Home > Security News > Web-borne malware targets unexpected industries
Security News:
EMAIL THIS

Web-borne malware targets unexpected industries

By Neil Roiter, Senior Technology Editor, Information Security magazine
13 Nov 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The unprecedented barrage of Web-borne malware in 2008 is falling in very unexpected patterns, striking users in select -- and somewhat surprising -- verticals in far greater numbers than others.

SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

A study, The Vertical Risk: Web-Delivered Malware Impact by Industry by ScanSafe Inc., analyzed how many times its Web security service blocked malware when users browsed compromised Web pages. The result showed the highest incidence in four startling verticals: energy and oil, pharmaceutical and chemical, engineering and construction, and transportation.

At the other extreme with the lowest incidence of blocking Web malware, were aviation and automotive, healthcare and insurance.

The question the research leaves unanswered is: "Why?"

"I was really surprised; these are not the verticals I would have anticipated," said Mary Landesman, senior security researcher at ScanSafe. The results were sorted into 21 verticals.

The report said the researchers expected that malware exposure would reflect surfing habits and that high-risk verticals would be things like travel and entertainment, which was fifth highest, and media and publishing, which was well below the median. Certainly, they did not expect to see the four sectors that were far and away at highest risk.

SearchSecurity radio:

The numbers are unassailable, based on an average of 17 billion Web requests and 170 million malware blocks per month from Jan. 1 through Sept. 30. Assuming the employees in these organizations are not, on the whole, stupider than their peers in other industries or more prone to dangerous Web surfing habits, the results are very confounding. The natural speculation is that there is a good deal of social engineering taking place in these verticals, and, by inference, targeted attacks. There's some evidence to suggest that may be the case.

"That's my hunch," said Landesman. "The number of unique variants and the higher number of outbound attempts point to social engineering."

The malicious outbound requests were overwhelmingly higher in the three worst sectors. This reflected requests that did not come from typical user behavior -- clicking on a link from Google, or typing in a URL from another Web page. Rather, they went directly to the compromised website, pointing to a user who was somehow manipulated, or a request from an already compromised PC.

The number of unique malware variants found in the hardest-hit sectors also suggests some deliberate focus on them.

"When you look at the individual number of variants and they still come out so much ahead, it's very concerning," said Landesman. "It indicates they're getting more than their fair share of socially engineered attacks."

This disturbing pattern comes in a year when the growth of Web-delivered malware has gone off the charts, actually starting late last year, Landesman said. ScanSafe's July Global Threat Report showed more Web-borne malware that month than in all of 2007. October was up another 21%. She points to a convergence of three factors fueling the fire:

  • The maturity of Web 2.0 and the "sheer number of websites and inexperienced people who are able to put up websites."
  • Automated tools that allowed for discovery of vulnerable Web servers and sites. Attackers no longer have to manually probe for vulnerable targets that are slow, inefficient and exposed the attacker to discovery.
  • Exploit frameworks available in the public sector. These are prebuilt with exploits that make it easy and cost effective to push out and deliver payloads.

    That's discouraging enough, Landesman said, but the possibility of a strong focus on targeted verticals makes the huge numbers even more disturbing.

    "I was looking for people that did heavy, heavy research so they were of necessity visiting lots of different and diverse Web sites, based on my expectations of what I believed was leading to much of this," she said. "In fact, there appears to be a great deal of social engineering involved. And I have to question that there is some sort of targeting."



    Tags: Malware, Viruses, Trojans and SpywareSecurity Industry Market Trends, Predictions and ForecastsSecurity Awareness Training and Internal ThreatsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Malware, Viruses, Trojans and Spyware
    Schneier-Ranum Face-Off: Is antivirus dead?
    Modern malware, stealthy botnets, adapt quickly, expert says
    Computer worm infections up, scareware antivirus down, Microsoft says
    Web-based attacks skyrocket, pirating sites surge, security firms say
    Mini guide: How to remove and prevent Trojans, malware and spyware
    Kaspersky system analyzes malicious URLs on Twitter for malware
    Silon malware intercepts Internet Explorer sessions, steals credentials
    Breach forces payroll service provider PayChoice to shut down again
    RSA research underscores problem tracking cybercriminals
    Conficker analysis finds P2P coding limited, less sophisticated

    Security Industry Market Trends, Predictions and Forecasts
    M86 buys Web security gateway vendor Finjan
    Information Security Decisions 2009: Presentation downloads
    Bruce Schneier on outsourcing, awareness training
    Marcus Ranum on cyberwarfare, infosec careers
    McAfee survey finds faults in midmarket enterprise security
    Email archiving vendor sues Gartner over Magic Quadrant
    Information Security magazine October issue PDF
    Editor's Desk: Security 7 Winners Chronicle Trends That Shape The Industry
    Information Security magazine Security 7 Award winners
    Security Squad: Privacy gone awry
    Security Industry Market Trends, Predictions and Forecasts Research

    Security Awareness Training and Internal Threats
    Creating a HIPAA employee training program
    Successful rogue antivirus hinges on social engineering
    External attacks start with unintentional mistakes, survey finds
    Security technologies fail to address insider threat management
    Data breach avoidance begins with security basics, panel says
    Monitoring program data and internal controls for risk management
    Software security threats and employee awareness training
    Twitter risks, Facebook threats trouble security pros
    Social engineering training could disrupt botnet growth
    How to write a risk methodology that blends business, security needs

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    bot worm  (SearchSecurity.com)
    directory traversal  (SearchSecurity.com)
    government Trojan  (SearchSecurity.com)
    Kraken  (SearchSecurity.com)
    man in the browser  (SearchSecurity.com)
    polymorphic malware  (SearchSecurity.com)
    RAT (remote access Trojan)  (SearchSecurity.com)
    RavMonE virus  (SearchSecurity.com)
    RFID virus  (SearchSecurity.com)
    Rock Phish  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts