Report: Worms Jump Back Onto Scene, But Rogue Security Software Still Top Threat

Microsoft Corp. recently released the seventh volume of the Microsoft Security Intelligence Report (SIRv7), which indicates that worm infections in the enterprise rose by nearly 100 percent during the first half of 2009 over the preceding six months. Rogue security software remains a major threat to customers; however, 20 percent fewer customers were affected by rogue infections during the past six months.

(In addition, the Zlob family of trojans, considered a top threat two years ago, has drastically declined due to Microsoft's work to aggressively clean customer machines and customers' diligence in applying software updates.

SIRv7 provides a deep, accurate view of the threat landscape country by country. For the first time, this report shares security best practices from countries that have consistently exhibited low malware infection. These best practices and security intelligence provide a valuable resource for business leaders who need to make accurate decisions based on the threats that are most pressing today.

"It's been said that knowledge is power -- and when it comes to security intelligence, a lack of accurate information can be detrimental to separating real threats from hype," said Vinny Gullotto, general manager of the Microsoft Malware Protection Center. "Microsoft is committed to providing not only security intelligence for our customers and the community, but also the most accurate and comprehensive view of the realities of the threat landscape."

The security intelligence contained in SIRv7 is collected through a broad community of customers around the globe who share Microsoft's goal of obtaining the most accurate view of the threat landscape. Reporting mechanisms for the Microsoft Security Intelligence Report are diverse and comprehensive, including Microsoft's Malicious Software Removal Tool (MSRT), on 450 million computers worldwide; Bing, which performed billions of Web page scans during the past six months; Windows Live OneCare and Windows Defender, operating on more than 100 million computers worldwide; Forefront Online Protection for Exchange and Forefront Client Security, scanning billions of e-mail messages yearly; and Windows Live Hotmail, operating in more than 30 countries with hundreds of millions of active e-mail users.

Ten years after Melissa appeared and defined mass-mailing worms as a class of malicious threats, worm infections have resurged to become the second most prevalent threat for enterprises in the first half of 2009. Worms rely heavily on access to unsecured file shares and removable storage volumes, both of which are plentiful in enterprise environments. According to SIRv7, the following were the top two families detected:

  • Conficker was the top worm threat detected for the enterprise, because its method of propagation works more effectively within a  irewalled network environment. Conficker is not in the top 10 for consumers, because home computers are more likely to have automatic updating enabled. This further reiterates the need for enterprises to have a robust security update management program in place.
  • Taterf, with detections up 156 percent since the second half of 2008, targets massively multiplayer online role-playing games (MMORPGs). These attacks rely less on social engineering to spread, and more on access to unsecured file shares and removable storage volumes -- both of which are often plentiful in the enterprise. Taterf's impressive  growth underscores the need for organizations to develop guidelines for removable drives (such as thumb drives) and evaluate how connections are made to outside machines.

According to the report, rogue security software remained the single largest threat category for the first half of 2009. In addition, while there has been progress combating rogues, this threat remained a major pain point for computer users during the same period. Also known as "scareware," rogue security software takes advantage of customers' desire to keep their computer protected. Microsoft products and services removed malware from more than 13 million computers worldwide, down from 16.8 million in the second half of 2008. Computer users are advised to use an anti-malware solution from a company they trust and to keep its threat definitions up to date.

In contrast, the report highlights the significant decrease in Zlob disinfections, from 21.1 million at its peak in 2007 to 2.3 million in the first half of 2009 -- a remarkable tenfold decrease.

Infection rates and threats vary geographically, and SIRv7 contains proven best practices from countries with the lowest infections. For example, infection rates in Japan, Austria and Germany remained relatively low during this period. Following is insight into how professionals from these regions keep their customers and resources safe from cyber threats:

  • Japan has seen its infection rates remain relatively low. One of the reasons is due in large part to collaborations such as the Cyber Clean Center, a cooperative project between Internet service providers (ISPs), major security vendors and Japanese government agencies to educate users.
  • Austria has implemented strict IT enforcement guidelines to lower piracy rates, and this -- along with strong ISP relationships and fast
    Internet lines, which aid in security update deployment -- has helped ensure its generally low infection rate.
  • Germany has also leveraged collaboration efforts with its computer emergency response team (CERT) and ISP communities to help identify and raise awareness of botnet infections and, in some cases, quarantine infected computers.


Central to the success in each of these regions is the growing trend of community-based defense, in which the broader industry combines its collective strengths and intelligence to help defend computer users. Customers worldwide can use SIRv7's detailed level of geographical insight to help inform their threat management and risk management operations on a local, regional and global level.

Featured

  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West
  • SIA Releases New Report on Operational Security Technology

    The Security Industry Association (SIA) has released an impactful new resource – Operational Security Technology: Principles, Challenges and Achieving Mission-Critical Outcomes Leveraging OST. Read Now

  • Cyber Overconfidence Is Leaving Your Organization Vulnerable

    The increased sophistication of cyber threats pumped by the relentless use of AI and machine learning brings forth record-breaking statistics. Cyberattacks grew 44% YoY in 2024, with a weekly average of 1,673 cyberattacks per organization. While organizations up their security game to help thwart these attacks, a critical question remains: Can employees identify a threat when they come across one? A Confidence Gap survey reveals that 86% of employees feel confident in their ability to identify phishing attempts. But things are not as rosy as they appear; the more significant part of the report finds this confidence misplaced. Read Now

  • Mission 500 Debuts Refreshed Identity Ahead of Security 5K/2K at ISC West

    Mission 500, the security industry’s nonprofit charity dedicated to supporting children in need across the US, Canada, and Puerto Rico, has unveiled a refreshed brand identity ahead of ISC West. The charity’s new look includes a modernized logo with refined messaging to reinforce Mission 500’s nearly decade-long commitment to serving the needs of children and families in crisis. Read Now

    • Industry Events

New Products

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.