Advertisement
Promo

Security threats Toolkit

Fewer flaws but more threats

Published: 16 Mar 2004 08:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The number of public alerts about software security flaws levelled off during the past six months, but worms continue to threaten the Internet, according to a report security company Symantec released on Monday.

In 2003, information on 2,636 security vulnerabilities was released to the public, according to Symantec's biannual Internet Security Threat Report. That's an increase of only 2 per cent from the 2,587 vulnerabilities disclosed by companies and security researchers in 2002, said Alfred Huger, senior director of engineering for Symantec. From 2001 to 2002, there was an 81 per cent increase, Huger said.

"This is the first year that we have seen the disclosure of vulnerabilities level off," he said.

The report affirms a trend found in data from the Computer Emergency Response Team Coordination Centre: The 3,784 vulnerabilities reported to the organisation last year decreased 8 per cent from the 4,129 flaws found in 2002.

The trend could be an indication that software development is getting better and that programmers are learning how to avoid the most common security missteps. Another factor is that security researchers are increasingly giving software companies a chance to fix the flaws before public alerts are sent out, which can delay the alerts.

"More people are working with vendors to patch these issues, and that takes more time," Symantec's Huger said. For example, Microsoft took more than six months to produce a fix for several recent Windows vulnerabilities.

However, the drop may have been influenced by another, not so positive, factor, Huger said. More researchers may be failing to report new flaws. "Good" security researchers could be keeping information on a given flaw to themselves as a competitive advantage, or malicious researchers could be keeping quiet so that they can use the flaw in an attack.

Much of Symantec's report is based on data submitted from more than 20,000 Internet devices owned by clients or affiliates. The data shows that 43 per cent of attacks were due to worms. Another 40 per cent constituted probes, not necessarily malicious, of systems vulnerable to specific problems. The remaining 17 per cent of attacks were intrusion attempts that weren't caused by worms.

The MSBlast, or Blaster, worm accounted for nearly a third of all attacking computers detected by Symantec's sensor network in the last six months, the report said, but it was responsible for only about 2 per cent of attacks. That's because a single computer can be used in several attacks, and other worms took greater advantage of this. The very efficient Microsoft SQL Slammer worm, for example, accounted for more than a quarter of total attacks detected, with only 2.4 per cent of attacking computers.

The Code Red and Nimda worms -- both more than two years old -- are also still spreading around the Internet, the report found.

Another trend appears to be that attackers are increasingly targeting previously compromised computers and taking advantage of the backdoors left by successful worm and virus attacks. The latest viruses -- including the MyDoom, Sobig and Bagel viruses -- leave behind a secret entry point into any system that has been infected by the programs. Increasingly, intruders are checking for those backdoors first.

"It is almost like it has created a different dimension to the underground exploitation of the Internet," Symantec's Huger said. "There are a whole bunch of 'properties' out there that are freely available to groups to take advantage of."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
80 out of 144 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters