tug
Volume 4, Number 5 -- February 8, 2007

IBM X-Force Says For-Profit Cyber Attacks to Increase in 2007

Published: February 8, 2007

by Alex Woodie

2006 was a record year for security vulnerabilities, with an average of 20 new flaws discovered every day. But brace yourself for 2007, as cyber criminals grow more sophisticated, requiring more vigilance by companies, according to a recent report issued by IBM's Internet Security Systems (ISS) X-Force research and development team.

There is a caveat to the vulnerability figures listed in the paragraph above. While the number of newly discovered vulnerabilities jumped 40 percent in 2006 compared to 2005-that's 7,247 vulnerabilities compared to 5,176--the rate of "high impact" vulnerabilities decreased somewhat, from accounting for 28 percent of all vulnerabilities in 2005 to 18 percent in 2006. Numerically, the decrease in the most severe vulnerabilities drops from about 1,450 in 2005 to about 1,300 in 2006.

That's where the good news ends. Gunter Ollmann, director of security strategy for IIS, says companies need to stay on high alert. "The security industry has made great progress over the last year, but despite promising statistics [such as the decrease in high-impact vulnerabilities], we predict that 2007 will require even higher levels of vigilance and innovation to deal with emerging threats and new vectors of attack."

Of particular note are the camouflaging techniques cyber criminals are using to hide what they're doing. X-Force reports that about half of the Web sites set up to infect visitors or steal personal information are attempting to obfuscate or camouflage their attack, and about 30 percent are encrypting their payload.

And while the IT industry scrambled to meet the burgeoning demand for "software as a service," the cyber criminal underground has been doing the same, with the rise of the "exploits as a service" industry. According to X-Force, the malware industry is ripe for an explosion of "managed exploit providers" who sell exploit code that's encrypted so it can't be picked up by the authorities and white hats. The growing sophistication of a sales channel trafficking in exploits will help to render traditional signature-based protection even less effective in the future, X-Force predicts.

It was another banner year for spammers, too. While it seemed like spam levels couldn't go much higher, the amount of spam trafficking the Internet managed to increase by a whopping 100 percent last year, according to X-Force. (Although, it must be said, that due to the fact that the vast majority of e-mail already was spam in 2005, the doubling didn't do much to increase the rate of spam, so maybe you didn't notice your spam repository--err, your inbox--overflowing just a little more.) Image-based spam, which is tough to detect using traditional methods, is largely to blame for this bump up.

The X-Force team, picked up by IBM last year in its ISS acquisition, had some other interesting tidbits to share in its report on 2006.

Among the factoids:

  • The biggest sources of spam are the U.S., Spain, and France.
  • The biggest source of phishing e-mails is South Korea.
  • After English, German is the most popular language in which spam messages are written.
  • The most commonly used exploit to infect Web browsers with malware was the MS-ITS vulnerability, which Microsoft fixed in 2004.

The 34-page X-Force report can be downloaded in PDF format here.



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
MKS

You're at Bat, and It's Time for a "Change Up".
Change Up to MKS Implementer and MKS Integrity
for Application Lifecycle Management - Move to MKS NOW and SAVE!

Has the recent acquisition of your change management provider thrown you a curve ball?
Is your vendor offering you loosely coupled tools, leaving you with information gaps and a technical headache? Can your current change management solution meet your needs
today - and tomorrow?

This isn't slow pitch.

The world of software development is moving at a rapid pace and you need to be ready to meet new demands. Change management is a vital component of your business -- the foundation for compliance, for modernization, for process control and risk management. You need a vendor that can keep up with these business demands.

A winning team, less risk, more advantages.

Join a team that is reliable, steadfast and dedicated to delivering tangible business results to System i5 customers as well as cross-platform teams. MKS is firmly dedicated to the change management market and has a clear product roadmap. MKS's Implementer for software change management and deployment has a reputation of technical excellence with large and small customers across every industry.

Make the change up - move to MKS NOW and SAVE!

For a limited time MKS will help you make the move with special pricing when you purchase Implementer with MKS Integrity - giving you integrated workflow, complete audit trails and
coverage of the application lifecycle as well as a platform to manage both System i5 and
cross-platform development.

Visit the Products section of the MKS website for more information on
Implementer and MKS Integrity.

Click here to request more information on our time limited "change up" offer.

Download the white paper:
"Managing iSeries Development in the Application Modernization Era."

The time is now to make the switch.

Call MKS today at 1-800-613-7535 to discuss your options, and while you're at it, request a
FREE change management process assessment by our team of experts with over 40 years of experience in the midrange market.

Contact MKS Sales at 1-800-613-7535 or sales@mks.com
For more information, visit www.mks.com/solutions


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

World Data Products:  FREE 84-page Unix/Midrange Server Spec Book
FreeBSD:  Advanced OS for X86 and X64, Alpha/AXP, IA-64, PC-98, and Sparc architectures
COMMON:  Join us at the Annual 2007 Conference & Expo, April 29 - May 3, in Anaheim, California


The Four Hundred
IBM Upgrades System i5 Disk Controllers, Adds Enclosures

IBM and ISVs Launch VIP Program to Reinvigorate System i5 Sales

Sundry Other System i5 Announcements

The X Factor: One Socket to Rule Them All

The Linux Beacon
PA Semi Samples Homegrown Dual-Core Power Chip

Intel, AMD Push and Pull for X64 Market Share

VMware, XenSource Launch Virtualization Bundles

The X Factor: One Socket to Rule Them All

Four Hundred Stuff
RevSoft Pushes 'Lights On' Approach to Systems Automation

Oracle Cools on Fusion, Focuses on Current ERP

LogLogic Aims to Ease Log Data Crunch

Halcyon Updates Systems Management Tools

Big Iron
Platform Solutions v IBM: Estoppel, Old Show Key

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Opportunities, Not Problems!

SQL Cross Platform Interoperability: The Proper Function

Admin Alert: Selectively Sending Break Messages to Active Users

System i PTF Guide
February 3, 2007: Volume 9, Number 5

January 27, 2007: Volume 9, Number 4

January 20, 2007: Volume 9, Number 3

January 13, 2007: Volume 9, Number 2

January 6, 2007: Volume 9, Number 1

December 30, 2006: Volume 8, Number 50

The Windows Observer
Microsoft Hits Snags in Anti-Piracy Net

AMD Delivers Faster and Cooler Rev F Opteron Chips

Microsoft Hypes the NAP, Unveils New Security Appliance

VMware, XenSource Launch Virtualization Bundles

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Canvas Systems
Lakeview Technology
Roaring Penguin
Sweeter Than Me
MKS



TABLE OF CONTENTS
HP Puts Solaris on More X64 Servers, Partners for Solaris Emulation

Sun Details Server Chip Roadmaps at Analyst Summit

AMD Delivers Faster and Cooler Rev F Opteron Chips

The X Factor: One Socket to Rule Them All

But Wait, There's More:


Power6 Comes in 2007, No Slip into 2008 for the System p . . . Will 45 Nanometer Chips Make Two Warring Camps? . . . HP Buys Bristol for Middleware, Gets Wind/U Emulator . . . IBM X-Force Says For-Profit Cyber Attacks to Increase in 2007 . . . Silly Rumor Says Oracle Wants to Buy SAP . . . Oracle Cools on Fusion, Focuses on Current ERP . . .

The Unix Guardian

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement