Web malware exploded in 2006
By Rene Millman,
The amount of malware targeting web browsers exploded in 2006 compared to previous years, a new report said.
The study, carried out by IBM's Internet Security Systems X-Force research team, found that web-targeted attacks and scripting vulnerabilities saw a massive increase with 7,247 vulnerabilities disclosed that year, 88 per cent of these were remotely exploitable by hackers.
The research found that 50 per cent of all websites hosting browser-targeted attacks used various obfuscation and encryption techniques to hide payloads from traditional detection techniques.
"Malicious individuals have stepped up efforts to defeat traditional client-side protection systems to help sustain profitable cyber crime," said the reports authors said. "Divisions between classic threat types are becoming blurred making it increasingly difficult to address cyber threats."
The report also found that malware is increasing in functionality and complexity. Downloaders dominated this area, comprising 22 per cent of total malware tracked. Worms such as Luder and Mytob continued to be a threat, while content-based malware has become one of the top threat risks to users and businesses.
Analysts at X-Force noted a five per cent increase in the number of vulnerabilities identified in April from the previous month. But there has been a seven per cent decrease in the number of vulnerabilities year on year for April.
The authors said that each vulnerability should be analysed along with the threat it posed.
"Paying attention to only a few purchased or internally discovered vulnerabilities could lead to risks in the network environment," said the authors. "Vulnerability discovery, while important, is only one of many activities that should be performed to mitigate risk."
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Who to trust after the VeriSign hack?
Davey Winder questions what data was stolen from VeriSign and wonders why the company hasn't been more forthcoming.
- Striving to solve the security skills crisis
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
- Are the cookie laws crumbling already?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Google releases Chrome for Android beta
- Will someone rid me of these troublesome Macs?
- OneNote hits Google?s Android
- BlackBerry Bold 9790 review
- Google sends in Bouncer to sort out malicious apps
- Ubuntu vs. Windows 7 on the business desktop
- Who to trust after the VeriSign hack?
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
- ACTA: the basics, the controversies, and the future
- BT considering Ofcom price cap appeal
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





