Are you ready for these Internet security threats?

Opinion
Apr 30, 20104 mins

Symantec just released its latest annual Internet security threat report and it shows that hackers and attackers are more prolific than ever. Learn about the areas where your enterprise is most vulnerable, as well as what new threats emerged in 2009.

Symantec has just published its annual in-depth threat report and recommendations on how to improve enterprise security. Symantec Global Internet Security Threat Report: Trends for 2009 is now available online, along with a Webinar that summarizes the key points from the report.

Symantec gathered the data for this report from an extensive Global Intelligence Network that includes more than 240,000 attack sensors in over 200 countries; 133 million virus submission systems; a vulnerability database with 35,000 vulnerabilities from 11,000 vendors in 80,000 technologies; and 5 million decoy accounts looking for spam and phishing in more than 1 billion e-mails per day and over 1 billion Web requests per day. By drawing from all these sources, Symantec can present an in-depth view of what threats exist on the Internet today, and what the trends are over a span of years.

10 of the worst moments in network security history

There are some key trends in the threat landscape for 2009, some of which simply build on what was found in 2008. For example:

* There continue to be many targeted attacks on enterprise organizations. The attackers appear to do research on their prey companies to learn who the key people are and what kind of information an attack could yield; for example, intellectual property and corporate strategy. Spear-phishing and zero-day vulnerabilities are common methods to reach these people. Symantec notes that much of the information that is useful to attackers is publicly available in annual reports, on company Web sites, and, increasingly, on social networks.

* Web-based attacks are still common, and they are the primary means to install malicious code on computers. The top Web-based attacks in 2009 targeted Internet Explorer and PDF readers. Users tend to trust PDF files because they don’t think of them as executing anything; however, embedded code in the PDF can carry malware. Attackers also target vulnerabilities in popular client-side applications such as Adobe Reader, Flash Player, Java SE Runtime Environment and RealPlayer.

* Novice hackers are able to get into “the business” easily and with little skill by purchasing attack kits available over the Internet. These kits lower the bar to entry into the shadowy world of Internet attacks. One reason the Zeus Trojan horse attack spread so far and wide was that there was an attack kit for sale that enabled the development of at least 90,000 unique binary files. Because of all the variants, companies need to use additional security measures on top of signature-based detection methods, according to Symantec.

*The underground economy was not affected by the downturn in the real economy. Unfortunately, business is booming in the underground. If anything, changes occurred as social engineering tactics shifted toward taking advantage of people facing economic hardships. Phishing and spam attacks involved advertisements and Web sites pertaining to refinancing loans, reducing credit card debt, credit counseling and the like.

Other points worth noting include:

* Symantec’s network detected more than 240 million distinct new malicious programs. One reason for such a high number is the emergence of “singletons” — atack code that shows up in only one computer. This trend further proves the need to complement signature-based security with reputation-based security and behavioral monitoring.

* Executable file sharing has become the primary means of transmission of infections, especially for viruses and worms. Other significant vectors are file transfer (both via CIFS and e-mail attachment) and remotely exploitable vulnerabilities. Symantec cautions against focusing too much on any one particular threat vector, however, since vectors can change rapidly. Instead, take into account all the in-roads to the network when planning your enterprise security strategy.

* Botnets are responsible for distributing 85% of spam. What’s more, bot herders are getting smarter; they are building “high availability” into their botnets, such as a secondary command and control server in the event that the primary server is shut down.

The report is an interesting read. It will help you understand how Internet security threats are evolving, and remind you to continue to adapt your security measures as attackers continue to innovate in their ways to harm you and your enterprise.

Read the entire report at www.symantec.com/threatreport. Follow Symantec throughout the year as it provides threat intelligence via Twitter at @threatintel.