinges on social engineering
DEFCON survey suggests hacker community on vacation
DoD urges less network anonymity, more PKI use
New hacker skills optimize revenue
Maturing cybercriminal economy buoyed by business savvy hackers

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
directory traversal  (SearchSecurity.com)
government Trojan  (SearchSecurity.com)
Kraken  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
RAT (remote access Trojan)  (SearchSecurity.com)
RavMonE virus  (SearchSecurity.com)
RFID virus  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts