Home > Security News > Cybercrooks going after the desktop
Security News:
EMAIL THIS

Cybercrooks going after the desktop

By Bill Brenner, News Writer
19 Sep 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Most online outlaws have abandoned server-clogging, headline-grabbing worms in favor of quieter malcode that extracts network files, hijacks identities and drops unwanted programs on PCs. They've also shifted from attacks against the network perimeter to those against client-side applications -- vulnerable browsers like Internet Explorer, for instance.

According to Symantec's latest Internet security threat report released today, that trend could continue to worsen. The Cupertino, Calif.-based antivirus giant expects cyberspace to grow even more hazardous in the future, with stealthier malcode that can download additional functionality and overwhelm networks increasingly reliant on wireless and VoIP technology.

"We had already seen this trend developing in the second half of 2004, but this year we've watched financially-motivated attacks really gain speed," said Oliver Friedricks, senior manager of Symantec Security Response. "This includes everything from stealing data from networks to stealing identities. When we look at the top 50 threats of the first half of 2005, 74% of them posed a risk of confidential information disclosure -- malware designed to open backdoors and so on. That's up from 54% in the second half of 2004."

Symantec also monitored an increase in the number of reported client-side application vulnerabilities, and the company's research indicates attackers have noticed the same thing. "We've seen a dramatic shift from attackers targeting the network parameter to attackers targeting client-side applications," Friedricks said. "Browsers are a big target, since flaws are increasing there."

He said Mozilla acknowledged 25 browser vulnerabilities in first half of the year, compared to 13 in Microsoft's much-attacked Internet Explorer. That doesn't mean Symantec now considers the latter browser more secure. "Though Mozilla had more vulnerabilities, with open source software the flaws are fixed quicker than would have been the case with IE," he said.

The bad guys realize they can accomplish a lot more by exploiting browser security holes. "These types of vulnerabilities can lead to drive-by installs," Friedricks said. "By visiting a malicious Web site, you can be infected with spyware, adware, Trojans and bots without your knowledge. These attacks have become more common."

More details on the Symantec threat summary
Symantec threat report: A closer look
The source of Symantec's findings
Symantec's conclusions are based on research it gathered from the following sources:

DeepSight Threat Management System and Managed Security Services. Through these services, the firm has more than 24,000 sensors monitoring network activities in over 180 countries.

Antivirus programs. Symantec said more than 120 million client, server and gateway systems that use Symantec antivirus products generate reports on malicious code, including spyware and adware.

Vulnerability database The company maintains a database on more than 13,000 vulnerabilities affecting more than 30,000 technologies from more than 4,000 vendors.

BugTraq. Symantec operates BugTraq, a forum where vulnerabilities are disclosed and discussed. The service has more than 50,000 subscribers.

Probe Network. Symantec also operates a system of more than 2 million decoy accounts that attract e-mail messages from 20 different countries. Symantec uses the system to measure global spam and phishing activity.

Advice for IT professionals
Grim as the picture may be, Friedricks said the situation isn't hopeless. There are a variety of steps IT professionals can take to stay ahead of the bad guys -- or at least keep up.

"My advice is to deploy defense-in-depth -- a variety of solutions to protect gateway and client-side applications like firewalls, antivirus and intrusion detection and prevention," he said. "Awareness of the latest threats is key."

Last month's attacks against Microsoft Windows' Plug and Play vulnerability showed that enterprises have nothing to fear when they stay on top of threats and take precautions, he said. "Companies that had defense-in-depth were not affected," he said.

Tags: Security Awareness Training and Internal ThreatsMalware, Viruses, Trojans and SpywareEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Awareness Training and Internal Threats
Creating a HIPAA employee training program
Successful rogue antivirus hinges on social engineering
External attacks start with unintentional mistakes, survey finds
Security technologies fail to address insider threat management
Data breach avoidance begins with security basics, panel says
Monitoring program data and internal controls for risk management
Software security threats and employee awareness training
Twitter risks, Facebook threats trouble security pros
Social engineering training could disrupt botnet growth
How to write a risk methodology that blends business, security needs

Malware, Viruses, Trojans and Spyware
Schneier-Ranum Face-Off: Is antivirus dead?
Modern malware, stealthy botnets, adapt quickly, expert says
Computer worm infections up, scareware antivirus down, Microsoft says
Web-based attacks skyrocket, pirating sites surge, security firms say
Mini guide: How to remove and prevent Trojans, malware and spyware
Kaspersky system analyzes malicious URLs on Twitter for malware
Silon malware intercepts Internet Explorer sessions, steals credentials
Breach forces payroll service provider PayChoice to shut down again
RSA research underscores problem tracking cybercriminals
Conficker analysis finds P2P coding limited, less sophisticated

Email and Messaging Threats (spam, phishing, instant messaging)
Messaging security risks have upper hand on solutions
Web-based attacks skyrocket, pirating sites surge, security firms say
Pushdo botnet uses Facebook to spread malicious email attachment
Scareware report highlights successful business model
How to prevent phishing attacks with social engineering tests
Phishing protection begins with training, antiphishing evangelist
Phishing attacks to remain a major problem, say security experts
Barracuda acquires Purewire expanding Web security reach
FBI raids phishing crime ring, nearly 100 arrested
Massive phishing scheme affects Microsoft Hotmail accounts
Email and Messaging Threats (spam, phishing, instant messaging) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
dumpster diving  (SearchSecurity.com)
Honeynet Project  (SearchSecurity.com)
insider threat  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
pretexting  (SearchCIO.com)
shoulder surfing  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
social engineering  (SearchSecurity.com)
Total Information Awareness  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts