Advertisement
Promo

Security threats Toolkit

Security lessons not learned will haunt us in 2009

Mary Landesman, ScanSafe

Published: 12 Jan 2009 13:48 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment
Security lessons not learned will haunt us in 2009

2008 will probably be remembered for a very long time for all the wrong reasons — and amid the grim litany of the year's events are ominous developments in malware, which we ignore at our peril, says internet security expert Mary Landesman.

In terms of malware, 2008 was a very bad year. But 2009 will be far worse. The most depressing thing is so many IT people still haven't grasped the significance of certain malware developments that occurred in 2008. That failing will mean they will be ill-prepared for the challenges 2009 will surely bring.

Let's look back. The power of distributed computing has brought malware to the masses via botnets. While systems administrators cling to desktop-security solutions, the attackers have clearly moved to the cloud.

Botnets such as Asprox incorporated the operational ease of exploit frameworks such as Neosploit with backdoors and downloaders such as Zbot. The end result: millions of compromised web pages delivering Trojans that silently syphon sensitive data from infected systems.

Less is more
Where technology fails, users pick up the slack. Social engineering escalated to new levels in 2008, proving once and for all that less really is more. To bypass spam filters, the messages contain little more than a few terse words and a link.

Some of the messages appeal to the recipient's vanity: "You look awesome in this video". Others exploit people's fear and curiosity: "Pope killed by assassin in Vatican City". In some cases, the links point to a malicious website rigged with exploits designed to install malware automatically. In most cases, however, the attackers can afford to be lazy and let the victims infect their own computers by simply pretending the malware is a video codex or Flash update.

Sneaker net-spread infections made a comeback this past year, thanks to autorun worms that target removable and mapped drives, dropping an autorun.inf to the root, which loads the worm executable each time the drive is accessed.

The continuing popularity of USB thumb drives provides an open door for the malware. Once these worms have taken root, mitigating the threat can be costly. And auto-run worms seldom work alone. Underlining the theme that malware is no longer about pranks, today's auto-run worms double as Trojan downloaders, installing an explosive cocktail of backdoors and data-theft Trojans.

The troops have been overwhelmed. In 2008, traditional antivirus detected 80 percent of new threats. Put another way, traditional antivirus on average missed 20 percent of new malware released during the year.

Signature-based methods rely on four critical components: discovery, analysis, pattern creation and updates. Attackers have overwhelmed the system by releasing...

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
45 out of 45 people found this useful


Full Talkback thread

0 comments

Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters