Search 
You are here: ArticlesIn Focus   
ArticlesMinimize
IN FOCUS: Symantec's New Internet Security Threat Report
Posted by SteveT on Thursday, March 29, 2007 :: Last Updated on Sunday, January 20, 2008:: Views 2822

   

by Mark Joseph Edwards, News Editor, mark at ntsecurity / net

Security vendors often release reports based on their perspective of  current and future Internet-related security threats. The reports are useful in learning what the vendor sees, which in turn can lead you to your own widened perspective on potential problems.

Symantec recently released "Internet Security Threat Report, Trends for July-December 2006." While the report is based on historical data, it does lend some insight into the future.

The company said it bases its findings on a network of more than 40,000 sensors in more than 180 countries, more than 2 million decoy email accounts, and information collected from its BugTraq mailing list. Some interesting highlights from the report include the discovery that of all the attacks that affected Web browsers, approximately 77 percent were aimed at Microsoft Internet Explorer (IE). Ninety-three percent of all attacks were aimed at home users.

Another interesting data point is that Symantec tracked over 5,200 Denial of Service (DoS) attacks per day. That's a lot! Interestingly enough, the company said that figure dropped from last year when it tracked more than 6,100 DoS attacks per day.

The company also documented more than 2,500 vulnerabilities; 66 percent of them were related to Web applications, and 79 percent were "easily exploitable."

Another interesting set of points are patch turnaround times for OSs.  Symantec measured five vendors: Microsoft, Sun Microsystems, Apple, HP, and Red Hat. Of those five companies, Symantec found that Microsoft had the fastest average turnaround time overall, Red Hat was second, HP was third, Apple was fourth, and Sun was fifth.

The number of vulnerabilities measured for each vendor varied as did the response time, when comparing the second half of 2006 with the first half. For example, HP's average response time in the first half of 2006 was 53 days for the seven vulnerabilities the company disclosed. In the second half of 2006, HP's number of disclosed vulnerabilities increased to 98 and the company's average response time increased to 101 days.

Even though we'll most likely see fewer vulnerabilities in Vista than we do in previous Windows platforms, I expect Microsoft's average vulnerability response time will remain steady since it uses a monthly patch release schedule.

Vista will no doubt affect the future reports of most any Windows-based security vendor--Symantec certainly included. The report predicts that third-party software developers could become the source of a significant percentage of attacks against the OS.

That's just the tip of the iceberg of the information in Symantec's  104-page report. Other information includes trends regarding specific types of attacks, what future trends might be, and a lot of detail about some of the topics I covered briefly here. If you're interested in reading the entire report, you can get a copy in PDF format at the URL below:

   http://list.windowsitpro.com/t?ctl=4FC12:E0792EBBCDE7A61A435D3A90B127C8E8

Previous Page | Next Page

COMMENTS


DonationsMinimize

Find our site useful? Make a donation to show your support

Donate

logo_ccMC.giflogo_ccVisa.giflogo_ccDiscover.giflogo_ccAmex.gif

ArGoStuff Supporters

 


News from ArGoSoftMinimize
1 2 3 4 5 6


Mail Server v1.0.8.3
  • Added support of STARTTLS (STLS) command for SMTP, POP3, IMAP, and SMTP relay and delivery, which will allow secure, fully encrypted connections, when possible;
11/6/2011 1:10:34 PM
Mail Server v1.0.8.2
  • Optimized delivery speed. In earlier versions each "tick" which was checking whether messages were in the outbox queue, was picking up only one message at a time. Now it will attempt to pick MaximumAllowedThreads-ActiveDelivery threads messages, which should considerably increase deliver speed;
  • Optimized SEARCH and STATUS IMAP commands. They appear to be used very extensively by Android, and (not that extensively, but still) by iPhone. Now users who use mobile phones to access their IMAP accounts will see considerable improvement;
  • Optimized STORE IMAP command. Before storing of IMAP flags was occuring one message at a time, which seemed to be fine with SQL server, but proved to be slow for SQLite... Now it happens with single SQL call.
10/8/2011 7:59:35 PM
ArGoSoft Mail Server v1.0.8.1
  • Fixed a bug: when using IMAP via Firefox with "When I delete a message, move it to Trash folder" option, marking messages in the trash folder was causing high CPU usage, and was taking some time, making the server pretty much non-responsive. The problem was happening only when using SQLite.
6/6/2011 9:33:36 PM
ArGoSoft Mail Server v1.0.8.0
  • Fixed a problem with web interface - was showing only first page of messages, and would not switch to other pages; In order to fix the web interface, mail server itself has to be updated;
  • When installint initially, was still using SQLite, even when SQL was requested;
  • There was a problem with switching from SQLite database engine to SQL server database engine: the SQL database was not being created;
5/23/2011 5:53:55 PM
ArGoSoft Mail Server .NET v1.0.7.9
  • The server no longer requires Microsoft SQL Server. If SQL server is not found, it will use SQLite engine, which does not require separate installation. If SQL server is found, then user will be prompted whether he wants to use it;
  • Made other improvements, such as, now mailbox rebuild indexes orphaned records, rather then deleting them, also added an opotion to increment UIDL validity of folder (both on the Mailbox viewer box);
  • Made minor improvements on web interface;
4/26/2011 9:47:25 PM


1 2 3 4 5 6

Protect Your Computer today withGet AVG Today


Home:ArGoStuff:Forums:Articles:Cyber Security Tips:FAQ:Downloads:Links
Copyright 2006-2011 by ArGoStuff Terms Of UsePrivacy Statement