Web threats dominate security landscape

By Victoria Ho, ZDNet Asia
Friday, March 14, 2008 06:19 PM

This year, the overall trend for most security threats appears to be Web-related--most are either directly from the Web, or a result of being connected while on the go.

According to the Unisys Security Index, the main concern enterprises have about mobility is not that of mobile viruses, but identity theft and data loss.

The survey of 891 Singaporeans conducted late last year showed a high 83 percent of respondents were anxious about identity theft. This is consistent with that of previous years' results, said Unisys Asia South vice president Scott Whyman.

Whyman said in an interview: "In spite of healthy discussion and banks putting in tighter security measures, people still feel threatened regarding identity theft."

Data lost from physically losing devices is a related concern. Anand Jude, business development director of Singapore-based mobile security vendor, Ufinity, said he is seeing a continual uptake of customer demand for mobile phone protection.

Jude said in an interview: "Most customers want to restrict access to personal information on stolen or lost devices. We don't hear much concern about mobile spam, compared to data theft."

Jude noted an increasing number of competitors appearing, providing similar tools for remotely locking phones because of this rising demand. Singapore-based tenCube provides such a service; its CEO, Darius Cheung, said in a previous interview that he was "very optimistic about the market potential" for such services.

Web threats on the rise
Direct attacks on systems delivered over the Web are a growing concern. According to security company Sophos, it discovered one new infected page every 14 seconds last year--that translates to 6,000 new infections a month.

Sophos adds that the majority 83 percent of the sites were not originally malicious in intent, but legitimate sites that were compromised by third parties.

The motivation for such threats is profit, according to Trend Micro.

Raimund Genes, Trend Micro's chief researcher, said in a presentation: "Malware for profit is definitely driving these Web threats," adding that most malware this year will originate from the Web, rather than e-mail--traditionally the medium through which attacks have been delivered online.

Trend Micro chief executive Eva Chen said the reason for this is that e-mail security tools have become commonplace, while Web traffic security is also more difficult to enforce.

Chen said: "HTTP is real time and you need to be able to deal with the latency in the user experience."

Web 2.0 contributing to malware attacks
Malware authors tend to capitalize on trends in user behavior, as with the "Heath Ledger" malware wave earlier in 2008.

Another trend is that malware is targeting the increasing popularity of social networking sites. According to Unisys, breach of privacy is the main hole that malware authors are poking in at sites such as MySpace or Facebook.

Unisys' Whyman said: "As these sites connect to one another, many will cross-reference a member’s credentials. If a hacker can compromise one account, he could end up compromising many."

Such sites also encourage users to share information, because they are social in nature, added Whyman.

Research house, Yankee Group, also said that companies are largely ignorant of such threats, perpetuating the danger. A recent study it conducted found 65 percent of U.S. companies doing nothing to block Web 2.0 applications such as instant messengers and file-sharing programs.

Tom Rashke, senior analyst at Forrester, said companies need to secure the data transferred, not just the infrastructure.

Rashke explained that tools need to go beyond the network into content to determine whether it is a security risk--either incoming as malware or outgoing as data leakage.


See also:  Security
WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

CodeGear extends the Borland legacy

Web Development

Discover what the CodeGear developers are working on.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. asian
  2. beat
  3. bpo
  4. business
  5. china
  6. deal
  7. deals
  8. firms
  9. future
  10. green
  11. hp
  12. icahn
  13. ict
  14. india
  15. jobs
  16. mian
  17. microsoft
  18. mobile
  19. offer
  20. price
  21. report
  22. services
  23. spore
  24. tech
  25. technology
  26. tier
  27. unveils
  28. us
  29. world
  30. yahoo

Has the Internet changed our core values?

Blog thumbnail

If you've been following this blog, you might remember that I'm a self-professed sufferer of a, erm, disorder I've come to call, privacy..... by Eileen Yu

Read more »