ThreatFire Research Blog Home
 
 
« Sunbelt IeDefender/zoey zane find still up and running
Current quicktime and client side exploits »

Sans Top 20 for 2007

The Sans Institute, a source of information security training, certification and research, released their Top 20 list — security risks for 2007. They release this Top 20 annually, it’s a popular read for security professionals and enthusiasts.

Not surprisingly, they noticed that operating system targets are not attacked by massively propagating worms anymore. They note that “Operating systems have fewer vulnerabilities that can lead to massive Internet worms…There have not been any new large-scale worms targeting Windows services since 2005.”
I think that the vulnerabilities are still present in XP. They just are not researched or attacked as much anymore.
One might also notice that the decrease in the presence of network worms coincided with a major sea of change in the OS marketplace: the introduction and rampup of Windows systems running a host-based firewall. In late 2004, XP SP2 users were treated to a host based firewall that finally was delivered and enabled by default. Users also started looking for better host based firewalls once they understood what host based fw really were. Accordingly, the Sassers and Zotobs of the internet had no easy in. By the end of 2005, it just wasn’t all that fruitful to try to remotely attack Windows services that were now closed off from the internet cloud. The activity did not stop, however, it just took a turn.

Reading through the list or press release, you might also notice a corresponding rise in methods attackers use to evade the Windows host based firewalls: “We have seen significant growth in the number of client-side vulnerabilities, including vulnerabilities in browsers, in office software, in media players and in other desktop applications. These vulnerabilities are being discovered on multiple operating systems and are being massively exploited in the wild, often to drive recruitment for botnets.”
This arena of research has received the most attention, because these attacks are now the easiest to deliver.

Overall, it’s an interesting read. Enjoy!

This entry was posted on Tuesday, December 4th, 2007 at 3:40 pm and is filed under Book/Doc review, Bot, Vulnerability, Worm. You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • Koobface on Yuotube
    • Spamvertizing Social Networks and Why Legitimate Money Will Help Clean Them Up
    • Zbot: Not Your Typical Malware
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • AV-Comparatives weblog
    • Bill Mullins’ Weblog – Tech Thoughts
    • Security Response Blogs
    • Swatkat’s rants
    • ThreatExpert Blog
  • Links

    • AMTSO
    • AV-Test
    • Frank Boldewin’s Reconstructor
    • PC Tools
    • ThreatExpert
    • ThreatFire
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).