By Jay Lyman E-Commerce Times Part of the ECT News Network
09/19/05 12:00 PM PT
"The whole threat landscape has changed dramatically in the last two years," Verisign iDefense senior engineer Ken Dunham told The E-Commerce Times. "It's these little nickel and dime exploitations that are giving hackers access into big networks and big assets. The risk has gone up with increased exploitation capabilities."
Tech Industry Paper - Finding Strength Through Customer Service Poised to capitalize on an upturn in the economy, technology companies are focused on retention & service. This paper, from Convergys, provides the latest research on customer experience for B2B & B2C technology customers. Learn more.
Today's virus outbreaks are not as loud as the Code Red attacks of a couple years ago, but beneath the quieter computing landscape is a perilous push to turn the growing amount of personal computers and personal information into profit through cybercrime, the latest Threat Report from security firm Symantec (Nasdaq: SYMC) indicated this week.
The Symantec findings -- including a significant jump in malicious code that exposed confidential information -- showed that attackers, now motivated by profit rather than notoriety, are setting their sights on individuals and commonly used applications instead of larger, corporate networks.
Still, other security experts indicate that the growing amount of personal data, including credit card numbers, stored by large companies continues to make corporations a target of ever-more advanced and increasingly quiet attackers.
"The whole threat landscape has changed dramatically in the last two years," Verisign iDefense senior engineer Ken Dunham told The E-Commerce Times. "It's these little nickel and dime exploitations that are giving hackers access into big networks and big assets. The risk has gone up with increased exploitation capabilities."
Rogue Code Report
In the eighth volume of its semi-annual Internet Security Threat Report, Symantec said malicious code that exposed confidential information jumped from 54 percent of the top 50 threat samples reported to 74 percent in the second half of this year.
"Attackers are moving away from large, multi-purpose attacks on network perimeters and toward smaller, more targeted attacks directed at Web and client-side applications," read a statement from Symantec Vice President Arthur Wong.
The security company also reported an increased incidence of networks of "bots" -- compromised computers amassed by hackers and used for attacks. These bot networks are even made available to rent.
Other malware on the rise includes "modular malicious code," bits of code with limited functionality that can then be updated with downloads, as well as phishing attacks -- the creation of bogus sites intended to lure users into disclosing data. Symantec said that phishing had risen from an average of 2.99 million messages per day in the first half of this year to 5.7 million messages per day in the latest report.
From Blaster to Bots
Dunham said that, rather than seeking to seize corporate networks and tout their control, today's profit-motivated attackers are more interested in nibbling away at the personal data that brings them profit.
"This shows a dramatic change in the nature of the risk. It's all about command and control for cash," Dunham said.
"It's a migration from the Blasters of the world to bots," he added, comparing the high-profile Blaster virus outbreak to the more recent Zotob outbreak, which involved many variants. "They're like mosquitoes. They just pick at you until you have no blood left."
Dunham also referred to the increase in bot networks, which are actually advertised for rent, sale or exploit among hackers online.
The security expert noted that Symantec's latest report validated his own company's findings, which mark the "movement to criminality for code" and an increase in "under-the-radar attacks."
Staying Ahead of the Head Games
Symantec said that, as the threat landscape continues to change, users need to be diligent in keeping systems up-to-date. The company also warned that, as the financial rewards increase, attackers will likely develop more sophisticated and stealthier malicious code that will be "implemented in bot features and networks," including disabling antivirus, firewalls and other protections.
Dunham said that users -- both consumers and corporate -- must also be aware of the social engineering tricks that are being refined by attackers, who are more likely now to single out a CEO or another official in an organization.
Critics: Ask Jeeves Silently Serves Software September 13, 2005
"No one should install any software without telling the computer user before doing it," Basex chief analyst Jonathan Spira told TechNewsWorld. "Burying it in a disclosure document that is not read by 99.9 percent of users is not an excuse."
Related Stories
Phishing, Malware Scams Rise in Katrina's Wake September 02, 2005
While many are legitimate, others have proven to be scams. Other scams have come in the form of e-mails that contain a link to PayPal, but when SANS attempted to reach e-mail senders to request a physical address to mail a check, no response came.
Analyst Hopes Zotob Arrests Slow Malware Activity August 29, 2005
"There's little to learn," Mikko Hypponen, director of antivirus research, F-Secure, told TechNewsWorld about the lessons of the malware attacks. "The problem is that few large companies can test and deploy patches company-wide in just five days, which was the deadline in this case."
Malware for Money: Zafi, Sober, Netsky Still Haunting Net July 01, 2005
Netsky-P, which was the hardest-hitting virus of 2004 and still ranks second on Sophos top 10 list, has enjoyed an extremely long reign near the top of the virus chart so far in 2005. German teenager Sven Jaschan, who admitted writing the Netsky and Sasser worms more than a year ago, will face trial next week.
Adoption of Alternate E-Mail Security Technologies Pushed June 25, 2005
"Each protocol provides different answers to different problems involving e-mail security issues. But both new protocols deal with sender authentication," Thomas Gillis, senior vice president for worldwide marketing at IronPort Systems, said.
Report Suggests Security Software Attacks Increasing June 21, 2005
Yankee Group recommended quality assurance and penetration testing measures such as reviewing security designs early and often; integrating security tests into regular software builds; reviewing code base; and truly simulating the tactics of an attacker.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.