Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Mac OS X, BSD Unix top security survey

But it could be that fewer numbers of Macs mean fewer break-ins
 

Sign up to receive Security Resource Alerts

November 2, 2004 (MacWorld) -- London-based security firm Mi2g Ltd. yesterday released a report that says Mac OS X and BSD Unix are the "world's safest and most secure 24/7 online computing environments." Linux operating systems offer the worst track record, according to Mi2g, with Windows coming in second.
"More and more smart individuals, government agencies and corporations are shifting towards Apple and BSD environments in 2004," said DK Matai, executive chairman of Mi2g. Matai calls adoption of Mac OS X and BSD Unix "an accelerating paradigm shift" thanks to professionals who "don't have the time to cope with umpteen flavors of Linux or to wait for Microsoft Corp.'s Longhorn when Windows XP has proved to be a stumbling block in some well chronicled instances."
The study analyzed 235,907 break-ins against permanently connected computers around the world between November 2003 and last month. The systems broken into run the gamut from home and small-office machines to small, medium and large corporations -- everything from computers connected to the Internet without the benefit of a firewall to firewall-protected enterprises with dedicated IT staff, intrusion-detection systems and other protective measures in place.
Of the 235,907 successful break-ins researched as part of this study, 65.64%, or 154,846, were made against Linux-based systems. Microsoft Windows computers accounted for 25.19% of all break-ins recorded, while Mac OS X- or BSD-based computers accounted for just 4.82% of all breaches recorded.
Mi2g's study reports that more than 32.7% of digital breaches occurred against what they term "micro entities" -- home-based individuals or other very small-scale operations -- while 58.8% of all breaches were carried out against "small entitles." As the companies grew larger, security definitely increased -- 6.1% of all such breaches were made against medium-size businesses, and only 2.5% were made against large entities, including big businesses, government agencies and nongovernment organizations.
Mac OS X and BSD Unix represent a smaller installed base of computers than Windows or, by some estimates, Linux machines. This has led to what some security experts and industry pundits call "security through obscurity": Because there are fewer Macs, fewer hackers will try to exploit them, since they aren't as familiar with the operating system and their efforts are less likely to have a widespread impact.
Mi2g made no attempt to weigh in on this issue.
The company estimates that worldwide economic damage in 2004 from these intrusions at between $103 and $126 billion.
Mi2g also concluded that environments running Mac OS X, as well as BSD Unix and Linux, have not experienced "any significant economic damage" from malware attacks such as viruses, worms and Trojan horses.
"Windows has become the most breached computing environment in theworld, accounting for most of the productivity losses associated with malware ... proliferation. This is directly the result of very insignificant quantities of highly damaging mass-spreading malware being written for other computing environments like Linux, BSD and Mac OS X," said the report.
The company estimates that malware will cost organizations and individuals another $166 billion to $202 billion in 2004, including support costs, loss of business, bandwidth clogging and other costs.


Reprinted with permission from

For more Macintosh news, visit MacWorld.com.
Story copyright 2006 Mac Publishing, LLC. All rights reserved.


Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"The recent attacks in Mumbai were carried out by assailants using high tech methods. It’s just another way in which..." Read more...
Read more Security posts or See all Blogs
Virtually every Windows PC at risk, says Secunia
License server glitch exposes SonicWall users to e-mail security threats
Transmitting data from the middle of nowhere
More top stories...
Moving to a start-up? Fasten your seatbelt
In high-tech schools of the future, Facebook in class is boosted -- not banned
Clues point to Jan. 13 release of Windows 7 beta
Thin as ever, the latest Air offers up to twice the storage and snappy performance.
We've got an array of economical, expensive, and just plain weird tech gifts for your friends and family.
The spam-spewing 'Srizbi' botnet that was shut down two weeks ago has been resurrected and is again under criminal control, say security researchers.
Facebook is popular and growing -- especially with criminals. Here's why they love it.
Get the latest news, reviews and more about Microsoft's newest desktop operating system
Find wage data for 50 IT job titles.
All Zones
Business Continuity Zone
The File Data Management Zone
Security Management Zone
The SAS Zone
Business Intelligence and Analytics Zone
The Enterprise Search Zone
Software as a Service Zone
The Security Zone

Ads by TechWords

See your link here
Moving to Windows Vista: The Promise, The Reality
Moving to Windows Vista: The Promise, The Reality
View this exclusive webcast today!
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Record Capacity for Microsoft® Exchange 2007 With VMware and IBM System x3850 M2
Download this white paper today!
(Source: VMware) The more that e-mail becomes an entrenched IT infrastructure application, the more that messaging administrators face numerous--sometimes conflicting--demands in the categories of availability, flexibility and cost. Employing a virtual solution can help avoid expensive over-provisioning of server computing resources, while improving management and disaster recovery. And ultimately, it can more than double the number of supportable Exchange 2007 users, as compared to a non-virtualized environment. This whitepaper explains how to break down the scalability barrier and respond faster to your mail system needs.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
The Importance of Application Management
Dell Client Migration and Deployment Services
Windows® Enterprise Data Protection with Symantec Backup Exec"
View more whitepapers 


Webcast: The Automation of IT Compliance Programs: Reducing Risk, Cost and Complexity of Corporate Compliance
To meet the growing number of industry and federal regulations, businesses spend significant time, effort, and budget determining how to best meet continuously evolving IT compliance requirements this new Forrester Research and Juniper Networks Webcast led by industry experts who examine global IT security and compliance trends, common IT compliance issues and challenges, and best practices for successful IT compliance programs.

View this webcast 
Whitepaper: Tackling the Top Five Network Access Control Challenges
The major challenge enterprises face today is how to create innovative business models and to increase productivity by opening the network to a dynamic workforce, while at the same time protecting critical assets from the vulnerabilities that openness and user mobility bring. In addition, to comply with industry and governmental regulations, enterprises must prove that they have stringent controls in place to restrict access to sensitive data. This paper describes the top five networking access control challenges that companies like yours are facing and solutions that they are deploying today.

Download this white paper 
Whitepaper: Addressing PCI Compliance with a Comprehensive Network Access Control Solution
The Payment Card Industry (PCI) is one of the most comprehensive data security standards in a cluster of regulations that have emerged over the past decade. Meeting its requirements is both complicated and expensive for many companies. Learn how a comprehensive access control solution allows retailers and consumer organizations adhere to the core tenets of PCI, and delivering the necessary information and reports needed for compliance audits.
Download this white paper 
Whitepaper: Control System Cyber Vulnerabilities and Mitigation of Risk for Utilities
Today's global industrial infrastructure includes thousands of electric utilities, water/wastewater management companies, oil and gas suppliers, chemical manufacturers and other facilities critical to daily functioning. Learn why relying on off-the-shelf operating systems and Internet-based remote access control to carry out production tasks, traditional control networks can leave today's global industrial infrastructures vulnerable to hackers, extortionists, worms, viruses and application-level attacks. Deploying network-based security can protect these at-risk systems–without requiring infrastructure replacement.
Download this white paper