Home > Security News > Microsoft sees OS flaws drop, application breaches rise
Security News:
EMAIL THIS

Microsoft sees OS flaws drop, application breaches rise

By Robert Westervelt, News Editor
03 Nov 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Operating system flaws continue their steady decline as attackers target application vulnerabilities, according to Microsoft's semiannual Security Intelligence Report.

There is a marketplace for the higher severity vulnerabilities and so that's where researchers are finding their focus.
Jeff Williams,
principal architect, Microsoft Malware Protection Center

Microsoft said nearly 90% of vulnerabilities discovered by researchers were in applications. OS flaws reached a high of 16% of all vulnerabilities discovered in 2003 and today they make up about 7% of flaw discoveries.

"Hackers attack low hanging fruit because it's easier for them," said Eric Domage, manager of security research and consulting at research firm IDC. "They think that if they spend their time on Vista, it is wasted time."

Despite a drop of interest in the OS, malicious software removed from Windows computers grew by 43% during the first half of 2008. Threats from keyloggers and other malicious programs continue to rise, as users get tricked into clicking on malicious email attachments. Web-based attacks are also contributing to the spread of malware, Microsoft said.

The Microsoft Security Intelligence Report, released today, discloses trends researchers observed from January 2008 to June 2008. The report is in its fifth iteration and pulls together data from hundreds of millions of Windows users as well as data from other security firms.

Microsoft said the total number of unique vulnerability disclosures across the industry continued to decrease in the first half of 2008, with new vulnerability disclosures declining by 4% from the second half of 2007 and by 19% from the first half of 2007.

SearchSecurity radio:

"The decrease in vulnerabilities is definitely due to the security development lifecycle, and just a general focus on security across the industry," said Jeff Williams, principal architect for the Microsoft Malware Protection Center.

Researchers are finding fewer vulnerabilities, but the flaws they discover are more severe, according to Microsoft. The vulnerabilities rated as high severity according to the Common Vulnerability Scoring System has increased 13% over the second half of 2007.

"There is a marketplace for the higher severity vulnerabilities and so that's where researchers are finding their focus," Williams said. "The ones who are working for the criminals are working to monetize it through criminal channels and the ones who are working through other monetization channels are looking to get the higher payoff."

Williams also heralded Microsoft's Trustworthy Computing Security Development Lifecycle as the reason for the decline in vulnerabilities. The process adds an increased security focus on each phase of the software maker's development process. Microsoft designed Vista using the SDL process, and while some analysts point to user frustration over the security controls resulting in slower adoption of Vista, it has slowed targeted attacks on the OS.

"Particularly in the case of Vista, we've seen significant reduction in the attack surface and as a result there are fewer vulnerabilities there," Williams said.

Browser-based attacks on Windows Vista-based machines accounted for just 6% percent of the total Microsoft vulnerabilities, while third-party vulnerabilities made up 94%.

"Attackers have limited interest in going into Vista," IDC's Domage said. "There's less market penetration of Vista, and a lack of interest by hackers to go into the OS level since they get low results because it's so robust from a security perspective."



Tags: Windows Security: Alerts, Updates and Best PracticesEmerging Information Security ThreatsApplication Attacks (Buffer Overflows, Cross-Site Scripting)Malware, Viruses, Trojans and SpywareVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Windows Security: Alerts, Updates and Best Practices
Exploit code targets Internet Explorer zero-day display flaw
Windows 7 DoS flaw allows hackers to freeze Microsoft's newest OS
Microsoft patches serious Windows kernel flaws
Microsoft to address flaws in Windows, Office for Mac
Microsoft fixes security update that breaks Internet Explorer
What is the best database patch management process?
Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
Microsoft releases temporary fix for SMB2 zero-day vulnerability
Microsoft issues SMB vulnerability advisory, patch pending

Emerging Information Security Threats
Hackers to sharpen malware, malicious software in 2010
Modern malware, stealthy botnets, adapt quickly, expert says
New ransomware Trojan pushes victims to buy software
Bruce Schneier on outsourcing, awareness training
US-CERT warns of BlackBerry snooping software
Marcus Ranum on cyberwarfare, infosec careers
Researchers find thousands of flawed embedded devices
Enterprise botnets contain thousands of malware variants
Nuke and pave to eradicate botnets
Rand study urges caution on cyberwarfare attacks

Application Attacks (Buffer Overflows, Cross-Site Scripting)
Quiz: How to build secure applications
Black box and white box testing: Which is best?
Adobe warns of critical update for Reader, Acrobat 9.1.3
9 Ways to Improve Application Security After an Incident
Developers Need Help with Security Errors
Buffer overflow tutorial: How to find vulnerabilities, prevent attacks
SQL injection protection: A guide on how to prevent and stop attacks
Experts rebuke programmers who use SQL injection as feature
SANS: Application threats, website flaws pose biggest security threats
Mozilla helps Adobe push out faster patches
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
BotHunter  (SearchSecurity.com)
principle of least privilege (POLP)  (SearchSecurity.com)
security identifier  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts