Tuesday, October 21, 2008
Human error and hardware theft are the two main causes of data breaches
By Kathryn Small
21 October 2008 05:00PM
Human error and hardware theft are the two main causes of data breaches, according to Symantec’s recent survey into Data Loss Prevention.
The global security, storage and systems management company surveyed 156 Australian companies with 100 or more employees. Results were sent in from IT managers and C-level executives. The majority of respondents represented businesses with a financial turnover of $10-$500 million.
The survey’s headline result is that 79 per cent of respondents have experienced some form of data breach, and 40 per cent have experienced anywhere from six to 20 known data breaches in the past five years.
Further, 59 per cent of respondents suspect that they have experienced undetected data breaches, with many considering it “impossible” to catch every attempted breach.
Respondents lost different kinds of data, including customer records (55 per cent); employee records (48 per cent); intellectual property (43 per cent); commercially sensitive information (35 per cent); bank and credit card details (21 per cent) and financial information (20 per cent).
Lost or stolen laptops were the top cause of data breaches, at 45 per cent. “Respondents estimated that the average cost of a data breach was the same as replacing a lost laptop,” said Steve Martin, Mid Market Manager Pacific. “But I believe that’s too low, since it doesn’t take into account the potential value of the data.”
Lost mobile phones or portable devices also weighed in at 30 per cent. “A phone is the easiest thing to lose, and the easiest thing to steal,” said Martin. “Whenever I ask groups if they have email access on their phones, and whether their phone is password protected, the second number is always very low.”
The other key cause of data breaches was accidental human error (42 per cent). Craig Scroggie, VP and MD Pacific, cited the case of a restaurant which accidentally emailed 3,500 customers a copy of their client database, containing names, addresses and dates of birth.
Malicious attacks included hacked systems (29 per cent), malicious insiders (28 per cent), paper records being smuggled out of an organisation (26 per cent) and malicious code infiltrating systems (24 per cent).
“Today’s organisations have no walls and information can be anywhere, so securing the perimeter is no longer adequate. Additionally, many organisations believe that confidential information is most at risk from malicious acts when employees are mobile and not connected to the corporate network,” said Scroggie.
Among intentional security breaches of company secrets or intellectual property, 77 per cent said that data was copied to removable storage devices, and 51 per cent said that printed paper records were removed from the premises.
Other methods of moving stolen data included email or instant messaging (41 per cent), posting to public websites (26 per cent) and copying or photographing confidential data onto mobile phones or PDAs (21 per cent).
Scroggie emphasised that Data Loss Prevention required a holistic approach to protect customers, brands and intellectual property.
“We can stop these problems today,” said Scroggie. “We have the ability to discover, monitor and protect confidential data.”
Tuesday, October 7, 2008
PC Tools to be poor man's Norton
28 August 2008 04:16 PM
Computer security giant Symantec said it would not integrate the software of recent acquisition PC Tools into its mainstream Norton suite, instead using the products as its low-cost option for countries such as India and China.
"The goal right now is to look at emerging markets. We'd like to see PC Tools take emerging markets — countries like Brazil, Russia, India, China," said Symantec's VP of consumer engineering, Rowan Trollope.
"They have been very successful at selling to a very specific segment of the market place that is more interested in lower price solutions."
The Australian security vendor is reported to have cost Symantec AU$300 million, and according to Trollope, gives it an avenue to target these countries without needing to drop its prices for Norton.
Asia Pacific is Symantec's fastest growing region, however, it generates the least revenue of its global operations, netting the company US$231 million, or about 14 per cent, of its total revenues for Symantec's first quarter 2009 earnings.
"I think price is an important component of the offering you bring to an emerging market. Some require lower prices, some accept higher prices, but with India and China in particular, you have to go in with lower prices," the executive told ZDNet.com.au.
While Norton Antivirus 2008 costs AU$59.00, and its Internet Security suite costs AU$99.00, PC Tools' equivalents respectively cost AU$49.95 and AU$79.95.
At the time of the acquisition, technology analysts at Gartner and Intelligent Business Research Services struggled to explain why Symantec would buy PC Tools, which had similar products to its own and added just 200 staff to Symantec's ranks of 17,000.
Trollope said that PC Tools did offer it some new technologies. Registry Mechanic, PC Tools Utility Suite, Threat Fire, and Browser Defender are considered "complementary" to Symantec's products.
While Symantec planned to run PC Tools as a "completely independent company", he said some products would be assessed for overlaps with Symantec's existing products.
"[PC Tools] have Spyware Doctor and they've got some other products that are similar to our products where we will be certainly interested in looking at how do they overlap and who provides which service," he said.
Trollope declined to confirm whether it had paid AU$300 million for PC Tools.
----------------------------------
Symantec have acquired PC Tools because of Threatfire engine (formerly Cyberhawk, Zero-day behavior based anti-malware) and ThreatExpert (PC Tools's sandbox automation tool for threat analysis).
Furthermore, because AV market is increasingly becoming competitive and narrower, it’s very important to acquired competitors to stay competitive in the market place.
Both Symantec, McAfee and Trend Micro have been acquiring third party anti-malware and security product vendors in order to acquire newly developed technology or destroy possible competitors, it’s usual Art of War strategy in ever competitive business world.
Monday, October 6, 2008
Single Trojan accounts for 60 per cent of September attacks
A single family of Trojans has accounted for over 60 per cent of malware infections in September, according to Fortinet. The RogueSecurity Trojan and its variants accounted for 61.5 per cent of all malware attacks in September the company claims. The Trojan and its varients took the top four positions of the company’s malware list.“Not since the start of this year when the notorious Storm virus made a continuous run of devastating attacks has any comparison been seen with this level of activity,” said the company.“However where the Rogue security applications excel is the accumulated volume: maintaining these extreme levels of activity for at least six days, not to mention the other variants. “The bulk of malware activity occurred in the second and third week of the month, with the W32/Inject.GZW!tr.bdr Trojan peaking at nearly two million in the middle of the month.
Virustotal report from two samples:
Sample 1 Sample 2
This is usual Fakealert trojan that have capability to inject it's own dll process to any executable (PE) files that alerts users being danger of "new bogus" infection or actually telling user that their PC is compromised and buy their Anti-virus or Anti-Spy product.
Tuesday, August 19, 2008
Symantec acquires Sydney's PC Tools
Mahesh Sharma | August 19, 2008
SYMANTEC has bolstered its consumer product portfolio with the acquisition of Australian security software developer PC Tools.
The value of the deal wasn’t disclosed. It is expected to be finalised by the end of the year.
PC Tools is headquartered in Sydney, with offices in US, Britain, Ireland and Ukraine. Symantec said the acquisition expands its reach in emerging regional markets.
PC Tools has over 200 staff globally and will remain a separate entity in the security giant’s consumer business.
Chief executive Simon Clausen will report to Symantec’s group president of consumer products, Janice Chaffin.
Symantec will not rebrand PC Tools’ products and will maintain existing partners and channels.
PC Tools also recently released anti-virus software to protect the Mac OS X operating system.
Tuesday, August 5, 2008
Vista Service Pack 1 isn't actually SP1
It appears that Microsoft's woes with Vista aren't quite over yet. According to the company's official Windows Vista blog, a bug in the SP1 update is the latest in a mounting load of blunders.
A number of users reported problems resulting from the service pack prerequisite KB937287. After receiving reports of the error, Nick White, Microsoft's Product Manager, quickly responded by notifying customers that a decision has been made to "temporarily suspend automatic distribution of the update to avoid further customer impact while we investigate possible causes." Microsoft says that only a small number of users has been effected and that the company is presently working to crack the problem and put the update back online as soon as possible.
Also, if your Vista PC have installed SP1, makesure you have done all the critical Windows Updates upto late June's update. Apparently there are two major critical updates relating to Windows stability and performance issues.Tuesday, April 8, 2008
Trend, Sophos and McAfee flunk Vista SP1 anti-virus tests
That would be a FAIL, then
By John Leyden → More by this author
Published Thursday 3rd April 2008 16:52Â GMT
Article from: http://www.theregister.co.uk/2008/04/03/vista_sp1_av_tests/
Top tier anti-virus vendors including McAfee, Trend Micro, and Sophos all failed to secure Windows Vista SP1 in recent independent tests.
Virus Bulletin, the independent security certification body, said 17 of 37 anti-virus products tested failed to reach the VB100 certification standard. McAfee VirusScan, Trend Micro Internet Security and Sophos Anti-Virus overlooked threats known to be in circulation. Other vendors whose products failed to make the grade included Alwil, BitDefender, Norman, PC Tools, and VirusBuster.
Some of the ignored threats - largely polymorphic file infectors - have been in circulation for months. "It is disappointing to see so many products tripping up over threats that are not even new - computer users should be getting a better service from their anti-virus vendors than this," Virus Bulletin technical consultant John Hawes said.
Products from Symantec, Microsoft (which has problems in the past in previous VB100 tests), AVG, and Kaspersky Lab all passed.
Although still lagging behind Windows XP, Vista is likely to see more widespread use with the introduction of its first service pack, making it more important for anti-virus vendors to deliver dependable protection for the platform. Vista SP1 came out in mid March.
Virus Bulletin's VB100 tests pit each anti-virus product against a set of viruses from the WildList, a publicly available up-to-date list of viruses known to be circulating. To earn VB100 certification, products must be able to detect all the viruses contained in the WildList test set without generating false alarms when scanning a set of clean files.
Unlike other certification schemes, Virus Bulletin tests all products free of charge and does not allow re-testing. Virus Bulletin's comparative reviews also cover detection rates against a selection of zoo viruses (those not seen outside the laboratory), scanning speeds, and computational overheads.
Test results are here (free registration required). ®
Top Spam Botnets Exposed
Srizbi has emerged over the past year as the distributed part of the long-established Reactor Mailerweb-based spam tool. Reactor may have used proxy servers in the past, but at some point a re-write of thesoftware was commissioned by the head of the company, known only as “spm”. The author who did there-write of the backend is a contract programmer living in Smila, Ukraine. It is unclear as to whether ornot he wrote the Srizbi trojan also, but it is a likely possibility.
BobaxEstimated # of bots: 185,000Alternate names: Bobic, Oderoor, Cotmonger, Hacktool.Spammer, KrakenSMTP engine: Template-basedTotal botnet spam-sending capacity: 9 billion spams/dayControl: encrypted, TCP port 447Rootkit-enabled: NoIdentifying strings: cCdipsuxX%, w:\projects\b3\release\core.pdbNotes: Despite reports of its demise, Bobax continues to be a strong player in the spam arena. At onetime, Bobax was solidly in the business of sending mortgage spam, but lately has been seen mailing lowinterestloan spam.
RustockEstimated # of bots: 150,000Alternate names: RKRustok, CostratSMTP engine: Template-basedTotal botnet spam-sending capacity: 30 billion spams/dayControl: HTTP with encryption, TCP port 80Rootkit-enabled: YesIdentifying strings: tmpcode.bin, unluckystrings, filesnamesNotes: Although Rustock started out in the stock spam business, it has branched out, and can currently beseen sending out pharmaceutical spam.
CutwailEstimated # of bots: 125,000Alternate names: Pandex, Mutant (related to: Wigon, Pushdo)SMTP engine: Template-basedTotal botnet spam-sending capacity: 16 billion spams/dayControl: HTTP with encryption, TCP port 4080Rootkit-enabled: YesIdentifying strings: Poshel-ka ti na hui drug averNotes: Cutwail is the most common spambot installed by the Pushdo malware installer system, but it'snot the only one. We've also seen Srizbi, Storm, Xorpix and Rustock installed on the same host togetherwith Pushdo and Cutwail.Canadian Pharmacy spam is one of the things we most commonly see withCutwail, but other types of spam are sent. Sometimes the botnet is used to send social-engineering emailsin order to seed more infected hosts with Cutwail.
StormEstimated # of bots: 85,000 (only 35,000 send email)Alternate names: Nuwar, Peacomm, ZhelatinSMTP engine: Template-basedTotal botnet spam-sending capacity: 3 billion spams/dayControl: HTTP on random ports with base64/zlib encoding, P2P-based server directoryRootkit-enabled: YesIdentifying strings: [blacklist], [peers]Notes: Although Storm has been rumored to be quite large in the past, it has dropped to a morereasonable size. In addition only Storm bots behind NAT firewalls actually send spam. This makes thecapacity of the spam-sending part of the Storm botnet smaller than most of the other lesser-knownbotnets. However, those other hosts don't go to waste, they are used as fast-flux HTTP and DNS hosts forthe spam system. Storm spent a lot of time sending pump-and-dump stock spam in the past, butoccasionally will send pharmaceutical spam and job-offer (phishing mule) emails. When it's notspamming, Storm is sending links to fake greeting card sites which use browser exploits and socialengineeringto infect more users with Storm.
GrumEstimated # of bots: 50,000Alternate names: None known, except for generic/misassignedSMTP engine: Template-basedTotal botnet spam-sending capacity: 2 billion spams/dayControl: HTTP on TCP port 80Rootkit-enabled: YesIdentifying strings: Hi all, Already start, $TO_HEXMAIL, /spm/s_alive, /spm/s_tasksNotes: Although little-known, Grum has accumulated a seizable botnet over the past year by sendingspam with supposed porn URLs which actually point to browser exploiting pages. This botnet usuallysends URLs hidden in non-related HTML, so it may be the botnet referred to by anti-spam vendorMarshal as “HTML”. Ultimately the links lead to Canadian Pharmacy sites.
OneWordSubEstimated # of bots: 40,000Alternate names: UnknownSMTP engine: Template-basedTotal botnet spam-sending capacity: UnknownControl: UnknownRootkit-enabled: UnknownIdentifying strings: UnknownNotes: Although we see a significant amount of spam emanating from this botnet, as of yet the malwarebehind it has yet to be identified. Due to the format of the spam it is sending, we believe this is the samebotnet which anti-spam vendor Marshal refers to as "One Word Sub". This botnet has been seen sendingCanadian Pharmacy spam.
OzdokEstimated # of bots: 35,000Alternate names: Mega-DSMTP engine: Template-basedTotal botnet spam-sending capacity: 10 billion spams/dayControl: encrypted, TCP port 443Rootkit-enabled: NoIdentifying strings: KILL_LAZZY_ON_CONNECT, KILL_LAZZY_MXNotes: Although Ozdok has a relatively small set of bots compared to some of the other botnets listedhere, it is quite capable of pumping out a generous amount of spam, most of it related to enlargementproducts, but designer knock-offs and other spam are frequently seen.
NucryptEstimated # of bots: 20,000Alternate names: Loosky, LockskySMTP engine: Template-basedTotal botnet spam-sending capacity: 5 billion spams/dayControl: HTTP with encryption, TCP port 3133Rootkit-enabled: YesIdentifying strings: 1f34ff45, taskmon.sys, /synctl/updNotes: Relatively small yet capable botnet - may have been evolving for a few years. Last seen sendingCanadian Pharmacy spam.
WoplaEstimated # of bots: 20,000Alternate names: Pokier, SloggerSMTP engine: Template-basedControl: encrypted, TCP port 8080Total botnet spam-sending capacity: 600 million spams/dayRootkit-enabled: YesIdentifying strings: %sxtempx.xxx, %.250s.lzo, ctxlsp.dll, psrip.dat, mailgrab_emails.dat, OEMSO2000Notes: Wopla is frequently installed by drive-by exploits in the same way as Srizbi, Rustock and Cutwail,although it doesn't appear to have been spread as widely. An interesting feature – Wopla can send spamdirect-to-MX or by logging into at least one public webmail service. Bots which send spam throughwebmail providers will probably continue to increase in number, since the spam can evade IP-basedblocklisting, and must rely solely on content-detection (or fingerprinting/anomaly detection at thewebmail provider). Wopla seems to be primarily dedicated to porn spam.
SpamthruEstimated # of bots: 12,000Alternate names: Spam-DComServ, Covesmer, XmilerSMTP engine: Template-basedTotal botnet spam-sending capacity: 350 million spams/dayControl: encrypted, multiple TCP portsRootkit-enabled: NoIdentifying strings: hs5p, XSMTPXNotes: Another botnet which cut its teeth mailing stock spam in 2006 and 2007, nowadays can be seensending pharmaceutical spam.
Other SpambotsIn addition to these bots, there are several other template-based spam botnets, and still many more proxybasedbotnets. Creating network-based fingerprints for proxy botnets is much more difficult, becauseultimately you are fingerprinting the mailer engine, not the bot itself. In the case where the same spamtool might utilize multiple proxy botnets, it would greatly skew the results.One template-based botnet (Warezov/Stration/Opnis) that was a major player six months ago hascompletely dropped off of the radar. Warezov was known for sending Chinese pump-and-dump stockspam. Perhaps it is no coincidence that in the same time frame that we stopped seeing Warezovspam/malware, the notorious spam kingpin Alan Ralsky was arrested and charged (among other things)with sending pump-and-dump stock spam for Chinese companies.
