Skip the navigation
News

Verizon: Data breaches often caused by configuration errors

By Jeremy Kirk
July 29, 2010 08:14 AM ET

IDG News Service - Hackers appear to be increasingly counting on configuration problems and programming errors rather than software vulnerabilities in order to steal information from computer systems, according to a new study from Verizon.

Verizon issues an annual report on data breaches, but this year had access to statistics related to investigations done by the U.S. Secret Service, which the company said broadened the scope of its analysis. For 2009, that covered 141 cases involving 143 million records.

Verizon said it found that a surprising and "even shocking" trend is continuing: There are fewer attacks that focus on a software vulnerabilities than attacks that focus on configuration weaknesses or sloppy coding of an application.

In 2009, there was not a "single confirmed intrusion that exploited a patchable vulnerability," the report said. The finding has caused Verizon to question whether patching regimes -- while important -- need to be done more efficiently given the trend in how attacks are occurring.

"We've observed companies that were hell-bent on getting patch x deployed by week's end but hadn't even glanced at their log files in months," the report said. "This kind of balance isn't healthy. Therefore, we continue to maintain that patching strategies should focus on coverage and consistency rather than raw speed."

In other findings, some 97 percent of the malicious software found to have stolen data in 2009 was customized in some way. For example, the malware was tweaked to evade detection by security software or new features were added, such as encryption for stolen information. That doesn't bode well for companies, Verizon said.

"As a defender, it's hard not to get a little discouraged when examining data about malware," the report said. "The attackers seem to be improving in all areas: getting it on the system, making it do what they want, remaining undetected, continually adapting and evolving, and scoring big for all the above."

Organized criminal gangs proved to be a major force in data breaches, pooling their resources and expertise together in credit-card data scams and others. While it can be difficult to find out exactly the source of attacks since hackers often hide their tracks, working via remote computers that they've taken over, investigators and law enforcement agencies still have a rough idea of where the hackers are operating from by using other information.

"Most organized criminal groups hail from East Europe, while unidentified and unaffiliated persons are often from East Asia," the report said.

Send news tips and comments to jeremy_kirk@idg.com

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.

Verizon Business

Additional Resources
Advancing Knowledge Sharing with Google: The LSNC Story
WEBCAST
In the modern work environment, knowledge sharing has become paramount to organizational success, given the geographic dispersion, mobility, and information overload. During this session, Legal Services of Northern California (LSNC) will discuss their recent knowledge sharing transformation. With employees across 14 offices, servicing one-third of California, and having to access information across a million documents, the challenge was daunting. To address this, LSNC tapped Google's expertise on enterprise search and cloud computing, and deployed a knowledge-content system.
Cost-Effective Virtualization Security
WHITE PAPER
Trend Micro(tm) Virtualization Security solutions deliver advanced security software to protect operating systems, applications and data on virtual and cloud servers to help ensure compliance, while allowing higher server consolidation rates, and maximizing performance and operational flexibility. With Trend Micro software deployed on your physical servers and virtual machines, your IT infrastructure receives comprehensive and integrated protection.
The Laptop Dilemma: How to Maximize Productivity and Lower the Burden on IT
WHITE PAPER
New era of mobile computing creates opportunities for remote productivity while next-generation, industry-standard technologies address management and data security. Read more in this white paper.
What People Are Saying
Network Security White Papers
Secure and Managed File Transfer in the Era of Regulatory Compliance
Getting the right information to the right people, quickly and securely, is the key strategy for business success. File transfer as a business...
Creating Your File Transfer Shopping List: Mapping Business Requirements to Technical Capabilities
Although many managed file transfer solutions are similar in basic capabilities, each solution offers unique features that, depending on your needs, may be...
Common File Transfer Myths--Debunked
Misconceptions and bad assumptions related to file transfer are common. This paper will bust some of these myths by examining common misunderstandings, explaining...
How to Tell if You Need Secure, Managed File Transfer
If your organization is like most, you probably move more than a few files from place to place. With all this data flying...
Five Network Security Threats and How to Protect Your Business
Threats abound in today's corporate networks. Keeping your enterprise and its assets secure requires a proactive security strategy. Discover the five most costly...
All Network Security White Papers
Network Security Webcasts
The Evolution of Managed File Transfer
Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
Desktop virtualization keys innovation drive
View now.
Guiding iPhone into the business world
Watch now.
Radical virtualization brings new benefits to...
Watch now.
Virtualization @ the speed of business
Watch now.
All Network Security Webcasts
IT Jobs