Businesses face new breed of security threats

By Tim Ferguson, Special to ZDNet Asia
Friday, April 11, 2008 06:16 AM

"Pass the hash" and "metasploit" are two of a breed of emerging security threats facing corporate IT departments.

The key security threats facing businesses range from mutations of established phenomena--such as malware or phishing--to less well-known ones, such as metasploit releases and pass-the-hash attacks.

The most dangerous new security threats were revealed by experts at the RSA security conference in San Francisco this week.

Ed Skoudis, a hacking expert at the Sans Institute, said most security threats stem from the fact that so many applications are now linked to the Internet.

He said: "We've Web-ified all applications."

Among the less familiar new threats are metasploit releases, which target networks by simultaneously attacking a number of vulnerabilities (up to 200) on different platforms, including Windows, Linux and the iPhone.

Pass-the-hash attacks, which use stolen password hashes to access other systems in a targeted network--avoiding more time-consuming password-cracking--were also singled out.

Although this approach has been around for some time, it is only now that it's becoming prevalent. Skoudis said: "These attacks have been around for years but now the tools are out there."

Web site attacks, which plant browser exploits to compromise users, are also becoming more of a problem, as they are able to target well-known, high-traffic sites.

A major threat is browser scripting attacks, which use Web browsers to get through corporate firewalls, allowing access to confidential information.

While not a new threat, the development of botnets remains a big security concern because the "fast flux" approach used by attackers to protect their robotic networks is making the life of botnet investigators difficult.

The security experts also warned about the threat of malware being spread through the use of embedded devices, such as memory sticks--now one of the main ways harmful code is brought into businesses.

Tim Ferguson of Silicon.com reported from London.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web