Report finds online attacks shift toward profit

August 2nd, 2005

IBM reported that virus-laden emails and criminal driven security attacks increased by 50 percent in the first half of 2005 - underscored by a significant rise in 'customized' attacks on the government, financial services, manufacturing and healthcare industries.

This substantial increase, along with a decrease in less profitable threats, such as spam and simple computer viruses, indicates a growth in targeted attacks against specific organizations and industries -- apparently created with the purpose of stealing critical data, identities or extorting money.

The Global Business Security Index, a worldwide barometer of security trends collected and analyzed by IBM's Global Security Intelligence team and its partners, indicates that such customized, 'for profit' attacks have been predominantly directed at government agencies, financial services companies, healthcare organizations and large multinational corporations, particularly within the aerospace, petroleum, and manufacturing industries.

According to the report, there were more than 237 million overall security attacks in the first half of the year. The government was the most targeted industry, with more than 54 million attacks, while manufacturing ranked second with 36 million attacks, financial services was third with approximately 34 million, and healthcare was hit with more than 17 million attacks - accounting for more than 137 million of all attacks this year.

IBM has seen a resurgence of targeted phishing attacks for money laundering and identity fraud purposes, believed to be largely driven by criminal gangs that have become more astute in the creation and delivery of such attacks. According to its latest Global Business Security Index, in the first half of the year, there were more than 35 million phishing attacks launched to steal critical data and personal information for financial gains.

Spawns of phishing threats such as 'spear phishing' - highly targeted and coordinated attacks at a specific organization or individual designed to extract critical data - increased more than ten-fold since January of this year alone. Unlike in previous years, when viruses were mainly created and launched to slow down and cripple IT systems, these types of 'customized' attacks have shown their potential to defraud businesses, steal identities and intellectual property and extort money, while damaging the brand and eroding customer trust.

The ratio of spam to legitimate email continuously decreased over the course of the last six months, from 83 percent in January to 67 percent in June 2005, while virus-laden email increased fifty percent over the same period. At first glance what appears to be good news - the leveling off of massive outbreaks that cripple IT environments on a regional or global basis in the past six months - seemingly indicates that hijacking computers to send spam is no longer the network disruption of choice.

Hackers have turned toward more criminal and lucrative areas of directing attacks to specific individuals or organizations, often financially, competitively, politically or socially motivated. IBM's Global Business Security Index shows that in December of 2004, one in every 52 emails was infected by some sort of malicious security threat; by January it was one in every 35 emails, and by June, that ratio increased to one in every 28 emails - signifying a fifty percent increase from last year - a disturbing trend for businesses and consumers alike.

"IBM advises its clients to rapidly adopt a holistic, enterprise-wide approach to security and risk management," said John Lutz, general manager, Financial Services Sector, IBM. "To protect their critical data, infrastructure, brands, and money, IBM advises businesses to rethink how they protect their operations, business processes and governance structures. Companies can employ the latest protective technology, while ensuring that their own customers get highest level of protection available."

Additional key findings from IBM's First Half 2005 Global Business Security Index:

  • Virus-laden emails increase: In January of 2004, 1 in every 129 emails was virus laden; by December 2004, it increased to one in every 51 emails. In January of 2005, the number was one in every 35; by June, the number had grown to one in every 28 emails
  • Phishing gains: 35.7 million emails contained some form of phishing attack; spear phishing directed attacks rose from one of every 56 emails in January, to more than 600,000 in June
  • Spam levels off: Spam consistently decreased from 83 percent of all emails in January to 67 percent of all emails in June 2005
  • Attacks by industry: the government was the most targeted industry with more than 54 million targeted attacks, manufacturing ranked second with almost 36 million attacks recorded, and financial services was third with a little over 34 million**
  • Attacks by location: Over the past six months, the United States was the source of the most attacks with 12 million, followed by New Zealand with 1.2 million, and China with approximately one million; Ireland was last with more than 30,000 attacks
  • Attacks by day: Increased critical security events are seen on Fridays and Sundays
  • Attacks by category: Reconnaissance attacks - probes to discover what devices, software, or vulnerabilities may exist - totaled more than 108 million, followed by service attacks of more than 61 million, web attacks with 29 million, denial of service attacks with 26 million; security administration was last with more than 230,000 attacks
    Top 10 malware (malicious software) detected, by family, included: W32.Mytob; W32.Agobot; W32.Opaserv; W32.Sober; Ranky and Sdbot Dropper; W32.Backdoor; W32.Ranky; W32.Mydoom; W32.Sdbot and W32.Maslan

    New threats emerged:
    In March 2005, the emergence of a potential new threat affecting the Internet - pervasive Domain Name Service (DNS) cache poisoning was discovered. DNS cache poisoning is the act of corrupting a DNS server's ability to map machine host names to its proper IP address and would hijack visitors to an advertisement or inappropriate web site instead. While these types of threats have been seen for a few years, the new version uses two new technologies and any DNS server that is not configured properly may be susceptible to this type of attack
    In May 2005, a malware business was uncovered operating from iframeDOLLARS.biz. This Web site attempted to recruit partner Web sites to host a variety of malicious code to exploit Internet Explorer browsers, which paved the way for numerous trojans, backdoors and spyware installed on a computer .

    The IBM Global Business Security Index Report is a monthly report that assesses, measures and analyzes potential network security threats based on the data and information collected by IBM's 3,000 worldwide information security professionals and thousands of monitored devices.

    For more information, please visit: http://www-1.ibm.com/services/us/index.wss/offering/bcrs/a1008776 .


    print this article email this article download pdf blog this article bookmark this article     Digg this Stumble it share on Facebook share on Reddit add to delicious save to Yahoo! bookmarks
    not rated yet


  • August 2nd, 2005 all stories
    Technology /

    Comments: 0
    Rank: not rated yet

    • Stumble this up

    • Digg this

    • Share it:
    • share on Facebook
    • share on MySpace
    • share on Slashdot
    • rss-newsfeed
    • share on Google
    • share on Reddit
    • add to delicious
    • save to Yahoo! bookmarks
    • share on Windows Live
    • Add to Mixx!
    Rating: not rated yet

    • Related Stories

    • UK looks to young geeks to secure cyberspace
      created Jun 25, 2009 | popularity not rated yet | comments 0
    • First Afghan fibre optic cable connects to Tajikistan
      created Jun 04, 2009 | popularity not rated yet | comments 0
    • Expert: Obama's cybersecurity response disappointing in scope
      created May 29, 2009 | popularity not rated yet | comments 0
    • How influenza virus evades the body's immune response
      created May 20, 2009 | popularity not rated yet | comments 0
    • Wanted: Computer hackers... to help government
      created Apr 19, 2009 | popularity not rated yet | comments 0

    Tags


  • Physicists Demonstrate Quantum Memory with Matter Qubits
    Physicists Demonstrate Quantum Memory with Matter Qubits
    Physics / General Physics
    created Jul 03, 2009 | popularity 4.4 / 5 (16) | comments 1
  • 'Holey' Nanosheets for Wastewater Dye Removal
    Nanotechnology / Nanomaterials
    created Jul 01, 2009 | popularity 5 / 5 (5) | comments 1
  • Jellyfish Robot Swims Like its Biological Counterpart
    Jellyfish Robot Swims Like its Biological Counterpart
    Electronics / Robotics
    created Jun 26, 2009 | popularity 4.4 / 5 (8) | comments 1
  • Could Maxwell's Demon Exist in Nanoscale Systems?
    Could Maxwell's Demon Exist in Nanoscale Systems?
    Physics / General Physics
    created Jun 24, 2009 | popularity 4.4 / 5 (18) | comments 29
  • Living Safely with Robots, Beyond Asimov's Laws
    Living Safely with Robots, Beyond Asimov's Laws
    Electronics / Robotics
    created Jun 22, 2009 | popularity 4.6 / 5 (52) | comments 40
  • Other News

    Japan demands 119 million dlrs in tax from Amazon: report

    Technology / Business

    created 3 hours ago | popularity not rated yet | comments 0

    Japanese authorities told a sales affiliate of US retail giant Amazon.com to pay about 119 million dollars in tax for unreported income over a three-year period, a newspaper said Sunday.


    Iconic skyscrapers find new luster by going green (AP)

    Iconic skyscrapers find new luster by going green

    Technology / Energy

    created 4 hours ago | popularity 1 / 5 (1) | comments 0

    (AP) -- When owners of the Empire State Building decided to blanket its towering facade this year with thousands of insulating windows, they were only partly interested in saving energy. They also needed ...


    UK spy chief's family details posted on Facebook

    Technology / Internet

    created 4 hours ago | popularity not rated yet | comments 0

    (AP) -- He's the spy who came in from the beach.


    Downturn dating: Hearts flutter as markets stutter (AP)

    Downturn dating: Hearts flutter as markets stutter

    Technology / Internet

    created 4 hours ago | popularity not rated yet | comments 0

    (AP) -- Credit the recession for "staycations" and bringing us more game-night parties at home. But also give it a shout for spurring more first dates.


    Printable batteries

    Printable batteries

    Technology / Engineering

    created Jul 02, 2009 | popularity 4.8 / 5 (12) | comments 4

    For a long time, batteries were bulky and heavy. Now, a new cutting-edge battery is revolutionizing the field. It is thinner than a millimeter, lighter than a gram, and can be produced cost-effectively through ...