Symantec's Top 10 Internet Security Trends of 2007Best Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!  Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Our Partners
Downloads
Windows Security : Symantec's Top 10 Internet Security Trends of 2007
Posted by Max on 2007/11/18 16:41:02 (1585 reads)
Windows Security

Security breaches, unknown security risks posed by Vista, spam and organized cyber crime are some of the Symantec's Top 10 Internet Security Trends of 2007.Phishing attacks will spread not only against the most popular brands of online services but also against any system which deploys single factor authentication such as username and password.

Here were the ten major security trends of the year as Symantec and others have seen them:


1. Data Breaches. Late last month, documents from an information-breach lawsuit against the TJX Corporation -- owners of TJ Maxx -- revealed that as many as 94 million customers using Visa and MasterCard were exposed to hackers. Further, in addition to Monster.com and Salesforce.com being hacked, there is also a report coming out next week that suggests half a million database servers are vulnerable. Turner says these events are what made data breaches the top concern among security experts this year.

2. Vista Introduction
. More than a dozen security patches, perceived complexity and an ambivalent reception among tech media and some technologists have kept the much talked about OS in the news, making it a top issue of 2007.

3. Spam. The hair-growth pill promotions, penny stock tips, and promises of money from deposed African dictators won't stop hitting your e-mail inbox anytime soon. Moreover, spammers are increasingly taking more sophisticated approaches such as sending disguised PDF files, pretending to know you in e-mail subject lines and delivering Storm Worm malware through e-greeting cards.

4. Professional Attack Kits. Symantec believes that not only are hackers becoming more savvy but are also setting up a new revenue stream by selling hacker kits to peers. Such kits include MPack, which was popular this year and "phishing" toolkits pervade cyberspace as well.

5. Phishing
. Phishing, a cousin of spoofing and masquerade hacking, gets its name from the way hackers use friendly or seemingly benign programs as bait. Symantec's Turner says criminals no longer have to hack in, as some users are coming to them.

6. Exploitation of Trusted Brands. By exploiting a trusted Website, hackers can trick someone into thinking they're getting on Bank of America's homepage by, for instance, sending them a link such as www.bofa.com@yourmoney.com. Someone may then key in information on a false interface. While most browsers nowadays are equipped with warning messages, "Phishermen" also take advantage of misspellings of popular Internet addresses.

7. Bots. Hacking by proxy is an increasingly common way for cyber criminals to maintain anonymity, and the use of "Bots", or Electronic Data Interchange translators, is one of the many malicious emissaries used to siphon protected information.

8. Web Plug-ins. ActiveX control modules, derived from Microsoft's Component Object Model and used to manage multimedia applications, comprised the majority of plug-in vulnerabilities in 2007, according to Symantec. These modules are usually downloaded from Web pages and used to make programs more compatible with others -- but they can also be used as attack vectors.

9. Vulnerabilities for Sale. This year the debate over the link between proof of concept exploits and "wild" exploits heated up after a decision in late September by Swiss tech upstart Wabi Sabi Labi Ltd., to create an eBay Inc.-style auction for unpatched, zero-day software vulnerabilities.

10. Virtualization Machine Security. Software and server virtualization, as evidenced by VMware's multi-billion-dollar IPO and new entries by Oracle, Sun, Microsoft and others, is definitely here to stay. If two file servers can do the work of ten, as some proponents attest, then a hacker can have a field day exploiting such technology.




Other articles
2010/3/18 8:07:31 - Panda Cloud Antivirus Receives ICSA Labs' First Cloud-Based Certification
2010/3/17 15:49:34 - Open-Source Email Security Taken To The Next Level at WebhostingDay
2010/3/17 15:18:40 - McAfee Warns ABout Scareware or Fake Antivirus Software
2010/3/2 5:22:13 - VeriSign and AVG Will Integrate VeriSign Trust(TM) Seal Within AVG LinkScanner(R)
2010/3/1 7:36:12 - New Stealth Software Protects P2P Users From Lawsuits by Copyright Holders
2010/2/24 13:55:16 - New State of The Art Firewall By Palo Alto Networks
2010/2/24 13:50:26 - Beware of Fake Antimalware Programs Like PCsProtector
2010/2/24 13:38:02 - New Registry Cleaner Guide Helps Your PC Perform Faster
2010/2/3 7:32:43 - PC Login Now (Full version) Available Now For Free.
2010/2/3 7:11:57 - Mitto Named One of 20 Top Web Applications

The comments are owned by the poster. We aren't responsible for their content.