tug
Volume 4, Number 35 -- September 27, 2007

Security Attacks and Breaches on the Rise

Published: September 27, 2007

by Timothy Prickett Morgan

Two reports by organizations that track attacks on corporate networks released last week will probably not make network and security administrators sleep any better. But, given all of the malware, worms, and other nasty stuff out there in the electronic world, they probably were going to sleep with one eye open and one hand on the BlackBerry anyway.

The Computing Technology Industry Association (CompTIA) recently commissioned a survey of IT organizations to try to find out how severe the security breaches they are seeing in their systems are. The severity level is on the rise, according to those companies survey. On a scale of 0 to 10, where 10 is the most severe level of breach, the level in 2005 was 2.3 and in 2006 was 2.6. But in the 2007 survey, the level jumped to 4.8, on average. Small, medium, and large enterprises report approximately the same frequency of breaches, and smaller companies tend to have slightly less severe breaches. Still, the point remains that companies all of sizes and IT persuasions are being cracked open by various kinds of malware and human mistakes.

"This suggests that while the number of security breaches has stabilized, the breaches that are occurring are having a greater impact than ever on organizations," said Brian McCarthy, chief operating officer at CompTIA.

Across all companies, the average cost of dealing with a security breach was $369,388, with a number of large companies with breaches that cost more than $10 million a pop bringing up the class average. About half of the respondents to the CompTIA survey said that the security breaches they have experienced in the past year cost $10,000 or less. Averaged across all respondents, lost employee productivity accounted for 35 percent of costs, with server or network downtime representing 21 percent of costs, and lost revenue-generating activity being about 20 percent of the cost associated with a breach. Legal fees and fines represented 8 percent of costs, and 17 percent of the cost was related to dealing with damage to physical devices and other assets. Nearly a quarter of the companies surveyed by CompTIA that had a security breach in the past year were inside jobs. Which just goes to show you that a firewall is not enough security.

The other interesting report to come out relating to hack attacks last week came from IBM's Internet Security Systems, which put out its X-Force malware report for the first half of 2007. Based on an analysis of over 210,000 malware samples from that time, the volume and sophistication of malware attacks is on the rise.

In fact, says IBM, the number of unique malware attacks in the first half of the year now exceeds the number that Big Blue monitored for the whole of 2006. Trojan horse malware--files that look legitimate but which have been compromised by hackers--account for 28 percent of the volume of malware so far this year; last year, downloaders--a small program that gets onto a machine so it can later go get the real malware and download it--were the most popular piece of malware being passed around the Internet.

The good news is that the number of vulnerabilities reported in operating systems, routers, and other gear has dropped a bit. IBM says that it identified 3,273 vulnerabilities in the first half of this year, down 3.3 percent from the same six months in 2006. The IBM X-Force team has catalogued over 33,000 vulnerabilities to date. If you want to get more detail on the X-Force report, follow this link.


RELATED STORIES

MPack Hacker Tool Claims 10,000 Compromised Web Sites

Security Still an Issue in 2007 for System i5 Shops

Security Experts Say Botnets, Web Extortion Threats on the Rise

SQL Injection Attacks Being Used by Hackers for Profit

More Than Half of Tech Companies Report Security Breaches



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
VIBRANT TECHNOLOGIES

HP, IBM and Sun Server Deals via RSS

                                                  · Subscribe to our Specials via RSS
                                                  · Up to 80% off manufacturer's list price
                                                  · Multi-million dollar inventory

We Buy & Sell new and remarketed servers,
upgrades, peripherals and parts.

HP Proliant, IBM xSeries, IBM pSeries, RS6000,
HP Integrity, Sun Microsystems, Cisco, more…
888-443-8606

View or Subscribe to:
Special Offers on Servers and Upgrades


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
Roaring Penguin:  Stop spam at the mail server on YOUR terms with CanIt-PRO
NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40


 

IT Jungle Store Top Book Picks

The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
SAP Plants Its Flag in Mid-Market Territory with SaaS Apps

A1S Is to Applications What AS/400 Was to Systems

EGL: At Least It's Not Java, But It Ain't RPG, Either

As I See It: Shocking

The Linux Beacon
IDF Server Wrap Up: Intel to Keep the Pressure on AMD

Mandriva Readies Linux 2008 Editions for October

SAP Plants Its Flag in Mid-Market Territory with SaaS Apps

Opsware Adds Storage, Process Management with System 7 Tools

Four Hundred Stuff
Boise Cascade Gets 'm-Powered' with mrc Reporting Tool

Red Oak Simulates World's Fastest Human Terminal Operator

Echo Cuts Waste with SPLTOOL Investment

BCD's WebSmart PHP Goes GA

Big Iron
Hosing z/OS.e and Other Withdrawals

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
System i Developers and .NET 2.0: ASP.NET and the Declarative Programming Model

Don't Disable Blocking

Admin Alert: When APPN Prevents You from Changing Network Attributes

System i PTF Guide
September 15, 2007: Volume 9, Number 37

September 8, 2007: Volume 9, Number 36

September 1, 2007: Volume 9, Number 35

August 25, 2007: Volume 9, Number 34

August 18, 2007: Volume 9, Number 33

August 11, 2007: Volume 9, Number 32

The Windows Observer
Microsoft Loses Antitrust Appeal in European Court

In Search Of a More Secure Internet

Sun and Microsoft Go All the Way with Windows

HP Engineers New Blade Server Box for SMB Shops

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Centrify
Vision Solutions
Arkeia
Canvas Systems
Vibrant Technologies


Printer Friendly Version


TABLE OF CONTENTS
Sun Enhances Solaris Developer Edition, Adds Support

Sun Ships Intel-Based Galaxy Rack Servers

IDF Server Wrap Up: Intel to Keep the Pressure on AMD

As I See It: Shocking

But Wait, There's More:

Sun Buys the Assets of Cluster File Systems . . . NEC and Sun Team for HPC Server Deals in North America . . . Security Attacks and Breaches on the Rise . . . Oracle Sales Go Boom in Its First Fiscal Quarter . . . Onstor Survey Confirms Data Centers Running Out of Juice . . . A Little Application Humor, Thanks to Lawson Software . . .

The Unix Guardian

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement