Verizon: Data breaches often caused by configuration errors
IDG News Service - Hackers appear to be increasingly counting on configuration problems and programming errors rather than software vulnerabilities in order to steal information from computer systems, according to a new study from Verizon.
Verizon issues an annual report on data breaches, but this year had access to statistics related to investigations done by the U.S. Secret Service, which the company said broadened the scope of its analysis. For 2009, that covered 141 cases involving 143 million records.
Verizon said it found that a surprising and "even shocking" trend is continuing: There are fewer attacks that focus on a software vulnerabilities than attacks that focus on configuration weaknesses or sloppy coding of an application.
In 2009, there was not a "single confirmed intrusion that exploited a patchable vulnerability," the report said. The finding has caused Verizon to question whether patching regimes -- while important -- need to be done more efficiently given the trend in how attacks are occurring.
"We've observed companies that were hell-bent on getting patch x deployed by week's end but hadn't even glanced at their log files in months," the report said. "This kind of balance isn't healthy. Therefore, we continue to maintain that patching strategies should focus on coverage and consistency rather than raw speed."
In other findings, some 97 percent of the malicious software found to have stolen data in 2009 was customized in some way. For example, the malware was tweaked to evade detection by security software or new features were added, such as encryption for stolen information. That doesn't bode well for companies, Verizon said.
"As a defender, it's hard not to get a little discouraged when examining data about malware," the report said. "The attackers seem to be improving in all areas: getting it on the system, making it do what they want, remaining undetected, continually adapting and evolving, and scoring big for all the above."
Organized criminal gangs proved to be a major force in data breaches, pooling their resources and expertise together in credit-card data scams and others. While it can be difficult to find out exactly the source of attacks since hackers often hide their tracks, working via remote computers that they've taken over, investigators and law enforcement agencies still have a rough idea of where the hackers are operating from by using other information.
"Most organized criminal groups hail from East Europe, while unidentified and unaffiliated persons are often from East Asia," the report said.
Send news tips and comments to jeremy_kirk@idg.com
Verizon Business

- Secure and Managed File Transfer in the Era of Regulatory Compliance
- Getting the right information to the right people, quickly and securely, is the key strategy for business success. File transfer as a business...
- Creating Your File Transfer Shopping List: Mapping Business Requirements to Technical Capabilities
- Although many managed file transfer solutions are similar in basic capabilities, each solution offers unique features that, depending on your needs, may be...
- Common File Transfer Myths--Debunked
- Misconceptions and bad assumptions related to file transfer are common. This paper will bust some of these myths by examining common misunderstandings, explaining...
- How to Tell if You Need Secure, Managed File Transfer
- If your organization is like most, you probably move more than a few files from place to place. With all this data flying...
- Five Network Security Threats and How to Protect Your Business
- Threats abound in today's corporate networks. Keeping your enterprise and its assets secure requires a proactive security strategy. Discover the five most costly... All Network Security White Papers
- The Evolution of Managed File Transfer
- Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
- Desktop virtualization keys innovation drive
- View now.
- Guiding iPhone into the business world
- Watch now.
- Radical virtualization brings new benefits to...
- Watch now.
- Virtualization @ the speed of business
- Watch now. All Network Security Webcasts