About
Subscribe
  • Home
  • /
  • Networking
  • /
  • Symantec Internet Security Threat Report identifies shift toward focused attacks on clients

Symantec Internet Security Threat Report identifies shift toward focused attacks on clients

Threats increasingly motivated by profit and desire to perpetrate criminal acts
Johannesburg, 21 Sep 2005

Symantec today released its eighth bi-annual Internet Security Threat Report, which provides analysis of network-based attacks, a review of known vulnerabilities and highlights of malicious code, as well as additional security risks, including phishing, adware and spyware. The current volume covers the six-month period from 1 January to 30 June 2005.

"This latest edition of the Internet Security Threat Report identifies a change in the threat landscape, as attackers move away from large, multipurpose attacks on network perimeters, toward smaller, more targeted attacks on host systems targets," said Patrick Evans, regional director, Symantec sub-Saharan Africa.

"To protect against these attacks, users should employ defence-in-depth practices, which emphasise multiple, overlapping and mutually supportive defensive systems, to guard against single-point failures in any specific technology or protection methodology. This should include the deployment of anti-virus, firewalls, and intrusion detection and prevention systems on client systems."

"This is particularly important in the South African environment, where we are now seeing an increased uptake and interest in Internet connectivity and broadband technologies in both the consumer and business markets," Evans adds.

Key findings of the report:

Increase in malicious code for profit: During the first six months of 2005, new methods of using malicious code for financial gain were observed with increasing frequency. For example, 64% of the top 50 malicious code samples reported to Symantec allowed spam relaying. Symantec also detected Trojans that download and install adware that displays pop-up ads in a user's Web browser. Additionally, bot networks and custom bot code were available for purchase or rent. Symantec observed a daily average of 10 352 computers that were active in a bot network, an increase of more than 140% from the previous reporting period's 4 348 bot computers. This is a serious security concern because as financial rewards increase, attackers will likely develop more sophisticated and stealthier malicious code that will attempt to disable anti-virus software, firewalls and other security measures.

Rise in confidential information exposure: Threats to confidential information can result in significant financial losses, particularly if credit card information or banking details are exposed. Moreover, this is concerning as online shopping and Internet banking continue to increase in popularity. During the first half of 2005, malicious code that exposed confidential information represented 74% of the top 50 malicious code samples reported to Symantec, up from 54% in the previous six months.

Increase in malicious code variants: Over the first half of 2005, Symantec documented more than 10 866 new Win32 viruses and worms variants - an increase of 48% over the 7 360 documented in the second half of 2004. It is also an increase of 142% over the 4 496 documented in the first half of 2004. This massive increase is important as each variant represents a new, distinct threat against which administrators must protect their systems and for which anti-virus vendors must create new definitions. The trend also signifies a shift away from broadly disseminated threats such as mass-mailing worms, towards malicious code that is modular and customisable.

Increase in phishing threats: Between 1 January and 30 June 2005, the volume of phishing messages grew from an average of 2.99 million messages per day to 5.70 million. Additionally, one out of every 125 e-mail messages scanned by Symantec Brightmail AntiSpam was a phishing attempt - an increase of 100% when compared to the last half of 2004. Furthermore, Symantec Brightmail AntiSpam antifraud filters were blocking more than 40 million phishing attempts per week on average, up from approximately 21 million per week at the beginning of January.

Increase in vulnerability disclosure: During the first half of 2005, Symantec documented 1 862 new vulnerabilities - the highest number ever recorded in the Internet Security Threat Report. Ninety-seven percent of these vulnerabilities were classified as moderate or high and 59% of all vulnerabilities were found in Web application technologies, marking an increase of 59% over the previous reporting period and a 109% increase over the first six months of 2004. Web application vulnerabilities are particularly dangerous because they can allow an attacker to access confidential information without having to compromise any servers.

Future and emerging trends

* The prevalence of modular malicious code (that is, malicious code that downloads additional functionality) is expected to increase.
* Bot networks are expected to increase in number, diversity and sophistication.
* Phishing targets are likely to expand as phishers employ increasingly sophisticated methods to avoid detection.
* Adware and spyware are expected to appear with increasing frequency on mobile devices and to employ stealthier technology to avoid detection.
* An increase in the number of attacks and threats directed at wireless networks is likely.
* Voice over Internet Protocol (VOIP) threats are expected to emerge as more enterprises converge data and voice networks.

Share

The Symantec Internet Security Threat Report

Symantec has established one of the most comprehensive sources of Internet threat data in the world. The following resources give Symantec analysts an unparalleled pool of data with which to identify and analyse emerging trends in Internet security activity:

* DeepSight Threat Management System and Managed Security Services - More than 24 000 sensors monitoring network activities in over 180 countries.
* Symantec's anti-virus solutions - More than 120 million client, server and gateway systems that have deployed Symantec's anti-virus products provide reports on malicious code as well as spyware and adware.
* Vulnerability database - Covering more than 13 000 vulnerabilities affecting more than 30 000 technologies from more than 4 000 vendors, Symantec maintains one of the world's most comprehensive databases of security vulnerabilities.
* BugTraq - Symantec operates BugTraq, one of the most popular forums for the disclosure and discussion of vulnerabilities on the Internet with over 50 000 subscribers.
* Symantec Probe Network - A system of more than 2 million decoy accounts, attracting e-mail messages from 20 different countries around the world, allowing Symantec to gauge global spam and phishing activity.

Symantec

Symantec is the world leader in providing solutions to help individuals and enterprises assure the security, availability and integrity of their information. Headquartered in Cupertino, California, Symantec has operations in more than 40 countries. More information is available at www.symantec.com.

If you would like additional information on Symantec Corporation and its products, please view the Symantec Press Centre at http://www.symantec.com/PressCenter/ on Symantec's Web site. All prices noted are in US dollars and are valid only in the United States.

Editorial contacts

Kim Lai Shong
Orange Ink
(011) 463 6910
kim@orangeink.co.za
Aimee Peters
Symantec
aimee_peters@symantec.com