SEO Jobs in India - ZDNet Asia http://bit.ly/c2JxOH
2 hours 52 minutes ago by jagbirsinghseo on topsyZDNet is available in the following editions:
The number of vulnerabilities found in software will jump this year, experts say--but there's a silver lining.
It isn't over yet, but 2006 is already a record year when it comes to security vulnerabilities.
There is, however, a silver lining: A smaller chunk of the flaws are high risk.
Last year, researchers at Internet Security Systems identified 5,195 vulnerabilities in software. On Monday, the count for this year stood at 5,450, according to the Atlanta-based company's survey, and the projected total for the whole of the year is almost 7,500 bugs.
"Three-quarters through the year, 2006 is looking to be a huge jump in terms of security vulnerabilities," said Gunter Ollmann, director of X-Force, the research and development group at ISS.
The number of problems found has increased as bug hunters and software makers have become more skilled at finding them and as access to automated audit tools has improved, Ollmann said. Also, there is more code to comb for security holes, because people use more complex software than ever.
Atlanta-based ISS, which is being acquired by IBM, predicts there will be a 41 percent increase in confirmed security faults in software compared with 2005. That year, in its own turn, saw a 37 percent rise over 2004.
But there is some good news as well: While there will be an overall jump in the number of security vulnerabilities, it will be accompanied by a fall in the percentage of bugs rated "critical" or high-risk, Ollmann said.
According to Ollmann, severe flaws like these accounted for 28.4 percent of all security holes last year. By comparison, they make up only 17 percent of the flaws identified this year up to Monday, and that percentage is expected to be the same for the full year.
"This is probably the most positive part of the vulnerability trend," Ollmann said. "In previous years, there was an upward trend in the number of critical and high-risk vulnerabilities."
ISS's description of a rise in flaws is backed up by other security companies. VeriSign's iDefense and eEye Digital Security also said they have seen an increase in vulnerabilities this year. Another indication of an increase comes from Microsoft's security bulletins. The software maker issued 55 in the first three quarters of this year, compared with 45 in all of 2005.
In addition, Symantec's Internet Security Threat Report says 2,249 new vulnerabilities were documented in the first six months of 2006, up 18 percent over the second half of 2005. That's the highest number ever recorded for a six-month period, the security company said. Eighty percent of newly disclosed issues were considered easily exploitable, and the window of exposure for enterprise flaws was 28 days.
More security vulnerabilities mean more opportunities for cybercrooks and more headaches for people creating and applying security patches, experts said.
"You have to protect against every single one of those vulnerabilities, while an attacker needs to find only one to stage an attack," Ollmann said. "The more vulnerabilities that are disclosed, the more at risk you are."
Warming up to fuzzers
Critical and high-risk vulnerabilities are
those that could let a network worm spread by itself, or could allow an
anonymous attacker to remotely gain control over a computer without the user
taking any action. As well as a percentage drop, ISS projects a fall in the
absolute number of these types of bug in 2006, which anticipate 1,265 compared
with 1,475 last year.
The drop in the most serious flaws can be attributed, in part, to better-built software. "Software is becoming more secure," Ollmann said. Also, many bug hunters have started using automated tools called 'fuzzers,' which often turn up flaws that end up being rated medium-risk," he said.
For example, a fuzzing tool could be used to test how a specific application handles a certain file format, such as the JPEG and GIF image formats. If that application--say, a Web browser--returns an error, the error could point to a vulnerability that could be used as the basis for an attack. To exploit this flaw, however, the attacker will often have to trick the victim into opening a malformed file.
Fewer of the most-serious flaws are being discovered in operating systems, said Steve Manzuik, an eEye representative. However, there are more being uncovered in other kinds of software.
"We have seen an increase in critical client-side flaws such as ones in Internet Explorer, QuickTime, and Office applications," he said.
The overall dip in severe flaws may be short-lived, Ollmann said. When a major new software product ships, the count of critical bugs typically spikes, he noted. In January, Microsoft's new Windows Vista, the operating system successor to XP, is slated to be broadly available. Microsoft has tagged Vista as the "most secure version of Windows ever."
"I think that certainly in the first half of 2007, we will see an increase in percentage terms of high-risk and critical vulnerabilities," Ollmann said. "That will most likely be associated with the release of Vista."
It isn't just the most serious flaws that people need to worry about, noted Ken Dunham, director of the rapid response team at iDefense. "This year has been unprecedented in terms of zero-day attacks," he said. "There is a much larger number of medium-level vulnerabilities today, and many of those are being used in attacks."
Zero-day attacks use previously unknown flaws that have yet to be fixed. Many of them take advantage of the type of security hole that can be found using a fuzzer.
Such mid-level vulnerabilities are being used in two main types of attacks. Consumers are targeted via malicious Web sites that try to silently install spyware or other nefarious software such as keystroke loggers and bots, Dunham said. Businesses are being targeted directly, with small-scale attacks that use rigged Word documents, for example, he said.
"Consumers can count on Web-based attacks, while the scary part for organizations is that they are being targeted specifically by certain attackers," Dunham said.
SEO Jobs in India - ZDNet Asia http://bit.ly/c2JxOH
2 hours 52 minutes ago by jagbirsinghseo on topsy[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia
5 hours 30 minutes ago by danielcktan on twitterURL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia
5 hours 58 minutes ago by angahsin on twitter#Cloud #Telecom Indian IT to clock double-digit growth in 2010 - Zd Net Asia.com: ... manager of India and Sou... http://bit.ly/dilbUI #TCN
6 hours 24 minutes ago by telecomcloudnet on topsyTemasek Holdings eyeing tech stocks, indicating optimistic outlook on IT sector. http://bit.ly/aM7VwU
6 hours 27 minutes ago by zdnetasia on twitterURL shorteners slow Web redirection. http://bit.ly/bySnWK
6 hours 27 minutes ago by zdnetasia on twitterChinese agencies cry foul over Google. http://bit.ly/by6rwV
6 hours 33 minutes ago by zdnetasia on twitterPhilippine antipiracy drive focuses on enterprises. http://bit.ly/aWryDC
6 hours 54 minutes ago by zdnetasia on twitterGartner: China to become world's fastest-growing enterprise software market. http://bit.ly/bqJTtb
6 hours 55 minutes ago by zdnetasia on twitterall of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...
9 hours 51 minutes ago by melvinchia on Web filters mean bad news for businessit is not to good for china.
Proactol
Salesforce.com is giving 5,000 developers access to its social networking and collaboration platform http://bit.ly/9dbNw5
12 hours 44 minutes ago by abhishekkatiyar on topsyRT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6
13 hours 6 minutes ago by LiruChan on twitterFor those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i
13 hours 31 minutes ago by zdnetasia on twitterHP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6
13 hours 39 minutes ago by zdnetasia on twitter** S'pore govt launches traffic Web app. http://www.zdnetasia.com/s-pore-...
15 hours 17 minutes ago by juiceliving on twitterthe new look site is very nice @zdnetasia @zdnetaustralia
18 hours 55 minutes ago by susan_m on twitterBig up to my peeps at www.ZDNet.com.au (and www.ZDNetasia.com and www.ZDNet.com.uk). Loving the redesign!
19 hours 11 minutes ago by randolphramsay on twitterHoliday homes for sale : ZDNet Asia Blogs : by http://bit.ly/aNsfp1
1 day 39 minutes ago by moonflowerstarf on topsyMcAfee steps up cloud assurance - Zd Net Asia.com
http://www.zdnetasia.com/mcafee-...
Interesting take on social analystics. http://www.zdnetasia.com/blogs/w...
1 day 37 minutes ago by zatso on twitterVery good explanation of JMX
1 day 41 minutes ago by Babith B on Managing applications with JMXThe reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.
1 day 44 minutes ago by lonemavericks on diggsAnother ZTE story....
1 day 46 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G licenseWe at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.
1 day 20 minutes ago by sarah Jane on Companies' outsourcing spend to increaseI agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...
1 day 50 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV insteadhermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...
2 days 28 minutes ago by ... on Facebook user charged in MalaysiaPassword manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...
2 days 28 minutes ago by ohanae on What defaults should random password generators use?I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.
2 days 2 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stickThanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...
2 days 3 minutes ago by Roger Biefer on Manage time accuracy with W32Tmavailable in singapore now
http://www.portablemall.com.sg/goods-71-Microsoft+Zune+HD+32GB+-+Platinum.html
How about just using http://www.random.org/strings/? It is very configurable, satisfies all of the flexibility requirements you have ment...
2 days 45 minutes ago by Varun V Nair on What defaults should random password generators use?Wi-Fi as the "Rodney Dangerfield of wireless", is a catchy metaphor, but it's already been used. In fact, it was the title of a...
3 days 44 minutes ago by Martin Suter on Selina Lo: Wired up for Wi-Fi in AsiaDear Sir/Madam, I am Narasimha Rao.L. From bangalore India , i searching job in abroad , in electronics field, i have 6+ years exp....
4 days 46 minutes ago by Anonymous on Hot tech jobs in SingaporeGood article, computational aspect of acquired knowledge from the social platform is really questionable, given that there are a lot of p...
4 days 52 minutes ago by JN on What will social analytics say about your company?The Desktop Virtualization Revolution is here!
Find our more with Citrix Simplicity is Power
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.
The Internet Show 2010, 21-22 Apr 2010, Singapore
FREE admission for visitors who pre-register online. Register Today!