Home > Security News > Report: IM, P2P threats on the rise
Security News:
EMAIL THIS

Report: IM, P2P threats on the rise

By Bill Brenner, Senior News Writer
12 Apr 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

According to the results of newly released research, threats targeting instant messaging (IM) and peer-to-peer (P2P) applications rose significantly in the first quarter of 2006 compared to the same period last year.

The findings come from research by Foster City, Calif.-based vendor FaceTime Communications Inc.

The company examined what it calls "greynets," programs installed on a system without permission from IT departments that are adept at evading existing security tools. The company considers instant messaging IM, peer-to-peer and spyware as greynet programs. Data used in the company's analysis came from server log files maintained by its lab. Each individual incident report represents the detection of a security issue impacting one or more real-time communications channels on one day, FaceTime said.

"The number of threats across multiple P2P and IM channels demonstrates the need for a comprehensive approach to managing threats," Tyler Wells, FaceTime's research director, said in a statement. "As malware creators increasingly attack these mainstream applications, administrators should ensure they have the ability to control and manage them."

Based on the criteria, FaceTime painted the following picture for the first quarter:

  • With 453 incidents recorded in the period, the number of security incidents was 723% percent higher in Q1 2006 compared to the same period last year.
  • The growth in threat incidents targeting public IM channels stabilized during the quarter, but the complexity of incidents and use of multiple delivery methods increased.
  • Multi-channel propagation was 23 times more common in Q1 2006 than the same period last year.
  • Internet Relay Chat (IRC) and chat-based attacks continue to dominate, but their share of all attacks dropped in favor of an increasing number of P2P attacks.
  • P2P attacks were almost 15 times more common in Q1 2006 when compared with a year earlier.
  • The number of threats using P2P in the first quarter has already surpassed the total number of P2P attacks in all of 2005.

    For more information

    IM threats grow, response lags

    Tips for securing Web-based applications

    Guide to understanding risk management

    FaceTime's report is the latest to show a surge in the level of malware targeting real-time communications programs.

    In February, Waltham, Mass.-based IMlogic Inc. and San Diego-based Akonix Systems Inc. released reports showing a dramatic spike in IM threats last year and an IT community that has yet to achieve an adequate defense.

    IMlogic reported a 1,700% increase in reported incidents in 2005, compared to all reported incidents in 2004. Meanwhile, Akonix surveyed more than 100 organizations and found that IM threats aren't on the radar screen for most of them. Only 11% reported having IM security tools in place, compared to 73% who use e-mail security programs. Incredibly, the company said, almost 50% of respondents replied that "an IM hygiene solution never crossed my mind."

    IT professionals have long lamented that it's difficult to block IM threats, since most programs are installed by end users and are hard to monitor.

    Tags: IM Security Issues, Risks and ToolsSecurity Industry Market Trends, Predictions and ForecastsApplication Attacks (Buffer Overflows, Cross-Site Scripting)Enterprise Risk Management: Metrics and AssessmentsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    IM Security Issues, Risks and Tools
    What are effective ways to stop instant messaging (IM) spam?
    Secure messaging complications result in limited protection
    Is it possible to ban chat programs on an enterprise LAN?
    How to lock down instant messaging in the enterprise
    AOL closes AIM attack vector, but risks remain
    Researcher says AIM still vulnerable, AOL insists it's fixed
    Serious security flaw in AOL Instant Messenger
    Security flaws found in AOL, Yahoo IM programs
    Flaw found in MSN Messenger
    AOL, Yahoo, Trillian IM applications under threat

    Security Industry Market Trends, Predictions and Forecasts
    Cybersecurity czar candidate questions clout of new position
    Gartner sees better days ahead for security budgets
    Sophos CEO on Symantec, McAfee after Utimaco acquisition
    WH cybersecurity plan needs private sector guidance
    Obama announces creation of cybersecurity coordinator position
    Security budgets take hit in media, tech industry, survey finds
    Cybersecurity Act of 2009: Power grab, or necessary step?
    Opinion: Gartner gets NAC wrong, again
    Cloud computing security group releases report outlining trouble areas
    White House cybersecurity advisor calls for public-private cooperation
    Security Industry Market Trends, Predictions and Forecasts Research

    Application Attacks (Buffer Overflows, Cross-Site Scripting)
    PCI management: The case for Web application firewalls
    Month of Twitter Bugs project to document Twitter flaws
    Adobe issues first quarterly patch release fixing 13 flaws
    Balancing security and performance: Protecting layer 7 on the network
    Adobe issues Reader update fixing zero-day flaw
    The Pipe Dream of No More Free Bugs
    Security Squad: Federal cybersecurity defenses
    Oracle issues 43 updates, fixes serious database flaws
    Attackers target new Microsoft PowerPoint zero-day flaw
    How to detect input validation errors and vulnerabilities
    Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    greynet  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    Focused on Channel Security?
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts