EXPLOITS & VULNERABILITIES

Report: Hackers Getting Faster at Cooking Up New Attacks

Print Version
E-Mail Article
Reprints

Computer hackers are whipping out exploits at an accelerating rate, according to a new IBM security report. They're able to come up with ways to attack newly discovered vulnerabilities faster thanks to automated programs, and they also benefit from well-intentioned security researchers who make too much information available too soon, according to the report.


95% of email is spam. Want to spend more time on the other 5%? Google's hosted email security, powered by Postini, stops email threats before they reach your business. There is no installation or maintenance required, freeing you to focus on strategic activities. Watch our video to learn more.

The bad guys on the Internet are narrowing the time frame they need to unleash computer attacks that take advantage of publicly disclosed security Free Trial. Security Software As A Service From Webroot. holes, new research shows.

More and more of these attacks are coming within 24 hours after a vulnerability is disclosed. That means security flaws are being exploited in Web browsers, computer operating systems and other programs before many people even have had time to learn there's a problem, according to IBM's (NYSE: IBM) Latest News about IBM latest Internet Security Systems X-Force report.

The report, scheduled to be released Tuesday, looked at the first six months of 2008 and reflects two growing trends in Internet-based threats.

Too Much Information?

The first is that online criminals have latched on in a big way to programs that help them automatically generate attacks based on publicly available information about vulnerabilities. In the past they apparently spent more time finding such holes themselves, but no longer find that as necessary.

"The bad guys are not the ones actively finding vulnerabilities -- they've shifted their business to standing on the shoulders of the security research community," Kris Lamb, operations manager Improve customer service and productivity with Avaya Unified Communications. for X-Force, said in an interview. "They don't have to do the hard work anymore. Their job is packaging what's been provided to them."

The second trend is that the debate among security researchers is intensifying over how much information should be released to the public when a new software flaw is discovered.

Most times the researcher will wait until the affected company has released a software patch before revealing details. But sometimes researchers will release not only details of the vulnerability but also so-called "proof-of-concept" exploit code to show the flaw is legitimate.

That runs the risk of providing criminals a framework for building their attacks, and saves them valuable time in doing so. Lamb said this finding "begs the question" of what the security industry's standard practice should be.

Some researchers defend the practice of supplying exploit code. They say it's a powerful tool to pressure companies into creating patches and users into applying them, and also helps technicians study how the attacks work and prevent against them in the future.

Faster Attacks

The IBM report found that the tools criminals use to generate their attacks -- known as "exploit code" -- are appearing online faster than before.

The time from vulnerability disclosure to the availability of exploit code or a working attack has typically been measured in days or even weeks as criminals try to get their arms around a newly discovered weakness.

But that gap has been shrinking quickly.

In Web browsers -- an area heavily targeted by hackers -- hacking exploits were available within a day after flaws were discovered 94 percent of the time, up from 79 percent in 2007, IBM's report said.

For all PC vulnerabilities, over 80 percent of the exploit code was released the same day -- or even before -- the holes were publicly disclosed. That's up from 70 percent last year, according to the IBM study.

Following the Clues

Exploit code can surface even before a vulnerability is made public if researchers have discussed the flaw without providing specifics.

The tactic allows them to attach their names to high-profile vulnerabilities they've discovered, while giving companies time to create patches. The downside is other researchers can often work backward from the public comments and create their own exploit code.

The report also found that spammers are changing their tactics. In many cases they are ditching the pictures and complicated messages they would include in their junk e-mail Learn how you can enhance your email marketing program today. Free Trial - Click Here. and opting instead for simple messages and a sole Web link to evade spam filters and redirect users to sites under their control. And the number of spam messages continues to rise.

© 2008 Associated Press. All rights reserved.
© 2008 ECT News Network. All rights reserved.

Social Networking Toolbox:

Print Version E-Mail Article Reprints   RSS

Related News Alerts

IBM Activate Alert | Search Archives

Related Resources

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]