Social engineering - in other words, user behaviour - and unpatched vulnerabilities accounted for 99% of all malware attacks during the first half of 2011, according to the 11th version of Microsoft's authoritative Security Intelligence Report (SIRv11).
By contrast, less than 1% of exploits in the first half of 2011 were against zero-day vulnerabilities, which are software vulnerabilities that are successfully exploited before the vendor has published a security update or “patch”.
What this means, says Microsoft South Africa's chief security advisor, Dr Khomotso Kganyago, is that most common computer threats can be mitigated through good security best practices.
“Fully 90% of infections that were attributed to vulnerability exploitation had a security update available from the software vendor for more than a year,” said Dr Kganyago.
User interaction, typically employing social engineering techniques, caused nearly half (45%) of all malware propagation in the first half of 2011. In addition, more than a third of all malware is spread through cyber criminal abuse of Win32/Autorun, a feature that automatically starts programs when external media, such as a CD or USB, are inserted into a computer.
The report includes guidance to help educate people about commonly known social-engineering techniques, how to create strong passwords and how to manage security updates. In addition, Microsoft provides insight into reducing Win32/Autorun abuse with updates released earlier this year for Windows XP and Windows Vista (Windows 7 already included these updates) that prevent the Win/32Autorun feature from being enabled automatically for most media.
“Within four months of issuing the update, the number of infections from the most prolific Win32/Autorun-abusing malware families was reduced by almost 60% on Windows XP and by 74% on Windows Vista in comparison to 2010 infection rates,” says Dr Kganyago.
To protect networks and systems, he suggests that users adopt a multifaceted approach to managing risk, including building products and services with security in mind; educating customers and employees; upgrading to the latest products and services; and considering cloud services.
Organisations can choose to leverage the cloud to help ensure the services they use have the most up-to-date security protections. Cloud providers, such as Microsoft, are resourced to focus on security, and in transitioning the management of a portion of security functions, resources are freed up to focus on other areas of security or on different IT projects altogether.
More information about SIRv11 is available at http://www.microsoft.com/sir.
Editorial contacts

