May 17, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Security Syndicate This
Print this article    Email this article    Talk Back!    Write to Editor
2007: The Year of Rising Threats?
02/19/2007
By Mike Paquette, Chief Strategy Officer, Top Layer Networks

Security threats paint a constantly evolving landscape, and there is no end in sight in terms of threats that keep appearing.  Enterprises have survived through extraordinary cycles of security threats: the 2003 “Summer of Worms;” the 2004 proliferation of DDoS-based cyber extortion of online betting sites, and the 2005/2006 rise of botnets used for spam, targeted-attacks and worse.  With the new calendars freshly hung on the wall, the question is, what security threats are on the rise for 2007? 

ADVERTISEMENT
Our Popular Webinars
Achieving Process Optimization and Efficiency in Manufacturing –
A BPM Best Practice
Accelerate Agility and Lower Costs by Virtualizing and Governing Your SOA
PepsiAmericas: Realizing Real-Time Communication
a refreshing approach to ESB and data integration
Avoid the SOA Pitfalls that Prevent ROI
BAM for BPM Survey Results Are In! Learn What’s Driving New BAM Investments
More Webinars

The Bulls-eye for Bad Guys - More Targeted Threats

Looking across the threat landscape, 2007 foresees more narrowly-defined threats or “targeted threats.” Targeted threats are different from what we have seen before -- they are more focused on individual information as opposed to mass-mailing worms that are sent over the Internet expected to randomly infect victims.  These targeted attacks can extract personalized information to later use in attacking a single person or company.

Targeted threats could be so narrowly-focused as to constitute industrial or even political espionage, trying to gain sensitive information from a single company or individual rather than the indiscriminate approach of letting a worm loose to randomly find victims wherever it may go.

Targeted attacks combine malware technology with social engineering, where an individual is lured, fooled or tricked through subtle, and sometimes not-so-subtle, manipulation to take some action that will ultimately result in damage or loss to that individual, his company, or organization, or to a third party.

Some attacks actually send the malware directly to the victim, perhaps as an email message attachment, and lure the user into executing the malware which will subsequently steal information from the victim.

Other attacks lure or trick he victim to download a file, such as a video, which might contain additional code or script instructions that can be used to steal identity information.   The recent Myspace.com “Quicktime worm” used this technique. 

More sophisticated attacks get the user to do nothing more than click a hyperlink to a specially crafted web site that knows how to install the malware on the victim PC without requiring any additional help from the victim to do so.  In this case the web site contains an exploit of a security vulnerability that exists in some of the software being used by the victim.

There are three factors pointing to the increased prevalence of targeted attacks in 2007:

Page 1

More Top Stories
Is Big the New Small in Application Security? Gold Club Protected
Doing Risk Management Right Gold Club Protected
Defending Against the Cross-Site Scripting Attack Gold Club Protected
Penetration Testing Like a True Hacker Gold Club Protected
Managing IT Risk Effectively Gold Club Protected
Edging Towards Secure Application Development Gold Club Protected
More Top Stories
Related News
Informatica Completes Acquisition Of Identity Systems
IBM and RIM Mobilize Web 2.0 Capabilities
NYSE Euronext Runs on Red Hat
More News
Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
PepsiAmericas: Realizing Real-Time Communication
a refreshing approach to ESB and data integration

Date: May 28, 2008
Time: 13:00 PM ET
(17:00 GMT)

REGISTER TODAY!
Accelerate Agility and Lower Costs by Virtualizing and Governing Your SOA
Date: May 29, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Archived Webinars | Upcoming Webinars
  Event Processing Market Pulse 2007

The buzz around event-driven architecture has been increasing in both practitioner and vendor circles. Unlike many emerging technologies that are...Learn More

ebizQ also recommends
 BI for Telecom
 BI for Process Industries
 BI for Health Care
 BI for Decision Makers
 BI for Consumer Packaged Goods
More White Papers

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map