Websense 2008 Security Threat PredictionsBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2008/8/29 20:49:42
2008/8/29 15:58:44
2008/8/29 15:58:44
2008/8/29 15:58:44
2008/8/29 15:58:44
Downloads
RSS / Atom Feeds
Web Security : Websense 2008 Security Threat Predictions
Posted by Max on 2007/12/6 15:38:15 (810 reads)
Web Security

Specifically, the Websense Security Labs expects: the Olympics will spur a flurry of hacker activity such as compromises of popular Olympic news or other sports sites; hackers will leverage the increased adoption of Macs and iPhones as new means for cross-platform Web attacks; special interest groups that fall within a certain age group, wealth bracket, or people with particular purchasing habits, will become targets of Web 2.0 attacks; and spam will increase in the blogosphere and “talk back” sections of news sites to drive traffic and increase search engine rankings of infected Web sites.

Websense 2008 Security Threat Predictions
 
1. Olympics – new cyber attacks, phishing and fraud
Event-based attacks and scams are popular, and with the whole world watching, the 2008 Olympics may fuel a surge in cyberattacks.

2. Malicious SPAM invades blogs, search engines, forums and Web sites
Websense predicts that hackers will increasingly use Web spam to post URLs to malicious sites within forums, blogs, in the commentary or “talk-back” sections of news sites and on compromised Web sites.

3. Attackers use Web’s ‘weakest links’ to launch attacks
The Web is an entanglement of links and content.  The advent of Web 2.0 additions such as Google Adsense, mash-ups, widgets, and social networks along with the massive amounts of Web advertisements linked to Web pages have increased the likelihood of ‘weak links’—or Web sites and content that are vulnerable to compromises.

4. Number of compromised Web sites will surpass number of created malicious sites
The Web as an attack vector has been steadily increasing for the last five years and now attackers are using compromised sites as their launching platforms—even more than their own created sites. Compromising sites—particularly, sites well-visited by end-users, such as the Dolphin Stadium attack that occurred a few days prior to the 2007 Super Bowl XLI in Miami., provides attackers with built-in Web traffic and minimizes the need for lures through email, instant messaging or Web posts.

5. Cross-platform Web attacks – Mac, iPhone popularity spurs increase
With the brand popularity and growing use of iPhones and Macintosh computers, Websense researchers predict attackers will increasingly launch cross-platform Web attacks that detect the operating system in use and serve up code specifically targeting that operating system instead of attacks based on just the Web browser.  Operating systems that are targeted now include Mac OSX, iPhone, and Windows.
 
6. Rise in targeted Web 2.0 special interest attacks—hackers targeting specific groups of people based on interests and profile
Web 2.0 has spawned a proliferation of Web users that visit chat rooms, social networking sites, and special interest Web sites such as travel sites, automotive, and more.

7. Morphing JavaScript to evade anti-virus scanners
Hackers are upping the ante with evasion techniques that use poly-morphic JavaScript (Polyscript) – which means that a uniquely-coded Web page is served up for each visit by a user to a malicious Web site. By changing the code every visit, signature-based security scanning technologies have difficulty detecting Web pages as malicious and hackers can extend the length of time their malicious site evades detection.
 
8. Data concealment methods increase in sophistication
Websense predicts an increased use of crypto-virology and sophistication in data concealment including the use of stenography, embedding data within standard protocols, and potentially within media files.

9. Global law enforcement will crack down on key hacker groups and individuals
In 2007, large-scale Internet-based attacks garnered the attention of law enforcement officials around the world. Websense anticipates that through the global cooperation of enforcement agencies, in 2008 the biggest crackdown and arrests of key members of a hacker group will occur.

10. Vishing and voice spam will combine and increase
The vast cell phone user population has grown into a lucrative market to exploit with spamming and “vishing” for financial gain. To date, researchers have seen an increased number of vishing attacks but not a lot of spam—or pro-active automated calling. In 2008 Websense predicts that “vishing”, or the practice of using social engineering and Voice over IP (VoIP) to gain personal and financial information and voice spam will combine and increase—users will receive automated voice calls on LAN lines with voice spam to lure them to input their credentials through the telephone.




Other articles
2008/8/21 15:52:01 - BitRoll and Torrent101 Used to Distribute the Lop Adware
2008/8/20 15:06:33 - FRAUDFacts Helps You Fight Identity Theft and Fraud for Life
2008/8/13 16:42:03 - 10 Million Zombies Are Spreading Spam and Malware Every Day
2008/8/11 9:03:35 - Nearly $8.5 Billion Lost by US Consumers because of Online Threats
2008/8/8 6:35:36 - EDS' Eight Tips for Consumers to Protect Themselves from Identity Theft

The comments are owned by the poster. We aren't responsible for their content.