Skip to navigation
   
Davey Winder's Blog

The browser mafia

By Davey Winder in Editorial

Posted in Blog, Security, IBM on February 16, 2008 at 11:18 pm

Permalink | Author Profile

According to IBM, or rather the straight out of a gangster movie sounding IBM X-Force to be precise, your web browser is under siege from organised crime gangs. The 2007 X-Force Security report details something of an expected rise in the sophistication of attacks, and an increase in the rate at which victims computers are being compromised. There is, X-Force says, a ‘complex and sophisticated criminal economy’ which has developed to capitalise on known web vulnerabilities, and underground brokers are now delivering the necessary tools to enable those who would screw you over to do just that and avoid detection by way of obfuscation or camouflage.

The report says that in 2006 only a small percentage of attackers employed camouflaging techniques. Compare and contrast with the first half of 2007 when some 80 percent of attacks did just that, and the 100% that were doing it by the end of the year. Using such by now commonplace techniques, the criminal element can all too easily infiltrate a system and compromise the data upon it. Don’t laugh this off as being just a problem for the home user either, X-Force quite rightly reminds us that when attackers invade an enterprise machine they can steal sensitive company information or use that compromised machine to gain access to other corporate assets behind the firewall.

“Never before have such aggressive measures been sustained by Internet attackers towards infection, propagation and security evasion. While computer security professionals can claim some victories, attackers are adapting their approaches and continuing to have an impact on users’ experiences,” said Kris Lamb, operations manager, X-Force Research and Development for IBM Internet Security Systems. “The Storm Worm provides a microcosm of the kinds of threats users faced in 2007. All in all, the exploits used to spread Storm Worm are a blend of the various threats tracked by X-Force, including spam, phishing and drive-by-downloads by way of Web browser exploitation.”

The X-Force report also reveals that:

  • The number of critical computer security vulnerabilities disclosed increased by 28 percent, a substantial upswing from years past.
  • The overall number of vulnerabilities reported for the year went down for the first time in 10 years.
  • Out of all the vulnerabilities disclosed last year, only 50 percent can be corrected through vendor patches.
  • Nearly 90 percent of 2007 disclosed vulnerabilities are remotely exploitable.
12345
Rated: 100% (1 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by traffictrial - February 18, 2008 on 10:11 am

good article. ….
nice info ..
thanks

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

Olympics scareware MiniBook service Hack documentation security economics surveys web standards Zango exploit biometrics OS Texas Instruments Mars millions hacker ISPA hardware BOFH privacy open source Obama Vista phishing holidays migration web 2.0 Firefox Business Adobe Windows 7 Research Trojan Ballmer Eee PC fraud library payment server InfoSec statistics Health banking Blogging The Federation Kill Switch second life black hat printing Silverlight survey Performance computing China Web Development tech Microsoft Apple Russia Finjan Space email xmas USA Noro OCR data protection AMD sick remote workplace ecommerce Gartner Death terrorism theft Bill Gates search news Twitter MessageLabs carbon copy betting mobile ASUS VM computing computer Big Brother malware broadband credit card fraud Energy VPN storage Yahoo remote working worm hubdub transactional security Mobile Phone compromise development hacking museum SMS spam chips christmas productivity technology green NASA Linux MSN money network trust Paris Hilton e-commerce FBI iPhone 3G size Deal Rumour home worker payments Project HPC copyright students Software Supercomputer universe fool shopping environment report IDC science Lotus global DNS Jesus Phone IP archiving Microchip ID Theft books Battery staffing teleworking prison Internet politics Government BSI IBM stupid Application digitise dumb linkedin Google data graphics Texting stupidity virtual world Facebook symantec Flash outsourcing world of warcraft policy code avatar virus Funny fun XP adware debian gaming Rant hypervisor CAPTCHA man-in-the-middle scam SSL rootkits work help office virtual machine NBC Top 500 scan iPhone botnet Eee MSNBC patch management crime Windows Steve Jobs social networking Digg Programming Video banks
Advertisement
Advertisement
Advertisement