SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

SQL Injection, Active X on decline: IBM X-Force report

SQL Injection, Active X on decline: IBM X-Force report

By:  Kathleen Lau  On: 26 Feb 2010 For: ComputerWorld Canada Creator

IBM’s X-Force 2009 Trend and Risk report shows a drop in some popular attacks, and a 345 per cent rise in others like new malicious Web links. Security consultant Brian O’Higgins said social engineering continues to be a useful tool for malware authors

IBM’s X-Force 2009 Trend and Risk report shows an 11 per cent drop in discovered vulnerabilities compared to 2008, including a decline in the largest categories like SQL Injections and ActiveX.

 

SQL Injection gained a lot of popularity as “proverbial flavour of the month,” and was subsequently exploited to the point that there were few who didn’t know what it was, said Nick Bradley, manager with IBM’s managed security services intelligence centre. “Now the awareness has saturated the industry. More are actively looking to protect against it,” said Bradley.

 

The 11 per cent decline in vulnerabilities is “really a drop in the bucket” in terms of the overall number of vulnerabilities, noted Bradley. Some contributing factors, he said, could be the retirement of two of the most “prolific discoverers of vulnerabilities” – r0t and rgod – and the disappearance of a well-known site for vulnerability publication, milw0rm.

 

That aside, Bradley acknowledges the increased awareness among software vendors regarding the value of security in the products they build.

 

The report also found a significant increase in attacks using obfuscation, often launched using automated exploit toolkits, to hide from security software. Since security awareness goes both ways, Bradley said it’s natural that malware creators will strive to exploit the very same vulnerabilities that the security industry tries to stop.

 

“It’s like a game of cyber cat and mouse, now that the mouse is aware that the cat is watching, it's going to look for new hiding places and safer modes of travel,” said Bradley.

 

The report also states that new malicious Web links increased by 345 per cent compared to 2008, indicating that hackers are getting better at hosting malicious sites. And phishing scams still continue to target the financial industry, with 61 per cent of overall phishing e-mails.


Sign up for our Newsletters












Print |  Views: 4367   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Kathleen Lau Kathleen Lau was a senior writer with ITWorldCanada.com and ComputerWorld Canada from December 2006 to August 2011.In her role as senior writer, she covered broadly technology news and issues r... more

Related Content

Fear, greed, lust: Phishing's sure-fire lures
Fear, greed, lust: Phishing's sure-fire luresA report from McAfee outlines the persuasive "mind games" cyber criminals play to get users clicking their way into an IT security breach. Experts discuss the right way to train your staff
Apps under attack
Apps under attackSecurity is just like quality – you’re never finished, because there’s always room for improvement. Compounding the problem is the fact that the security threat continues to evolve; it simply moves to attack new vulnerabilities as soon as you patch old ones. Not surprisingly, in the past few months we have seen a new trend – attacks that target web applications.
Bush advisor predicts possible cyber-catastrophes
Bush advisor predicts possible cyber-catastrophesIn his keynote address at an information technology auditing conference in New York, Howard Schmidt, U.S. President Bush's advisor on cybersecurity, predicted that networks operated in the U.S. and abroad are likely to be brought down by catastrophic events unless security greatly improves.
Cyber crooks getting cleverer
by joaquim p. menezes - several years ago, john roese – when he was chief technology officer of enterasys networks (he’s now cto of nortel) comme
BlackHat USA 2008 - Day 2 Review
today was the second and final day of the blackhat usa briefings. a lot of great content was presented today. much like yesterday we’ve included some highlevel comments on the various presentations that tadd and i attended. we will be attending defcon over the weekend and tying that into one final posting next week. what follows is our summary.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.