User-Agent: *
Allow: /

Custom Search
Tampilkan postingan dengan label Networking. Tampilkan semua postingan
Tampilkan postingan dengan label Networking. Tampilkan semua postingan

Kamis, 08 Januari 2009

Top 10 security predictions for 2009 Part. 2

By Asavin Wattanajantra

More legitimate website hacking

It arose as a big problem in 2008 and is sure to continue next year, as criminals realise that hacking a legitimate website is a great way to persuade users to click and downloads malicious files.

Many users are still unfamiliar with web-based malware and 2009 could a boom year as cybercriminals look to capitalise on this ignorance. It is a very recent evolution to exploit flaws in browsers and web servers, and new toolkits are now constantly being made to take advantage.


The fact that these toolkits often don’t need users to have a great technical knowledge lowers the barrier for entry for cybercriminals and pushes the threat level even higher than before.

Unemployment creates more cybercriminals

The credit crunch will affect the security landscape in a number of ways. One of the scariest prospects is that the economic downturn will make it tempting for unemployed IT workers to use their technical knowledge to commit internet crime.

It’s a very lucrative business - and as mentioned before - the growth of malware-as-a-service will make it very easy for people to make money on the web, even if they lack the right technical knowledge.

It could also be a problem in developing countries, as the lack of IT jobs could force qualified and skilled technical workers into the arms of criminal gangs, who will exploit their skills in aid of making money over the web.

Security budgets unlikely to grow

Although the threats keep multiplying, most would agree that in the current economic climate, budgets are unlikely to grow significantly.

This means that there will be more consolidation in the security field and means that instead of multiple boxes carrying out single functions, it will be consolidated into single boxes.

In 2008 this has already been happening, but with budgetary pressures there is no doubt this will accelerate.

It will also be interesting to see how the new focus on data security will affect the way businesses work, and whether there will be a change of focus in security to securing the data, rather than protecting the network.

Mobile computing hacks

The growth in popularity of smartphones will make them a bigger target to criminals as they will not have the security protection that PCs have had for years.

Applications and associated data will be accessed from anywhere and make them a big target for hackers. IT administrators need to be on their guard as these threats will have multiple points of entry, targeting different devices and applications.

This is made even more important by the fact that the use of mobile internet will have increased significantly by the end of 2009.

The value of the data that new sophisticated phones will carry will mean that subscribers will expect mobile operators to take greater security measures to protect personal data, especially when mobile commerce takes off.

The new generation of botnets

At the end of 2008 many of the biggest botnets were taken down with the closing of the McColo server. MessageLabs predicted that these will find new hosting services in countries such as Russia or China, improving botnet technology.

A particular sophisticated type of botnet that was described takes the form of hypervisor technology, with malware existing as a virtualisation layer running directly on the hardware and incorporating key operating system calls.

The “real” operating system remains unaware of the existence of underlying malware controlling the computer. Particularly technical attacks like SQL injection and cross-site scripting will also continue, and become more commonplace in 2009.

Cyber hacking on virtual worlds

Like social networking, hackers are likely to move away from the traditional forms of email spamming and move towards the potential goldmine of virtual worlds.

This could be gaming universes like World of Warcraft, or more social reality-based worlds like Second Life, where stolen virtual goods could be sold for real hard cash.

Users are often more relaxed about their personal details in online worlds, and this means that there could be a good opportunity for criminals to create technology which steal this data.

The increasing use of virtual worlds by businesses will also be a factor, as the value of data that these worlds will carry may grow significantly. This will make it more profitable, and therefore attract more criminals.

Reputation hijacking flourishes

The vulnerability in the design of the Domain Name System (DNS) found by Dan Kaminsky could in theory poison a server’s cache causing people sending emails or requesting a website to be given the wrong IP address.

This could mean victims are sent to a fake website which is looking for personal details, but looks perfectly real. If organised gangs manage to exploit this DNS vulnerability it could mean a whole different set of problems in 2009.

There was a multi-vendor patch deployed in August to protect servers from attack, but it has been made clear that the vulnerability had only been slowed down – not eliminated.

source : www.itpro.co.uk

Read More...

Top 10 security predictions for 2009 Part. 1

What will next year hold in the ever-changing world of IT security?

By Asavin Wattanajantra, 6 Jan 2009 at 18:05

New tech means new ways for criminals to attack systems. Next year will see hackers get smart about cloud computing, social networking and more. Here's our top ten threats to keep an eye on...

Malware 2.0

Malware will increasingly target Web 2.0 as well as cloud services. New cloud-based services - such as Amazon Web Services and Microsoft Azure - are vulnerable new targets for cybercriminals or spammers.



The cloud could be used simply to send spam, but it also could launch sophisticated attacks such as hosting malicious code for downloads.

Web 2.0 has also created an environment where malware can change depending on an event or a situation. Separate harmless bits of malware can be constructed to combine and maliciously attack.

A good example of this is with mash-ups, where data from many websites can be reconstructed to create something malicious.

Malware-as-a-service becomes more common, which will allow automated malware to be bought and sold to order. This will be a big problem, as it lowers the technical level needed for criminals to become online fraudsters.

An explosion in new malware variants and web threats

Anti-virus vendor Symantec claims that new strains of malware consisting of millions of distinct threats can propagate as a single, core piece of malware. This will create a number of unique malware instances.

Indeed, research has shown we have now reached an inflection point where we are now more malicious programs than legitimate ones. Businesses and vendors need to move away from signatures and concentrate on detection methods, such as the reputation-based approach.

As web services keep increasing, and as browsers start to move towards a uniform standard for scripting language, expect new web-based threats.

Social networking spam

As the year went on, criminals were gradually moving from email-based spam to different techniques. One of these was social networking spam, where websites such as Facebook and MySpace were targeted.

Personal information is gold to the bad guys, and they will learn better tricks to persuade users to give away their details and find ways to access private accounts.

The rise in popularity of social networking sites that allow user-generated content will be a problem. Web spam will increase as will malicious posting into user-forums and blogs.

Security firm Websense claims that new web attack toolkits have emerged that allows attackers to discover posts and/or have vulnerabilities. Bots may also add more HTTP post functionality among their many capabilities.

source : www.itpro.co.uk

Read More...

Top 10 mobile features of 2009 Part. 2

By Clare Hopping

HSDPA

Although some handsets still don’t feature 3G yet, it’s something that will certainly grow in the next 12 months. As people start to use web browsing more and more on their handsets (even if just for Facebook), speed will become a big issue. By the end of 2009, HSDPA will be the preferred data connection for all manufacturers.

Location-based services

With GPS integrated into phones now becoming an expectation rather than a useful added extra, software companies will build on this with an influx of possibilities. Mobile turn-by-turn navigation will stamp out the paid for software, and you’ll be able to find any point of interest on a map and then call it direct from your mobile. Take a look at Nokia’s new improved Nokia Maps for just a hint of things to come.





NFC

After successful mobile phone-based near-field communication (NFC) trials in 2008 for making payments and accessing public transport, it’s quite likely we’ll see the first widely available device with integrated NFC towards the end of this year.

Social networking

Social networking is becoming huge on the PC, so this will be a trend for mobile in 2009. Handsets including BlackBerrys ship with a Facebook app preinstalled so it’s no surprise manufacturers are already creating social-networking based devices such as the INQ1 from 3. Expect more collaboration in this area with the likes of Twitter, MySpace and Facebook.

Touch screens

With BlackBerry introducing the ‘click touch screen’ on the Storm, we are going to see more technologies this year that change the way we use touch screens. Companies are likely to use more multi-touch capabilities as seen on the iPhone and LG KC910 Renoir, and there will probably be a lot more touch display devices coming out too.

Source : www.itpro.co.uk

Read More...

Rabu, 03 Desember 2008

Visits to the laboratory F-Secure in the Streets

The view from close analysis of the virus
On 10 July 2008 and CHIP opportunity to see FSecure laboratory in Kuala Lumpur. What is there? Seoul following. Andi Desmal
Before entering the laboratory area, it Heinonen, Vice President FSecure for Asia Pasiik, provide a brief explanation about FSecure have 20 years to handle the virus in the world. Currently, FSecure already has 15 offices in 15 countries and three laboratories in the world. In addition, in Malaysia, two other laboratories in the United States and Finland. According to it, until now, the focus FSecure still analyzing the virus and various other gadfly to the end user because the virus type is the most Internet users in the world.
There are many things that have been done FSecure security services to the Internet in the next 20 years. Even since 2000, FSecure not only to focus on handling the virus only a PC, but also in the mobile phone virus.
Laboratory
In the laboratory security FSecure this, FSecure monitor the development of the virus in the world. In the activities, not less than 70,000 examples of the virus viruses into the lab. Around 2,000 species can be directly detected. For other types, FSecure will analyze further. The results of this analysis will be out in the form of updates in the seven to nine days. Watched the development of this virus by FSecure through various ways, such as user reports FSecure own that send virus samples, special radar, Google maps, and the International beritaberita discuss Internet security issues. According to Wing Fei Chia, Security Response Team Manager FSecure Security Labs, the creator of the virus at this time to focus more money. Viruses are expected to steal the data of various important information from users of the Internet. These data will be used to dredge sebanyakbanyaknya money from the victims. " Targettarget the virus of course, from individuals, organizations, governments, to a social networking service users. Therefore, analysts and antivirus always work the maximum to prevent widespread virus.
In laboratory security FC this, the staff FSecure also observe the development of viruses for mobile phones. Smartphones become the target of frequent diincar by the virus because it has a system in operation. To examine this mobile phone virus, FSecure utilize a special room, which also is in the laboratory. In this space, the security level of a handheld communication device can be analyzed. The researchers mengotakatik free of the virus in this space without having to worry that the virus will contaminate other ponselponsel outside the special room. CHIP also see some of the phone when tested in the room. Some mobile phone began to open. The phone has not had a virus protector will be contaminated with the virus when switched bluetooth facilities. According to Chia Wing Fei, the development of features in the communication devices that encourage the virus tries to log into the device. Moreover, now there are no restrictions in the mobile phone. Phone not only can be used for communication only. Users can now be used for various activities, ranging from games to financial transactions in the bank.

Source: Ed Chip Magazine. 08/2008

Read More...
free counters