Home > Security News > Cisco: Cybercriminals more savvy than ever in 2008
Security News:
EMAIL THIS

Cisco: Cybercriminals more savvy than ever in 2008

By Marcia Savage, Features Editor, Information Security magazine
15 Dec 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Internet criminals are always devising new tactics but this year they reached incredible new levels in sophistication and specialization, according to security researchers at San Jose-based Cisco Systems Inc.

SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

"We've seen a streak of capitalism to maximize their profits and an ability for them to work together in ways that are truly mind boggling," said Patrick Peterson, Cisco fellow and chief security researcher.In the Cisco Annual Security Report released Monday, researchers reported seeing a 90% growth in threats originating from legitimate domains this year, nearly double of what they saw in 2007. Other key findings from the report: Spam accounted for nearly 200 billion messages every day -- about 90% of email sent worldwide, and the overall number of disclosed vulnerabilities grew by 11.5%. Specifically, vulnerabilities in virtualization products shot up to 103, up from 35 last year.

Listen to the interview:
Information Security magazine's Marcia Savage interviews Patrick Peterson, Cisco fellow and chief security researcher about Cisco's Annual Threat Report. (8 min)

Download Mp3

Peterson cited CAPTCHA breaking for "reputation hijacking" as an example of criminals' increased savvy. CAPTCHA, or Completely Automated Turning Test to Tell Computers and Humans Apart, is used by free webmail services as a security measure when new accounts are created, but criminals are using automated and manual processes to circumvent the technology, Peterson said.

Businesses have popped up in India and China that employ people to manually type in the distorted text used in CAPTCHA tests, which are designed to ensure the response is not computer-generated, he said. Criminals then use the email accounts, which appear legitimate, for more effective spam delivery, targeted phishing attacks and to distribute links to malicious websites.

According to Cisco estimates, spam due to email reputation hijacking of the top three webmail providers -- Yahoo, Google and Microsoft -- accounted for less than 1 % of all spam worldwide but made up 7.6 % of all the providers' mail.

Related threat reports:
Flash, PDF are growing malware targets: Security vendor Finjan reports a growing army of cybercriminals are buying cheap toolkits to exploit the Web.

Cybercrime leaves cybercops in the virtual dust: McAfee report paints bleak picture of Internet law enforcement.

Spam declines, Web-based attacks rise, says MessageLabs: Spam was down 3.4% in 2008, but attacks on social networks and flaws in websites are rising, according to an annual report from Symantec's MessageLabs.

The report also shows that criminals exploited vulnerabilities in Web browsers, media players and browser plug-ins -- what Cisco calls the Web ecosystem -- to gain control of computers, networks and data.

Developers are rushing to provide functionality for rich media content on the Web, but the report shows that's not always done securely, Peterson said.

Web security should be a priority for enterprises next year, and they should also fine-tune their procedures for patching and updating software, he said. "Part of that criminal specialization is finding these vulnerabilities and weaknesses in our software and getting them published…much more quickly than we've seen one or two years ago," he said.

One type of attack actually declined this year, according to Cisco: Malware propagated via email attachments. The number of email attachment-based attacks decreased 50% over the past two years compared to 2005-2006.



Tags: Security Industry Market Trends, Predictions and ForecastsApplication Attacks (Buffer Overflows, Cross-Site Scripting)Virtualization Security Issues and ThreatsMalware, Viruses, Trojans and SpywareEmerging Information Security ThreatsHacker Tools and Techniques: Underground Sites and Hacking GroupsEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Security Industry Market Trends, Predictions and Forecasts
Cybersecurity czar candidate questions clout of new position
Gartner sees better days ahead for security budgets
Sophos CEO on Symantec, McAfee after Utimaco acquisition
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Security budgets take hit in media, tech industry, survey finds
Cybersecurity Act of 2009: Power grab, or necessary step?
Opinion: Gartner gets NAC wrong, again
Cloud computing security group releases report outlining trouble areas
White House cybersecurity advisor calls for public-private cooperation
Security Industry Market Trends, Predictions and Forecasts Research

Application Attacks (Buffer Overflows, Cross-Site Scripting)
Adobe ColdFusion websites being compromised
PCI management: The case for Web application firewalls
Month of Twitter Bugs project to document Twitter flaws
Adobe issues first quarterly patch release fixing 13 flaws
Balancing security and performance: Protecting layer 7 on the network
Adobe issues Reader update fixing zero-day flaw
The Pipe Dream of No More Free Bugs
Security Squad: Federal cybersecurity defenses
Oracle issues 43 updates, fixes serious database flaws
Attackers target new Microsoft PowerPoint zero-day flaw
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

Virtualization Security Issues and Threats
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Virtual appliances boost flexibility, improve security
Lack of cloud computing definition adds confusion, risk
Three cloud computing risks to consider
App service cloud could boost security, manageability
Kodak CISO on virtualization, compliance
Face-off: Assessing cloud computing risks
Citrix virtual desktop, app delivery controller includes security benefits
Who should secure virtual IT environments?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
backscatter body scanning  (SearchSecurity.com)
marketecture  (SearchSecurity.com)
NCSA  (SearchSecurity.com)
Palladium  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts