Cloud Computing, Virtualization Will Increase Security Demands On Service Providers, According To Trend Micro

With the growing diversity of operating systems among companies, as well as the growing use of mobile devices, cybercriminals should have a very profitable 2011. Their tactic will be to put a new spin on social engineering by way of "malware campaigns," by bombarding recipients with e-mail that drop downloaders containing malware. All this will largely be made possible because of the Internet. Already, Trend Micro threat researchers have found that more than 80 percent of the top malware use the web to arrive on users' system.

2011 will bring about a growth in exploits for alternative operating systems, programs and web browsers, combined with tremendous growth in the use of application vulnerabilities.

Cloud computing and virtualization -- while offering significant benefits and cost-savings -- move servers outside the traditional security perimeter and expand the playing field for cybercriminals and increases security demands on cloud service providers.

Trend Micro expects more proof of concept attacks against cloud infrastructure and virtualized systems to show up in 2011. Knowing that the desktop monoculture will disappear, cybercriminals will test how to successfully infiltrate and misuse a monoculture in the cloud.

Targeted attacks on "unpatchable" (but widely used) legacy systems – like Windows 2000/Windows XP SP2 -- will continue to proliferate. 

Social engineering will continue to play a big role in the propagation of threats.  Trend Micro believes in 2011 there will be fewer infiltrated websites; instead cybercriminals will focus on malware campaigns, the promotion of malware through cleverly designed e-mails convincing users to click on a link that will ultimately lead to a malicious downloader. The downloader then randomly generates binaries to avoid detection, as Conficker and ZeuS-LICAT have done in the past.

Thanks to easy-to-use underground toolkits, mid-sized companies will be targeted in cyber-espionage.  In 2010, the use of underground toolkits exploded, making it easier to target particular types of organizations.  ZeuS primarily targeted small businesses in 2010.  Moving forward, localized and targeted attacks are expected to continue to grow in number and sophistication both against big name brands and/or critical infrastructure.  

In 2011, it is very likely that cybercriminals will increasingly target security vendors' brands in order to cause confusion and insecurity among users.

More key forecasts for 2011 and beyond:

  • It's all about money, so cybercrime will not go away.
  • There will be an increase use of stolen or legitimate digital certificates in malware attacks, to avoid detection. 
  • Further consolidation will happen in the cybercrime underground as groups merge and/or join forces as global and public attention for cyber attacks will grow.
  • Some security vendors will run into trouble with their inability to store all the threat information with local signatures. They will retire old signatures which will lead to infections from old/outdated malware.
  • More proof of concept and some successful attacks on mobile devices will occur.

 

Featured

  • Pragmatism, Productivity, and the Push for Accountability in 2025-2026

    Every year, the security industry debates whether artificial intelligence is a disruption, an enabler, or a distraction. By 2025, that conversation matured, where AI became a working dimension in physical identity and access management (PIAM) programs. Observations from 2025 highlight this turning point in AI’s role in access control and define how security leaders are being distinguished based on how they apply it. Read Now

  • Report: Cyber Attackers Continue to Turn to AI-Based Tools to Avoid Detection

    Comcast Business recently released its 2025 Cybersecurity Threat Report, a comprehensive analysis of 34.6 billion cybersecurity events detected between June 1,2024 and May 31, 2025. Now in its third year, the report offers business leaders a unique perspective into the evolving threat landscape and provides actionable insights to help organizations strengthen their defenses and align cybersecurity with business risk. Read Now

  • Axis Communications Creates AI-powered Video Surveillance Orchestra

    What if cameras could not only see the world, but interpret it—and respond like orchestra musicians reading sheet music: instantly, precisely, and in perfect harmony? That’s what global network technology leader Axis Communications set to find out. Read Now

  • Just as Expected

    GSX produced a wonderful tradeshow earlier this week. Monday was surprisingly strong in the morning, and the afternoon wasn’t bad at all. That’s Monday’s results and asking attendees to travel on Sunday. Just a quick hint, no one wants to give up their weekend to travel and set up an exhibit booth. I’m just saying. Read Now

    • Industry Events
    • GSX
  • NOLA: The Crescent City

    Twenty years later we finds ourselves in New Orleans. Twenty years ago the aftermath of Hurricane Katrina forced exhibitors and attendees to look elsewhere for tradeshow floor space. Read Now

    • Industry Events
    • GSX

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities