ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Web malware exploded in 2006

ISS X-Force report finds that malware targeting web browsers massively increased last year.

By Rene Millman, 16 May 2007 at 16:34

The amount of malware targeting web browsers exploded in 2006 compared to previous years, a new report said.

The study, carried out by IBM's Internet Security Systems X-Force research team, found that web-targeted attacks and scripting vulnerabilities saw a massive increase with 7,247 vulnerabilities disclosed that year, 88 per cent of these were remotely exploitable by hackers.

The research found that 50 per cent of all websites hosting browser-targeted attacks used various obfuscation and encryption techniques to hide payloads from traditional detection techniques.

"Malicious individuals have stepped up efforts to defeat traditional client-side protection systems to help sustain profitable cyber crime," said the reports authors said. "Divisions between classic threat types are becoming blurred making it increasingly difficult to address cyber threats."

The report also found that malware is increasing in functionality and complexity. Downloaders dominated this area, comprising 22 per cent of total malware tracked. Worms such as Luder and Mytob continued to be a threat, while content-based malware has become one of the top threat risks to users and businesses.

Analysts at X-Force noted a five per cent increase in the number of vulnerabilities identified in April from the previous month. But there has been a seven per cent decrease in the number of vulnerabilities year on year for April.

The authors said that each vulnerability should be analysed along with the threat it posed.

"Paying attention to only a few purchased or internally discovered vulnerabilities could lead to risks in the network environment," said the authors. "Vulnerability discovery, while important, is only one of many activities that should be performed to mitigate risk."

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement