two
Volume 4, Number 3 -- January 24, 2007

Security Experts Say Botnets, Web Extortion Threats on the Rise

Published: January 24, 2007

by Timothy Prickett Morgan

Some days, the Internet doesn't feel like a very safe place. Two reports issued recently are predicting some pretty ugly weather conditions out there in cyberspace looking ahead into third year.

A report by Trend Micro, which provides security software for servers and PCs, indicated that 2006 saw a "resurgence in malware" and that the "botnet became the hacker's best friend." For 2007, Trend Micro is predicting that hackers will continue to ramp up their efforts on these fronts while targeting popular social networking sites.

What did not happen in 2006, by the way, was widespread virus outbreaks, which we have seen in prior years. Now, hackers are doing more targeted or regional attacks. This is both comforting and alarming at the same time--comforting because you don't have to cope with a virus outbreak, but alarming if you happen to be the target of the attack. In many cases, these targeted attacks use various pieces of malware and distributed denial of service (DDOS) approaches to try to bring down the systems at a specific company or user group, according to Trend Micro.

Organized crime is using identity theft and the threat of attacks to conduct corporate espionage, and extortion, and hackers have adopted botnets--remote robots created by viruses and other malware that sit unsuspected on Internet-connected PCs that can do a DDOS--to do havoc.

The company said that digital threats have increased by an average of 163 percent per year over the past several years. Web-based threats grew 15 percent from 2005, with nearly a half million reports into TrendLabs, the analysis and tracking side of Trend Micro. More than 2 million unique pieces of spam per month and 140,000 unique bots per month flood the Internet.

"Computer crime has evolved into organized crime, it is no longer the game of individual attackers," said Jamz Yaneza, the senior threat research analyst at Trend Micro who put together the 2007 threat report. "With money as their main driver, our research has tracked how attacks have moved from being fast and large scale to being cleverly crafted to attack very specific groups under the radar. The unseen Web threat is maturing, and users should be ever-more careful about what they download and install, as blended threats are ever-more cunning in their attempt to steal corporate and personal data or money."

Risk Bloggers, a federation of blogs put together by computer and network security experts, released a similar warning report last week, called Ready or Not, Here Comes 2007. "What do you call billions of spam messages, millions of lost customer records, thousands of new viruses, and hundreds of governments asleep at the wheel?" asked the report's author, Jim Reavis rhetorically. "In our business, we call it 2006, just a normal year in the information security industry."

Reavis offers a pretty sobering outlook for security in 2007. "Increasingly, sophisticated criminal organizations are able to exploit technology to stay ahead of corporate and consumer defenses and steal billions of dollars and disrupt whole economies. Botnets, Web application holes and uncontrolled mobility loom large as villains in this tale. Skepticism about the government's ability to be relevant in face of these challenges abounds." Reavis is president of Reavis Consulting, which as the name suggests does consulting on security issues and which hosts the RiskBlogger site.



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
WOLF COMPUTER CONSULTING

Reliable service and affordable rates for all
of your business computing needs.

                                             * Network Design/Installation/Support
                                             * Network Printing/Digital Print Migration
                                             * Upgrades and Troubleshooting
                                             * Training
                                             * Graphic Design
                                             * Virus Removal
                                             * Consulting

Wolf is a Microsoft Certified Systems Engineer and
Microsoft Certified Systems Administrator.

Contact Wolf
Email: info@wolfconsult.net
Fax: 973-293-0100
Phone: 914-443-5534


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Micro Focus:  Develop, extend and deploy applications with Server Express and Enterprise Server
OpenLogic:  Install, integrate, test, manage, and learn over 120 open source projects with BlueGlue
COMMON:  Join us at the 2007 conference, April 29 - May 3, in Anaheim, California

 

The Four Hundred
Big Blue Readies Revamped Storage for the System i

IBM Closes Out 2006 With a Strong Fourth Quarter

Zend Describes Multiple Instances on i5/OS, Previews RPG Wrapper

Ask TPM: The Economics of Open Source Software

The Linux Beacon
OSDL and Free Standards Group Merge into the Linux Foundation

Sun, Intel Form Alliance for Xeon Servers and Workstations

IDC Says Global IT Spending Will Kiss $1.5 Trillion By 2010

The X Factor: Solaris Versus Linux Support Pricing

Four Hundred Stuff
IBM Lotus Adds Handles to Information Overload

Applied Logic Launches OS/400 Encryption Utility

BOSaNOVA Launches Four Thin Clients

GT Software Gives Web Service Smarts to Web-Enabled Apps

Big Iron
IBM Closes Out 2006 With a Strong Fourth Quarter

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Using APIs to Send Impromptu Messages, Take Two

Gotcha Lurking in Datalink File Manager for DB2/400

Admin Alert: Ending Subsystems Properly

System i PTF Guide
January 13, 2007: Volume 9, Number 2

January 6, 2007: Volume 9, Number 1

December 30, 2006: Volume 8, Number 50

December 23, 2006: Volume 8, Number 49

December 16, 2006: Volume 8, Number 48

December 9, 2006: Volume 8, Number 47

The Unix Guardian
Sun Tapes Out Rock Sparc Chip, Gooses Clocks on Niagara Sparc T1

Sun Finally Gets Solaris 10 11/06 Update Out the Door

Unisys Broadens Oasis Open Source Software Stacks for Linux

Why the Number of Women in IT Is Decreasing

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Vision Solutions
World Data Products
MKS
Lakeview Technology
Wolf Computer Consulting



TABLE OF CONTENTS
Microsoft Keeps the Pressure on IBM's Notes, Domino

IBM Lotus Adds Handles to Information Overload

Symantec Expands Performance Management Software

Salesforce.com Reports AppExchange Milestone

But Wait, There's More:


Windows Vista Launches Next Week . . . Iowa Lawsuit Brings Claims of New Evidence . . . Microsoft to Build $550-Million Data Center in San Antonio . . . Security Experts Say Botnets, Web Extortion Threats on the Rise . . . Aldon Joins Microsoft's Midrange Alliance Program . . . IBM Closes Out 2006 With a Strong Fourth Quarter . . .

The Windows Observer

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement