Computerworld - The majority of Web sites serving up attack code are legitimate domains that have been hacked by criminals, according to security research firm Websense Inc.
In a report released last week, San Diego-based Websense said that credible sites accounted for 51% of those classified as malicious. The sites had been compromised by hackers who seeded them with attack code that infected unpatched machines visiting those addresses, it said.
A year earlier, Websense estimated that about 35% of malicious sites were actually legitimate sites that had been compromised.
The remaining deleterious sites were "intentionally built for malicious intent," the Websense report said.
Hacking legitimate sites so that they can sling malware gives attackers distinct advantages, said Dan Hubbard, vice president of security research at Websense. "It's a great vector, because they don't need to drive users to the sites, they get free hosting, and [it's] hard to trace ownership," he said.
"The trend has definitely been accelerating," said John Pescatore, an analyst at Gartner Inc. It has become "harder for criminals to do the more traditional kind of phishing attacks."
He noted that hackers have been aided by "the growth in social networking sites and blogs, where security is just not one of the ingredients. Hackers are saying, 'It's easier to put our malware on these sites than to build our own.'"
Pescatore said the growth of Web 2.0 technologies and mashups "may make this even worse. If I can trick you into mashing up stuff from my sites on yours, then I can put malicious code in your mashups."
He suggested that users install what Gartner calls "Web security gateways," the URL-blocking tools available from security companies. "We're also telling them to turn on the inbound Web filtering that detects malicious code," Pescatore added.
Read more about Security in Computerworld's Security Topic Center.
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts