SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Rising malware pave way for security 'white-list'

Rising malware pave way for security 'white-list'

By:   On: 16 Sep 2007 For: IT World Canada Creator

Symantec and IBM each released its own Internet security report this week. What each document say about the state of IT security.

Two reports out this week on the State of the Union security-wise, and, as you might have expected, there are some divergence in the conclusions. They’re also complementary in a way, and the pair gives a clearer picture of the security battlefield.

Symantec Corp. took the wraps off its twice-yearly Internet Security Threat Report at 12:01 a.m. Monday. IBM Internet Security Systems chipped in with its two cents later in the day.

There are some things on which the two reports agree; first and foremost that the black hats are becoming more professional and profit-oriented. “There’s money to be made in the attacks today,” Michael Murphy, GM of Symantec Canada, told journalists and analysts at an embargoed briefing on Friday.

There’s also a growing element of commercialization of the malware market. “The majority of attacks today are generated by tool kits you can buy,” Murphy said. MPack, for example, is a $1,200 phishing tool kit which compromises legitimate Web sites and redirects traffic to an MPack Server, which downloads a “small, modular threat” to the user’s system.

Further to the commercialization point, IBM Internet Security Systems’ X-Force R&D team points to a burgeoning “exploits as a service” industry (and coins the rather innocuous title of “managed exploit provider”). And the MEPs have added a leasing element, allowing malware perps to test exploits for less upfront – a sort of “try before you buy” arrangement.

The two agree that Trojans are the predominant Internet threat this year. Worms and viruses are passé, particularly in Canada where, Murphy says, ISPs have taken it upon themselves to do something about the problem. Of the Top 10 exploits catalogued by Symantec, Murphy said, seven – including Nos. 1 through 6 -- are Trojans. The other three are back doors. For its part, X-Force said Trojans accounted for 28 per cent of all malware.

And the sheer volume of malware is making the current security regimen sag at the shoulders. With more than 600,000 attacks catalogued – 212,000 of them added since January of this year – “we’re approaching a tipping point,” where there just won’t be room in antivirus databases for all of them, Murphy said. But legitimate applications are about the same in number as they were when only about 15,000 attacks had been documented. A white-list, allow-only approach may be the better one, as opposed to “an ever-growing black list.”

“I think this will be the future of security technology,” Murphy said.

A few other interesting nuggets:

• On the spam front, if you think most of your e-mail is UCE, you’re right. Symantec, monitoring from two million decoy accounts, figures 61 per cent of all e-mail is spam. Sixty per cent of that’s in English, and 47 per cent comes from the U.S. Canada dropped out of the Top 10 origin-of-spam countries. X-Force says spam message size has decreased; image-based spam is down to 30 per cent from 40 as spammers experiment with PDF- and Excel-based spam.


Sign up for our Newsletters












Print |  Views: 1150   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




dwebb

Related Content

Cyber crooks exploit recession, social media in '09
Cyber crooks exploit recession, social media in '09Cybercrime becomes all about building online communities, as crooks step up efforts to take advantage of the global fear over the recession and harness emerging social net technologies to spread malware
Top cyber-crook targets for 2008
Top cyber-crook targets for 2008A look at five online security predictions for 2008
Spammers exploit ANI glitch in Microsoft products
Spammers exploit ANI glitch in Microsoft products  Microsoft moved to fix the critical .ANI vulnerability that affects roughly a dozen of its most popular products, including Vista, but spammers and malware brokers are already tapping into the flaw to infect unprotected machines.
The pen is not mightier than the encryption software
everyone in the security sector seems to be worried about endpoint security, including symantec. i was
More efficient Norton AntiVirus for PC gamers only?
symantec corp. has announced a new version of norton antivirus software, specifically geared towards pc gamers. the selling point for norton antivirus 2009 gaming edition is that i
blog comments powered by Disqus