* 2007 is expected to be a record year for security vulnerabilities
Last week I did my best to shatter your sense of security by discussing the high prevalence of man-in-the-middle phishing attacks. I even told you about a MITM “software development kit” that is readily available over the Internet for as little as $1,000. This is evidence of the exponential growth of “exploits as a service,” which IBM Internet Security Systems X-Force identifies as a growing trend and a big threat for 2007.
The X-Force recently released its 2006 Trend Statistics report, a summarization of the 7,200+ security vulnerabilities the team studied last year. While there are a few encouraging trends – “high impact” vulnerabilities continue to decrease as a percentage of total vulnerabilities in 2006 – for the most part, the news is grim. Despite millions of man-hours and billions of dollars being thrown at the problem of security vulnerabilities, the bad guys are running a few steps ahead of the good guys and pulling ahead.
Exploiting flaws in software has become big business. So big, in fact, that Raimund Genes, CTO of security vendor Trend Micro, estimates that the malware industry now accounts for more than the $26 billion in revenue generated by legitimate software businesses in 2005. No longer the domain of amateur hackers, the underground economy of malware, viruses and spam has become quite organized, with developers, distributors, channels and users.
Nevertheless, we can’t give up and let the bad guys win.
The real importance of the X-Force trend report is not to scare the wits out of us. Rather, it is to show us areas of concern that are on the rise, so that legitimate security vendors and the security-conscious public know where to invest time and effort in measures to prevent attacks. That said, here are some of the key points to note from the 34 page report.
* Vulnerabilities are on the rise. The exponential increase of vulnerabilities in 2006 over all previous years shattered many records. X-Force researchers catalogued, tracked and researched 7,247 vulnerabilities – an average of 20 unique vulnerabilities per day, and an increase of 40% over the number reported in 2005.
Lesson to learn: Increase your vigilance, even if you have already deployed security solutions in your organization. This is an ever-evolving problem.
* Ten vendors account for 14% of the vulnerabilities. The top 10 vulnerable vendors in 2006 accounted for 964 of the total vulnerabilities disclosed. Although this seems like a large number of vulnerabilities that likely affected millions of systems worldwide, it only accounted for 14% of the total vulnerabilities disclosed during the year. And, these 10 vendors are more aggressive in issuing patches for their vulnerabilities. Out of the top 10 vendors, only 14% of the publicly-disclosed vulnerabilities remain un-patched, while 65% of all other publicly-disclosed vulnerabilities (i.e., from the vendors below the “top 10”) remain unpatched.
The report cautions that if system administrators and end-users only implement workarounds or apply security patches and upgrades to vulnerabilities in top-vendor software and hardware, it is likely that several thousand vulnerable software packages go unnoticed and unpatched.
Lesson to learn: Be aware of what vendors provide your application software, and stay tuned to the patches they provide.
* Attackers want to gain access. As part of the research into each vulnerability disclosed in 2006, X-Force records the primary consequence of exploitation. In 2006, the most common consequence of exploitation was “Gain Access,” which accounted for 50.6% of all vulnerabilities. X-Force defines the “Gain Access” category as one in which an attacker can obtain local and remote access to a compromised computer. This also includes vulnerabilities by which an attacker can execute code or commands, because this usually allows the attacker to gain access to the system.
Lesson to learn: Focus your time and attention on the vulnerabilities that allow an attacker to gain access to your systems (e.g., malware that turns PCs into botnets).
* The spam problem isn’t licked yet. The volume of spam e-mail increased 100% in 2006. Spammers have gotten more sophisticated, now using HTML-coded or image-based messages to better circumvent spam filters.
Lesson to learn: More sophisticated spam detection methods are needed to combat the new image-based messages.
There’s lots more to learn from the trend report. It’s a worthwhile read and a good eye-opener on security vulnerabilities.




