tfh
Volume 16, Number 37 -- September 24, 2007

Security Attacks and Breaches on the Rise

Published: September 24, 2007

by Timothy Prickett Morgan

Two reports by organizations that track attacks on corporate networks released last week will probably not make network and security administrators sleep any better. But, given all of the malware, worms, and other nasty stuff out there in the electronic world, they probably were going to sleep with one eye open and one hand on the BlackBerry anyway.

The Computing Technology Industry Association (CompTIA) recently commissioned a survey of IT organizations to try to find out how severe the security breaches they are seeing in their systems are. The severity level is on the rise, according to those companies survey. On a scale of 0 to 10, where 10 is the most severe level of breach, the level in 2005 was 2.3 and in 2006 was 2.6. But in the 2007 survey, the level jumped to 4.8, on average. Small, medium, and large enterprises report approximately the same frequency of breaches, and smaller companies tend to have slightly less severe breaches. Still, the point remains that companies all of sizes and IT persuasions are being cracked open by various kinds of malware and human mistakes.

"This suggests that while the number of security breaches has stabilized, the breaches that are occurring are having a greater impact than ever on organizations," said Brian McCarthy, chief operating officer at CompTIA.

Across all companies, the average cost of dealing with a security breach was $369,388, with a number of large companies with breaches that cost more than $10 million a pop bringing up the class average. About half of the respondents to the CompTIA survey said that the security breaches they have experienced in the past year cost $10,000 or less. Averaged across all respondents, lost employee productivity accounted for 35 percent of costs, with server or network downtime representing 21 percent of costs, and lost revenue-generating activity being about 20 percent of the cost associated with a breach. Legal fees and fines represented 8 percent of costs, and 17 percent of the cost was related to dealing with damage to physical devices and other assets. Nearly a quarter of the companies surveyed by CompTIA that had a security breach in the past year were inside jobs. Which just goes to show you that a firewall is not enough security.

The other interesting report to come out relating to hack attacks last week came from IBM's Internet Security Systems, which put out its X-Force malware report for the first half of 2007. Based on an analysis of over 210,000 malware samples from that time, the volume and sophistication of malware attacks is on the rise.

In fact, says IBM, the number of unique malware attacks in the first half of the year now exceeds the number that Big Blue monitored for the whole of 2006. Trojan horse malware--files that look legitimate but which have been compromised by hackers--account for 28 percent of the volume of malware so far this year; last year, downloaders--a small program that gets onto a machine so it can later go get the real malware and download it--were the most popular piece of malware being passed around the Internet.

The good news is that the number of vulnerabilities reported in operating systems, routers, and other gear has dropped a bit. IBM says that it identified 3,273 vulnerabilities in the first half of this year, down 3.3 percent from the same six months in 2006. The IBM X-Force team has catalogued over 33,000 vulnerabilities to date. If you want to get more detail on the X-Force report, follow this link.


RELATED STORIES

MPack Hacker Tool Claims 10,000 Compromised Web Sites

Security Still an Issue in 2007 for System i5 Shops

Security Experts Say Botnets, Web Extortion Threats on the Rise

SQL Injection Attacks Being Used by Hackers for Profit

More Than Half of Tech Companies Report Security Breaches



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
RJS SOFTWARE SYSTEMS

Make Your Office Paperless

With WebDocs you can electronically store, manage and distribute paper documents,
spool files, PC data, emails, faxes and more. Think of WebDocs as an electronic filing cabinet
that allows you to securely access and share information from anywhere at anytime.

Visit us at www.rjssoftware.com or call us at
1-888-RJS-SOFT for a free 30-day demo.


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

HiT Software:  DBMoto performs real-time as well as snapshot data replication
COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

 

 

IT Jungle Store Top Book Picks

The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Linux Beacon
Canonical, VMware Create Skinny Linux for Virtual Appliances

HP Engineers New Blade Server Box for SMB Shops

SCO Files for Bankruptcy Protection

Transitive Rejiggers Emulation Software, Adds Partners

Four Hundred Stuff
Windows Vista Poses Challenges to Emulation Vendors

NetCustomer Capitalizes on Dissatisfaction with Oracle

Infor Provides Details on SOA Roadmap

Microsoft Ships BizTalk Server R2

Big Iron
Leverage

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
System i Developers and .NET 2.0: ASP.NET and the Declarative Programming Model

Don't Disable Blocking

Admin Alert: When APPN Prevents You from Changing Network Attributes

System i PTF Guide
September 15, 2007: Volume 9, Number 37

September 8, 2007: Volume 9, Number 36

September 1, 2007: Volume 9, Number 35

August 25, 2007: Volume 9, Number 34

August 18, 2007: Volume 9, Number 33

August 11, 2007: Volume 9, Number 32

The Windows Observer
Microsoft Loses Antitrust Appeal in European Court

In Search Of a More Secure Internet

Sun and Microsoft Go All the Way with Windows

HP Engineers New Blade Server Box for SMB Shops

The Unix Guardian
SCO Files for Bankruptcy Protection

Sun and Microsoft Go All the Way with Windows

SAP Plants Its Flag in Mid-Market Territory with SaaS Apps

As I See It: The Dons of Dialogue

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

BCD
Tango/04
COMMON
Krengeltech
RJS Software Systems


Printer Friendly Version


TABLE OF CONTENTS
SAP Plants Its Flag in Mid-Market Territory with SaaS Apps

A1S Is to Applications What AS/400 Was to Systems

EGL: At Least It's Not Java, But It Ain't RPG, Either

As I See It: Shocking

But Wait, There's More:

IBM Is Looking for Some Help on the V6R1 Rollout . . . IBM Cuts User Prices on User-Based CBU Editions . . . Security Attacks and Breaches on the Rise . . . Oracle Sales Go Boom in Its First Fiscal Quarter . . . Onstor Survey Confirms Data Centers Running Out of Juice and Space . . . A Little Application Humor, Thanks to Lawson Software . . .

The Four Hundred

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement