hacker
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Web threats continue to rise

Latest Symantec threat report finds a big increase in site specific attacks

Phil Muncaster, IT Week 08 Apr 2008
ADVERTISEMENT

Web security threats jumped again in the second half of last year, driven by continuing vulnerabilities in web applications and the growing maturity of the underground criminal economy, according to security vendor Symantec.

The firm's biannual Internet Security Threat Report covering July to December 2007, found that the phishing hosts – computers which host one or more phishing sites - increased in number from 32,939 in the first half of 2007, to 87,963, a 167 per cent jump. Total new threats detected in 2007 numbered 711,912 compared to 125,243 in 2006 – an increase of 468 per cent.

The report also highlighted a growth in web application vulnerabilities, especially site-specific ones which criminals are increasingly looking to exploit because they are less likely to have been patched. The number of site-specific cross site scripting vulnerabilities during the period was 11,253, as opposed to only 2,134 traditional vulnerabilities.

"There has been a huge increase in the number of threats out there – they've almost doubled – and it's happening because there's a lot more investment in automation [by the criminals]," argued senior director of global services at Symantec, Richard Archdeacon. "On the other side, there has been a huge increase in web app vulnerabilities; we need to bring up to speed everyone in the web area."

The report pointed to the growing sophistication of the underground malware economy, as it seeks to draw lessons from business to increase success rates.

In particular, it reported the outsourcing of malware production to certain countries, and the increasing agility with which the criminals are operating – switching command and control centres before law enforcers can find them

"This is being done on a massive scale now. Specialist teams buy and sell threats – it's almost a cottage industry," said Archdeacon. "There is the ability to generate industrial amounts of code and new vulnerabilities on sites give them a target."

Mike Maddison, UK head of security and privacy services at consultancy Deloitte, agreed that the malware industry is maturing at a dangerous rate. "What we've seen develop over the last two years is that the technical capabilities of organised crime have become significant and is generated out of particular geographies," he added. "They have the ability to respond much more quickly than organisations can."

Maddison added that basic web application vulnerabilities exist in about 80 per cent of the firms Deloitte checks, and warned that they need to make their development processes more robust by "building security into the lifecycle".

"For a long time availability was the challenge for customers, but with the advent of Trojans [that can steal information], it's very much about taking an information-centric view of protecting your assets, because that's certainly what the criminals are after," said Maddison.

In related news a new survey by security vendor Fortinet has found that outsourcing your coding practice could increase the risk of that code being hacked.

According to the report, 60 per cent of companies that outsource the coding of their critical applications don't mandate that security must be built into the applications, and 20 per cent don't consider security when building applications. Yet despite this, 84 percent of respondents said that code development is business critical or important.

"For a lot of firms the point of outsourcing is cost reduction, but when that's your aim you're trying to cut corners," argued Rob Rachwald of Fortinet. If you offshore code the developers may also lack that security coding exposure – they're not thinking about the negative functionality; how people can take advantage."

Rachwald added that if firms are to protect their mission critical code, the order needs to come from the top down to focus on negative as well as positive functionality in development of new applications.

See also:

vaultDetails of over 350,000 customers go missing in the post  07 Apr 2008
virusSymantec and the EC are to support a virus collecting WOMBAT  02 Apr 2008
New tools to guard software throughout lifecycle  31 Mar 2008
Users given greater IT freedoms, but not security training  28 Mar 2008
a secure systemSecurity firm Websense has launched a new threat monitoring system  26 Mar 2008
a virus wormAnalyst firm Forrester has some strong words of advice and caution for firms  26 Mar 2008

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Guildford, Surrey, United Kingdom | Enstar
 IT Development Manager/IT Development Project manager - Guildford - £40k - £60k plus benefits   Enstar (EU) Limited (formerly Castlewood (EU) Limited) is seeking an IT Development Project Manager and an IT Development Manager to ... more >
London, Haringey, United Kingdom | Haringey Council
PMO Support Officer - Haringey, London - £32,289 - £37,542 pa   Experienced project support officer required by the internal IT services organisation of a London borough council to work within its Programme Management Office ... more >
Leek Wootton, United Kingdom | Warwickshire Police
 IT Business Analyst - Leek Wootton, Warwickshire - £29,112 - £31,491 PA - 37 hrs per week   Everyone who works for Warwickshire Police helps to protect our communities from harm. Work with us and ... more >
Oxford, Oxfordshire, United Kingdom | University of Oxford
Senior Business Analyst - Oxford University - £34,793 - £45,397   Business Services & Projects (BSP) Are you an experienced Business Analyst with the skills to improve the efficiency of Oxford University's business systems? The ... more >
More job opportunities