On last.fm: Exclusive interview with Phoenix
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Mar 21, 2005 6:27:00 PM

More than half of recent major Internet threats tried to harvest personal information, a sign that financial gain is behind the attacks, according to a Symantec study.

Identity theft features were found in 54 percent of the top 50 malicious codes detected between July and December last year, the security company said in a report released on Monday. That marks an increase on the 36 percent found during the same period in 2003.

"This represents a clear trend that attackers have gone from seeking fame to seeking fortune," said Oliver Friedrichs, a senior manager with Symantec Security Response.

Computers are increasingly coming under attack from Trojan horses, worms and viruses that attempt to glean users' cached log-on data and passwords to financial information. This trend is not likely to slow down soon, Friedrichs noted.

The study also detected a rise in phishing attempts, which are used by financially motivated attackers. Phishing scams, which rely on social engineering to dupe people into providing sensitive financial and confidential information, use fake e-mails and Web sites that look legitimate.

Symantec said that by the end of December, it was blocking an average of more than 33 million phishing attempts a week--up from an average of 9 million a week in mid-July.

Regulatory intervention and technological means of checking the legitimacy of e-mails have been suggested as methods of reducing identity threat attacks. But regulations are somewhat limited, because the individuals behind the scams are already breaking the law and show an apparent disregard for rules and regulations, Friedrichs said.

He added that technology, in its current form, is also hard-pressed to combat phishing e-mails and identity threat attacks.

"Most of the technology today is in its infancy," Friedrichs said. "There are a number of efforts underway to create standards to validate these e-mails, but right now there is no clear standard that has been incorporated into technology."

The study also found an increase in the number of flaws in Web applications, which could let attackers get past traditional protections such as firewalls. Vulnerabilities in Web applications accounted for 48 percent of the total number of flaws detected between July and December, up from 39 percent during the first six months of the year.

"Attacks are increasingly focusing on the Web server, which is one of the few things exposed externally," Friedrichs said, referring to the server's placement outside the network wall.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 42 Talkback(s)
Socially Engineered OS Agnostic
Security starts with the user. If he installs whatever, doesn't matter what platform you are running. However, expect little help from Symantec. Their bread & butter is assured when others are infected.... (Read the rest)
Posted by: osreinstall Posted on: 03/22/05 You are currently: a Guest | | Terms of Use
GREAT! This means the Mac is gaining market share!!  Laff | 03/21/05
strange though  doh123 | 03/21/05
Yup.....just the same way I feel about MS studies.  Laff | 03/21/05
It exists because banks make money on ALL illegal transactions. (NT)  Vily Clay | 03/21/05
OK Vily here is your chance to impress me  Squawkbox | 03/21/05
Squawkbox, because you have no clue about everything you say ...  Vily Clay | 03/21/05
Oh that is good!!! You start off by insulting me  Squawkbox | 03/21/05
So far your credentials are good for kindergarten.  Vily Clay | 03/21/05
Hey Squawker, You still in a good mood?  osreinstall | 03/21/05
osreinstall, I see you like the way I correct your mood. Thanks. (NT)  Vily Clay | 03/21/05
But of course, Thanks for asking  Squawkbox | 03/21/05
Squawkbox, where are your promised credentials? Get lost? (NT)  Vily Clay | 03/21/05
Dude...  Martin Marvinski | 03/21/05
Translation: if you same as Martin do not have brains to argue ?shut up. NT  Vily Clay | 03/22/05
Or it means  voska | 03/21/05
Oh, so coool, and so unsecure...  quietLee | 03/21/05
Yup  Jeff Spicoli | 03/21/05
Then ZDNET posts this from Symantec  Squawkbox | 03/21/05
Glad someone FINALLY got a clue !!!  realitycheck101 | 03/21/05
Social engineering  Anton Philidor | 03/21/05
Social engineer works computer or no computer  voska | 03/21/05
Message has been deleted.  JoeMama_z | 03/21/05
That was incredibly lame  Jeff Spicoli | 03/21/05
Because ZDNet Is Run By A Bunch Of Brownshirt Bush Nazis  itanalyst | 03/21/05
I thought that post was very helpfull  JoeMama_z | 03/21/05
ZDNet Is Under Orders To Delete Posts Helpful To The Downfall Of Microsuck  itanalyst | 03/21/05
interesting point  Jeff Spicoli | 03/21/05
it wasn't on how to deploy FF  JoeMama_z | 03/21/05
Heehee  Jeff Spicoli | 03/21/05
you like that?  JoeMama_z | 03/21/05
I actually replied to that...  Martin Marvinski | 03/21/05
me too.  JoeMama_z | 03/22/05
Hey Joe..  Jeff Spicoli | 03/22/05
Jeff...  JoeMama_z | 03/22/05
Virus writers follow the money  nerdnick | 03/21/05
Increase in attacks, or increase in successful attacks?  hipparchus2000 | 03/21/05
Exactly!  Xunil_Sierutuf | 03/21/05
Nice Try, Symantec..!  Xunil_Sierutuf | 03/21/05
The DARK SIDE  nerdnick | 03/22/05
Can we have the statistics please?  vincedevries | 03/22/05
The only one reaching for anyone's wallet...  bugmenotznet | 03/22/05
Socially Engineered OS Agnostic  osreinstall | 03/22/05

What do you think?

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here