Home > Security News > Symantec: Data thieves thrive on zero-day flaws
Security News:
EMAIL THIS

Symantec: Data thieves thrive on zero-day flaws

By Bill Brenner, Senior News Writer
19 Mar 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Business was good for data thieves in the second half of 2006, as they aimed their botnets and Trojan horse programs at an increasing array of zero-day flaws and took full advantage of misplaced or stolen USB flash drives. IT administrators should shield their networks from those attacks and brace for fresh phishing scams and other exploits against Windows Vista, mobile devices and virtual environments.

That's the takeaway from Symantec Corp.'s threat report for the period, released on Monday. It covers the threat landscape over the six-month period between July 1 and Dec. 31, 2006 and is similar in many respects to the vendor's threat report for the first half of 2006.

Vincent Weafer, senior director of Symantec Security Response, in Cupertino, Calif., said attackers used 2006 to continue building themselves a foundation for crime.

"Attackers are focused on data leakage and malcode that targets specific organizations and it's all about how to get your data and your assets for financial gain," he said. "The data leakage problem is about the home user as well as the enterprise. Enterprises have a responsibility to protect data, and there's a wider area to worry about as they use more VoIP and smart phones. They need to know what information is going out [via that technology]."

Among the highlights of the latest report:

  • Symantec reported more than 6 million distinct bot-infected computers worldwide during the second half of 2006, a 29% increase from the previous period. The number of command-and-control servers used to relay commands to these bots actually decreased by 25%, though Weafer attributes that to botnet owners consolidating their networks and increasing the size of their existing networks.
  • Trojans accounted for 45% of the top 50 malware samples, a 23% increase over the first six months of the year.
  • Twelve zero-day vulnerabilities were counted during the second half of 2006, marking a significant increase from the one zero-day flaw documented in the first half of the year.
  • Digital miscreants are using underground economy servers to sell stolen information, including government-issued identity numbers, credit cards, bank cards and personal identification numbers (PINs), user accounts, and email address lists.
  • Theft or loss of a computer or data storage medium, such as a USB thumb drive, made up 54% of all identity theft-related data breaches.
  • Countries with the highest amount of malicious activity originating from their networks were the U.S. at 31%; China at 10% and Germany at 7%.

Attackers are focused on data leakage and malcode that targets specific organizations and it's all about how to get your data and your assets for financial gain.
Vincent Weafer
Senior Director, Symantec Security Response
Weafer said botnets and other malware are also increasingly used for extortion and intimidation. "The bad guys are saying 'pay me money or I'll give you a denial of service,'" he said.

Going forward, Symantec warned IT security professionals to prepare for:

  • Threats against Windows Vista, with a focus on vulnerabilities, malicious code and attacks against the Teredo platform. Attackers will also target third-party applications that run on Vista.
  • New phishing economies, with phishers expected to expand their targets to include new industry sectors like online gaming. The bad guys will also develop and implement new techniques to sneak past anti-phishing solutions such as block lists.
  • An increase in spam and phishing attacks against mobile platforms.
  • New attacks against virtual environments as a way to compromise host systems.


Tags: Windows Security: Alerts, Updates and Best PracticesEnterprise Data GovernanceMalware, Viruses, Trojans and SpywareVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Windows Security: Alerts, Updates and Best Practices
New attack code targets Microsoft ActiveX zero-day vulnerability
When BIOS updates become malware attacks
Microsoft patches WebDAV security vulnerability in bevy of updates
Microsoft plans 10 security updates, fixing IE, Word, Excel vulnerabilities
Hackers targeting unpatched Microsoft DirectShow flaw
Microsoft warns of IIS zero-day vulnerability
Microsoft updates Office to address serious PowerPoint vulnerabilities
Microsoft to patch critical PowerPoint zero-day flaw
How to perform Microsoft Baseline Security Analyzer (MBSA) scans
Microsoft patches serious Excel zero-day, Windows flaws

Enterprise Data Governance
Risk management must include physical-logical security convergence
Simple information security mistakes can cause data loss, says expert
Organizations struggle with data leakage prevention, rights management
Encryption in data management should never be ignored, expert says
Attackers cash in on fundamental data handling mistakes, Verizon finds
Data loss prevention benefits in the real world
Mass., Nev. data protection laws wrong, ineffective
Cybersecurity hearing highlights inadequacy of PCI DSS
Enforcing a vendor risk assessment to avoid outsourcing security risks
How to Secure Cloud Computing

Malware, Viruses, Trojans and Spyware
How to get rid of malware, botnets on a hospital IT network
Should a national cybersecurity strategy include offensive botnets?
How to prevent mobile phone spying
How can search results lead to malware?
How to defend against rogue DHCP server malware
New Trojan stealing FTP credentials, attacking FTP websites
Cybercriminals exploit Michael Jackson, Farrah Fawcett deaths
When BIOS updates become malware attacks
Antispyware buying guide for Indian enterprises
PCI compliance requirement 5: Antivirus

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
BotHunter  (SearchSecurity.com)
principle of least privilege (POLP)  (SearchSecurity.com)
security identifier  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts