SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Cyber criminals converging

Cyber criminals converging

By:  Mari-Len De Guzman  On: 29 Mar 2007 For: ComputerWorld Canada Creator

There’s a different kind of consolidation taking place in the IT space and it is one trend organizations should be cautious about

COMMENT ON THIS ARTICLE

There’s a different kind of consolidation taking place in the IT space and it is one trend organizations should be cautious about.

Cyber criminals are getting more organized and are refining their methods to make their attacks more coordinated, according to the latest Internet Security Threat Report (ISTR) released by antivirus vendor Symantec Corp.

While higher levels of malicious activity were still observed, the past six months saw an increasing trend toward the consolidation of malicious activities such as phishing, spam, bot networks, Trojans and zero-day threats.

“Whereas in the past these threats were often used separately, attackers are now refining their methods and consolidating their assets to create global networks that support coordinated criminal activity,” the Symantec report indicated.

Symantec’s ISTR is released every six months and contains details of Internet security and threat activities around the world. The report is essentially a compilation and analysis of security data gathered from over 40,000 intrusion detection system and firewall sensors in 180 countries, over 120 million systems that deploy Symantec’s antivirus products, and over two million decoy accounts that attract e-mails from about 20 countries.

The recently released ISTR includes security data collected between July 1 and Dec. 31, 2006.

According to the report, there is increasing interoperability among threats and attack methods, where one attack can pave the way for another attack or a series of attacks. For example, targeted malicious code may take advantage of vulnerabilities in Web-enabled technologies and third-party applications to install a back door that can be used to download and install bot software, creating a network of bot-infected computers.

Bots are programs installed on a computer, without the user’s knowledge, which allows an attacker to remotely control the infected system and use it for distributing spam, hosting phishing sites or launching attacks, creating a single, coordinated network of malicious activity.

The ISTR showed an increase in the number of bot-infected computers per day to 63,912, or an 11 per cent increase from the previous reporting period.

There was also a 25 per cent decrease in the number of command-and-control servers worldwide. Bot network owners use command-and-control servers to relay commands to bot-infected systems in order to carry out an attack.

The rising number of bot-infected computers and the decreasing number of command-and-control servers are an indication that bot networks are also consolidating, said Dean Turner, executive editor of ISTR.

“This really is a thriving ecosystem because it generates millions of dollars,” he said. Because the motivation has long since changed from fame to fortune, today’s malicious attackers are also making an effort to remain anonymous, in contrast to the earlier generation of bragging hackers.


Sign up for our Newsletters












Print |  Views: 654   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Mari-Len De Guzman Mari-Len De Guzman is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Don't use WEP, say German security researchers
Don't use WEP, say German security researchersThe Wi-Fi security protocol WEP should not be relied on to protect sensitive material, according to three German security researchers who have discovered a faster way to crack it. They plan to demonstrate their findings at a security conference in Hamburg this weekend.
Issues with SSID cloaking
Issues with SSID cloakingAre there any pitfalls to using SSID cloaking? Many organizations use SSID cloaking as a mechanism to add a layer of security to the WLAN. This technique requires that all users have knowledge of the SSID to connect to the wireless network. While this is commonly viewed as a mechanism to improve security and is a recommended best-practice by the PCI Data Security Standard, it can reduce the effective security of the WLAN.
New Brunswick university hosts hi-tech research hub
New Brunswick university hosts hi-tech research hubThe University of New Brunswick (UNB) in Fredericton recently became home to one of the first research facilities in Canada focusing solely on information and network security studies
Keep your resume safe, and your data even safer
mari-len wrote an article in the latest cw that i thought was really inventive. after the recent scandal around monster.com losing all kinds of user information,
blog comments powered by Disqus