http://www.homelandsecuritynewswire.com/internet-threat-landscape-offers-gri
m-picture

 


Internet threat landscape offers a grim picture


Published 6 April 2011

A new Symantec report paints a grim picture of the Internet threat
landscape; Symantec detected more than three billion malware attacks from
286 million malware variants in 2010 -- up 93 percent on 2009; 49 percent of
malicious sites found through Web searches were pornographic; in 2010, 6,253
software vulnerabilities were reported, higher than in any previous year;
fourteen vulnerabilities were used in zero-day attacks, including four
different Windows zero-days used in the Stuxnet attack; the bad guys also
demonstrated a firm grasp of new technology: social networking sites are a
huge target, and hackers are exploiting the boom in URL shortening services
such as bit.ly; smartphones are also beginning to attract malware

The numbers are staggering. Symantec detected more than three billion
malware attacks from 286 million malware variants last year, according to
the 2010 edition of its annual Internet Security Threat Report, published
the other day <http://www.symantec.com/business/threatreport/index.jsp> .
Web-based attacks were up 93 percent on 2009, and you were most likely to
come across a malicious Web site if you were on the hunt for pornography; 49
percent of malicious sites found through Web searches were pornographic.

Ars technica reports
<http://arstechnica.com/security/news/2011/04/2010-in-malware-business-is-bo
oming.ars?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+arstech
nica%2Findex+%28Ars+Technica+-+Featured+Content%29>  that overall, the
report paints a grim picture of the Internet threat landscape. Software
flaws are abundant. In 2010, 6,253 software vulnerabilities were reported,
higher than in any previous edition of the report. Fourteen vulnerabilities
were used in zero-day attacks, including four different Windows zero-days
used in the Stuxnet attack.

Though data breaches are still relatively rare - 457 in 2010
<http://datalossdb.org/yearly_reports/dataloss-2010.pdf>  according to
aggregator DataLossDB - they still put many at risk. About 61,000 identities
were compromised on average, with breaches in the finance sector
particularly big, at an average of over 235,000 identities per breach.
Breaches as a result of hacks - rather than insiders, or theft or loss of
hardware and media - tended to be substantial, averaging more than 262,000
identities per hack.

Symantec notes that the bad guys also demonstrated a firm grasp of new
technology. Social networking sites are a huge target, both due to their
wide use and their enormous susceptibility to social engineering. In mass,
untargeted attacks, the social networking sites give malicious links a
veneer of integrity - if a friend of yours posts a link it is surely going
to be safe. For spear-phishing and other targeted attacks, the social
networks give valuable insight into individual habits and interests, not to
mention the ability for hackers to strike up friendships with their would-be
victims and to gain their trust that way.

Hand in hand with social networking sites like Twitter, there has also been
a boom in URL shortening services such as bit.ly. Hackers have been quick to
exploit the way these mask the destination URL, making it much harder to
know whether a link is malicious until you actually click on it. Two-thirds
of attacks used on social networking sites used such masked, shortened URLs.


Smartphones are also beginning to attract malware. 2010 saw the discovery of
the first Android trojan, and it looks like hackers regard Android as a ripe
platform for attacks-last month more than 50 malicious programs were yanked
from Android Market
<http://arstechnica.com/open-source/news/2011/03/malware-in-android-market-h
ighlights-googles-vulnerability.ars> . More vulnerabilities are being found
on mobile platforms, with 163 found last year, an increase of 41 percent.
While still small-scale attacks compared to their PC-based counterparts,
this is set to be a growth market. Smartphones are chock full of personal
information and thanks to premium rate phone and text numbers, have an
unparalleled ability to monetize malware.

Symantec says that 2010 was also a big year for targeted attacks; Google
came out as a victim of the Aurora attacks
<http://arstechnica.com/tech-policy/news/2010/01/furious-google-throws-down-
gauntlet-to-china-over-censorship.ars> , and Stuxnet struck Iran. The
targeted attacks were notable for their use of zero-day vulnerabilities -
three different Internet Explorer zero-days were used in three separate
targeted attacks, and Stuxnet used four Windows zero-days.

Ars Technica notes that the use of zero-days is significant because it means
that even an organization with good practices (patching machines on a timely
basis, using anti-malware software) is at risk; these old mechanisms do
little to guard against this style of attack. Heuristic analysis and
sandboxing techniques both have a role to play in detecting these problems
but work still needs to be done to make these easy to use, robust, and
effective.

More than anything else, the report shows that the security situation is not
improving; it is getting worse. Social networking-based social engineering
and zero-day targeted attacks put even conscientious, well-educated users at
risk.

 



[Non-text portions of this message have been removed]



------------------------------------

--------------------------
Want to discuss this topic?  Head on over to our discussion list, 
[email protected].
--------------------------
Brooks Isoldi, editor
[email protected]

http://www.intellnet.org

  Post message: [email protected]
  Subscribe:    [email protected]
  Unsubscribe:  [email protected]


*** FAIR USE NOTICE. This message contains copyrighted material whose use has 
not been specifically authorized by the copyright owner. OSINT, as a part of 
The Intelligence Network, is making it available without profit to OSINT 
YahooGroups members who have expressed a prior interest in receiving the 
included information in their efforts to advance the understanding of 
intelligence and law enforcement organizations, their activities, methods, 
techniques, human rights, civil liberties, social justice and other 
intelligence related issues, for non-profit research and educational purposes 
only. We believe that this constitutes a 'fair use' of the copyrighted material 
as provided for in section 107 of the U.S. Copyright Law. If you wish to use 
this copyrighted material for purposes of your own that go beyond 'fair use,' 
you must obtain permission from the copyright owner.
For more information go to:
http://www.law.cornell.edu/uscode/17/107.shtmlYahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/osint/

<*> Your email settings:
    Individual Email | Traditional

<*> To change settings online go to:
    http://groups.yahoo.com/group/osint/join
    (Yahoo! ID required)

<*> To change settings via email:
    [email protected] 
    [email protected]

<*> To unsubscribe from this group, send an email to:
    [email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/

Reply via email to