Web Based Trojans Are The New HitBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Downloads
RSS / Atom Feeds
Web Security : Web Based Trojans Are The New Hit
Posted by Max on 2007/11/2 15:15:51 (533 reads)
Web Security

The war against computer malware is far from ending as Trojan writers find new ways to elude the security countermeasures deployed by corporations and end-users alike. The latest trend in Trojan distribution is web hosted malware and this has put the cyber criminals one step ahead of the security vendors.

Secure Computing principal research scientist Dimitri Alperovitch says that “We have seen a steady increase over the last year or so from malware being distributed typically through email now shifting to the Web factor.

Google confirms this by a recent study which showed as many as 10% of all Web sites are host to some type of malicious code.

The reason for this move is straightforward; most businesses and enterprises have focused mainly on messaging security and protecting email systems by scanning for malware and stopping executable code from entering enterprise networks through email. Web security has centered more on preventing users from accessing certain types of content.

Roger Thompson, a seasoned security researcher who is the CTO at Exploit Prevention Labs (www.explabs.com), agrees. Throughout his 20-year career in the security industry, Thompson has also witnessed backdoors and Trojans morph into an organized network of crime, costing global organizations billions of dollars annually. According to Computer Economics’ “2007 Malware Report,” the total cost of damages due to malicious code reached $14.2 billion in 2005.

Ryan Hicks, who heads up EarthLink’s (www.earthlink.net) spyware research team, concurs. “If you look over the years, what used to be the primary threat was replicable code—Trojans were a concern, but not a big one. Now if you look at it, the technology behind Trojans is at the top of everyone’s list.”

“Traditionally, the Web security has taken a backseat to other security considerations,” says Alperovitch. Recognizing this, criminals’ techniques have evolved, and what they have discovered is that they are able to obtain a much higher return on investment by distributing Trojan horses and backdoors via Web sites.

According to Thompson, “So much is built on the browser. When you open a browser, you’re creating an instant tunnel right through the firewall. Firewalls are really good at keeping out network worms, and email filters are good at keeping out email worms, but when you open a browser, you’re authorizing pretty much whatever wants to go on to come straight through the firewall.”




Other articles
2008/8/21 15:52:01 - BitRoll and Torrent101 Used to Distribute the Lop Adware
2008/8/20 15:06:33 - FRAUDFacts Helps You Fight Identity Theft and Fraud for Life
2008/8/13 16:42:03 - 10 Million Zombies Are Spreading Spam and Malware Every Day
2008/8/11 9:03:35 - Nearly $8.5 Billion Lost by US Consumers because of Online Threats
2008/8/8 6:35:36 - EDS' Eight Tips for Consumers to Protect Themselves from Identity Theft

The comments are owned by the poster. We aren't responsible for their content.