CA outlines online threats for 2008

The company's recent report states that malware has become a true international criminal activity and grew several times in volumes within 2007 alone.

  • E-Mail
By  Administrator Published  February 18, 2008

The company's recent report states that malware has become a true international criminal activity and grew several times in volumes within 2007 alone.

Online gamers, social networks and sensitive corporate data are among the top potential targets for online attacks in 2008, according to the latest Internet Security Outlook Report from CA. The study, based on data compiled by CA's Global Security Advisor researchers, features internet security predictions for 2008 and reports on trends from 2007.

"Cyber-criminals go where opportunity lies and take advantage of any and all vulnerabilities," said Ganesan Lakshmanan, team leader for security management at CA. "While security protection is becoming better at detecting malware, online thieves are getting smarter and stealthier in the way they attack."

"The Middle East's technology sector is growing faster than many other regions, but many enterprises still see security as an after-thought or even a single, grudging deployment," continued Lakshmanan. "There is an acute need for greater security oversight among the region's business community. Enterprises should ensure that their internet service providers and vendors are providing them with constant, up-to-date security risk information."

According to the report, malware volumes grew 16 times between January and October 2007. For the first time, malicious spyware surpassed trojans as the most prevalent form of malware. In 2007, 56% of the total malware seen was malicious spyware, 32% was trojans, 9% was worms, and 2% was viruses.

Lakshmanan stated, "We've seen malware evolve from a cottage industry to a full-fledged fraud business. Shockingly, it is now operating with business practices and development similar to legitimate software organisations. Our attitude about protecting our internet privacy and the subsequent actions we take can dramatically alter our safety."

The most widespread worms in 2007 were simple network and removable drive worms. Some worms cripple computers as they go. Other worms drop additional malware or open the compromised computers to backdoor control by an attacker.

Fake security software made up 6% of the total spyware volume in 2007.

The report also stated that more than 90% of e-mail was spam, and more than 80% of spam contained links to malicious sites or malware. The quality of spam also improved and was no longer obviously riddled with typos. It is also increasingly laden with attachments-images, PDFs, documents, spreadsheets or videos-that have malware or link to malicious sites.

CA’s security predictions for 2008

1. Bots will dominate 2008: The number of computers infected by botnets will increase sharply in 2008. In an effort to become harder to detect, bot-herders are changing their tactics and decentralising via peer-to-peer architectures. They are increasingly using instant messaging as their main vehicle for spreading botnets.

2. Smarter malware: There are new levels of sophistication in malware. Malware will target virtualised computers, and increasing use of obfuscation techniques to hide in plain sight, including steganography and encryptions, will help criminals conceal their activities.

3. Gamers under fire: Gamers already are a prized target, and stealing their account credentials continues to be a primary objective of online criminals.

4. Social networking sites in the crosshairs: Social networking sites will become increasingly popular and, as a result, more vulnerable. The large number of aggregated potential victims and relatively small concern for computer security make these sites a windfall for cyber thieves.

5. Key dates for opportunity: The US presidential election and the 2008 Olympics in Beijing offer high-profile opportunities for destructive attacks and corruption or outright theft of information.

6. Web 2.0 services and sites will come under targeted attacks: While it is relatively easy to implement Web 2.0 services, it can be quite challenging to configure them to be totally secure. Therefore, many internet sites using these services are easy targets with little outward indication that a site is compromised.

7. Windows Vista at risk: Although it is designed as Microsoft's most secure operating system, 20 vulnerabilities were reported in 2007, according to the National Institute of Standards and Technology in the US. As more people use it, more attackers will target it.

8. Mobile devices will still be safe: Mobile devices are still safe, despite rumours of mobile malware. Smartphones and other mobile devices will not be a real opportunity for criminals in 2008. Proof-of-concept malware for mobile devices has not yet translated into any meaningful attacks. The only significant mobile vulnerability reported in 2007 was to the Apple iPhone.

Add a Comment

Your display name This field is mandatory

Your e-mail address This field is mandatory (Your e-mail address won't be published)

Security code