The Enterprise Security Supersite
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Network Security Viruses & Malware Spam & Hackers Security Products More Topics...
Network Security
Average Rating:
Rate this article:  
IBM X-Force Security Report Calls Web Insecure IBM X-Force Security Report Calls Web Insecure
By Jennifer LeClaire
August 28, 2009 1:39PM

Bookmark and Share
IBM's X-Force 2009 Mid-Year Trend and Risk Report says malware threats are converging to create an insecure Web. IBM said new malicious Web links found in the first half of 2009 rose 508 percent and included trusted sites. PDF file exploits are at an all-time high, IBM said. X-Force Director Kris Lamb said, "There is no such thing as safe browsing."
 


Web insecurity. That's the two-word summary of IBM's X-Force 2009 Mid-Year Trend and Risk Report. Big Blue released its latest survey Wednesday with some troubling news: Web client, server Relevant Products/Services and content threats are converging to create an untenable risk landscape.

IBM recorded a 508 percent increase in the number of new malicious Web links discovered in the first half of 2009 -- and the problem is no longer limited to malicious domains or untrusted Web sites. The X-Force report points to an increase in the presence of malicious content on trusted sites, including popular search engines, blogs, bulletin boards, personal Web sites, online magazines, and mainstream news sites. The consequence for victims is attackers gaining access to private data Relevant Products/Services.

The X-Force report also discovered evidence that suggests attackers are getting more sophisticated. Veiled Web exploits, especially PDF files, are at an all-time high. PDF vulnerabilities disclosed in the first half of 2009 surpassed findings from all of 2008. From the first quarter to the second quarter alone, the number of suspicious, obfuscated or concealed content monitored by the IBM ISS Managed Security Services team nearly doubled.

Safe Browsing Extinct

"The trends highlighted by the report seem to indicate that the Internet has finally taken on the characteristics of the Wild West where no one is to be trusted," said X-Force Director Kris Lamb. "There is no such thing as safe browsing today and it is no longer the case that only the red-light district sites are responsible for malware. We've reached a tipping point where every Web site should be viewed as suspicious and every user is at risk. The threat convergence of the Web ecosystem is creating a perfect storm of criminal activity."

Web security Relevant Products/Services is no longer just a browser or client-side issue, according to IBM. Criminals are also leveraging insecure Web applications to target users of legitimate Web sites. The X-Force report discovered a sharp increase in Web-application attacks aimed at stealing and manipulating data and taking control of infected computers. SQL-injection attacks rose 50 percent from the fourth quarter 2008 to the first quarter 2009 -- and then nearly doubled from the first quarter to the second quarter.

"Two of the major themes for the first half of 2009 are the increase in sites hosting malware and the doubling of obfuscated Web attacks," Lamb said. "The trends seem to reveal a fundamental security weakness in the Web ecosystem where interoperability between browsers, plug-ins, content and server applications dramatically increases the complexity and risk. Criminals are taking advantage of the fact that there is no such thing as a safe browsing environment and are leveraging insecure Web applications to target legitimate Web-site users." (continued...)

1  |  2  |  Next Page >

 

Tell Us What You Think
Comment:

Name:



Advertisement


 Network Security
1.   Keeping Your Computer and Data Safe
2.   Sunbelt Software Acquired by GFI
3.   Virtual Personal Networks for Security
4.   Cyber Command Logo Has a Secret
5.   NSA Will Monitor Systems for Attacks


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Spam & Hackers | Security Products | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.