Microsoft warns against rogue security apps
- By Trudy Walsh
- Apr 08, 2009
Keep your street smarts on the Internet, according to a new report from Microsoft. Although some areas of security risk have shown improvement, threats from rogue security software to phishing scams are on the rise.
Microsoft today issued volume 6 of the Security Intelligence Report, detailing threats posed by rogue security software, browser-based exploits, popular document format exploits and security breaches.
According to the report, rogue security software uses “fear and annoyance tactics” to convince people to pay for bogus versions of software that will protect them from malware. This sort of threat has been on the rise during the past few years.
The report also offered analysis of browser-based exploits during the period between June and December 2008. Microsoft assessed a sample of data from incidents reported by customers, malicious code reports and Microsoft Windows error reports. The most common exploits occurred in U.S. English, about 32.4 percent, followed by Chinese, which had 25.6 percent of all incidents.
Browser-based attacks were much more likely to occur on PCs running the Windows XP operating system, about 40.0 percent of the total. By contrast, Windows Vista-operated machines accounted for just 5.5 percent of these attacks.
The report also lists the top 10 browser-based vulnerabilities attacked on computers running Windows XP in the second half of 2008, six of which were found in Microsoft software.
Hackers are now more likely to use common file formats as transmission vectors for their attacks. E-mail and instant messaging programs allow Microsoft Office and Adobe Portable Document Format (PDF) files as attachments, so they have become a target for the creators of malicious exploits, the report said. Use of PDF files as a transmission vehicle for attacks rose sharply in the second half of 2008, with attacks in July alone amounting to more than twice as many as in the first half of 2008.
The report also looked at security breach trends as provided by the Open Security Foundation’s (OSF) Data Loss Database. The main cause of data loss is the theft of equipment such as laptops, which account for 33.5 percent of all data loss incidents reported. Security breaches from hacking or malware attacks accounts for less than 20 percent of the total loss of data.
And although the Web is by definition worldwide, not all Internet security threats are global, the report said. Many threats are dependent on common language and cultural factors. The banking malware that plagues Brazil, for instance, is not common in South Korea, which is troubled by viruses such as Win32/Virut and Win32/Parite.
Finally, home PC users need to be especially vigilant, the report said. Home computers are more likely than corporate computers to encounter trojans, trojan downloaders and droppers, adware and exploits.
And there’s a reason your spam filter is always full. More than 97 percent of e-mail messages sent over the Internet are unwanted, the report said. They either have malicious attachments or are phishing attacks or spam, most of which (72.2 percent) consists of product advertisements.
Trudy Walsh is a senior writer for GCN.