Markets
SecurityInfoWatch




IT Asset & Technology Centers

Updated: July 30th, 2008 11:32 AM GMT-05:00

Cyber criminals becoming quicker

New report shows hackers are utlizing programs that automatically generate attacks

The New Zealand Herald

SAN JOSE - The bad guys on the internet are narrowing the time frame they need to unleash computer attacks that take advantage of publicly disclosed security holes, new research shows.

More and more of these attacks are coming within 24 hours after vulnerability is disclosed. That means security flaws are being exploited in web browsers, computer operating systems and other programs before many people even have had time to learn there's a problem, according to IBM's latest internet Security Systems X-Force report.

The report, scheduled to be released today, looked at the first six months of 2008 and reflects two growing trends in internet-based threats.

The first is that online criminals have latched on in a big way to programs that help them automatically generate attacks based on publicly available information about vulnerabilities. In the past they apparently spent more time finding such holes themselves, but no longer find that as necessary.

"The bad guys are not the ones actively finding vulnerabilities - they've shifted their business to standing on the shoulders of the security research community," Kris Lamb, operations manager for X-Force, said in an interview. "They don't have to do the hard work anymore. Their job is packaging what's been provided to them."

The second trend is that the debate among security researchers is intensifying over how much information should be released to the public when a new software flaw is discovered.

1 2 3 next


More From IT Asset & Technology Centers




SIW eNews

FrontLine

Markets & Sys

PracticeReport

AppReport

ProductWatch

EventWatch

Weekly Recap

EndUser Blasts

Dealer Blasts