McAfee: Threats get small
The days of the mega-outbreak are over as financial motives rule
Computerworld New Zealand - The days of big virus outbreaks like MyDoom, Melissa and SQL Slammer are gone, said Joe Telafici, director of operations for McAfee Inc.'s Avert Labs.
Telafici was speaking at the recent AVAR (Association of Antivirus Asia Researchers) conference, which was held in Auckland. Today's cyber criminals don’t want to draw attention to themselves as the main motivation for cybercrime now is money, not fame, he said.
They are "clearly getting more devious," he said, but law enforcement cooperation across borders is also getting more efficient.
Telafici’s team of around 100 security experts in 16 countries builds McAfee’s security content. But they also educate and cooperate with law enforcement.
At the end of last month, McAfee Avert Labs made 10 security threat predictions for 2007. They are:
- The use of bots, computer programs that perform automated tasks, will increase. Botnetworks will also increase, but there will be a move away from internet relay chat (IRC) towards less obtrusive instant messaging and peer-to-peer communication, said Telafici.
- The number of rootkits on 32-bit platforms will increase, but protection and remediation capabilities will increase too. Telafici said that rootkits are becoming a de facto standard in malicious programs and that they will increase over the next couple of years.
- Vulnerabilities will continue to cause concern, fuelled by the underground market for them. McAfee Avert Labs thinks the number of vulnerabilities will grow because of the increased use of fuzzers -- automated tools and technologies that allow for large-scale testing of applications -- and "bounty programs" that reward researchers for finding vulnerabilities. McAfee is not involved in any such initiatives, said Telafici.
This year, Microsoft Corp. has already announced 140 vulnerabilities, compared with 62 in 2004 and 2005 combined, said McAfee. Also, zero-day attacks are being released soon after "Patch Tuesday" to get the most out of the vulnerability’s window of opportunity, said the company. - Identity theft and data loss will continue to be issues --computer theft, loss of backups and compromised information systems are at the result of these crimes. According to the U.S. Federal Trade Commission, 10 million Americans are victims of identity fraud each year, said Telafici.
- The number of password-stealing Web sites will increase, using fake sign-in pages for popular online services such as eBay.
- The volume of spam, particularly bandwidth-eating image spam, will continue to increase.
- The popularity of video-sharing on the Web makes it inevitable that hackers will target MPEG files as a way of distributing malicious code.
- Mobile-phone attacks will become more prevalent as mobile devices become "smarter" and more connected.
- Adware will go mainstream, following the increase in commercial Potentially Unwanted Programs (PUPs).
- Parasitic malware that modifies existing files on a disk will make a comeback.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Protection for Every Enterprise: How BlackBerry 10 Security Works Get an IT-level review of BlackBerry® 10 Security, addressing data leakage protection, certified encryption, containerization and much more.
- A Comprehensive Strategy to Leverage Mobile A successful mobile strategy begins with a common platform for integrating and managing mobile devices and the corporate assets that are stored on...
- IDC - SAP Enterprise Mobility: Bringing a Cohesive Approach to a Complex Market This IDC white paper discusses key mobility trends and examines how SAP's mobile enterprise solutions map to meet organization's mobile requirements.
- The App Happy Enterprise This Computerworld playbook explores key aspects of the enterprise mobile revolution and provides a set of step-by-step directions on how to productively manage...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts