Stolen hardware crops up in more IT security incidents than hacking.
That is according to the latest half-yearly Security Intelligence Report (SIR) from Microsoft, covering the second half of 2007.
Exploits, malware, and hacking account for less than a quarter of security breach notifications. The majority of the breaches analysed resulted from the absence or failure of proper information handling or physical security procedures. The IT firm urged computer users to โconsider all stages of the data life cycle, including storage, transit, and destruction, when developing policiesโ. Malicious and potentially unwanted software, malware, has shifted from an amateur phenomenon to a tool used by professional criminals and groups to generate revenue. Many of the more prevalent malware families rely on social engineering tactics that trick the computer user into taking action that bypasses or lessens the effectiveness of the userโs existing protection.
More than 90 percent of all e-mail messages sent over the internet are spam. In addition to annoying the recipients and taxing the resources of e-mail providers, the flood of spam creates what the authors call a potent vector for malware attacks and phishing attempts. As with malware, spam has evolved from a tool used by small operators to one typically used by larger, organised criminal groups to perpetuate scams and to sell fraudulent or dubious goods and services. As the senders of spam have changed, spam messages themselves have shifted away from selling legal products and services and toward the underground economy of illegal products and scams. In other words, spam selling cheap drugs or herbal remedies is on the rise; pornographic emails have greatly diminshed.
Phishing
Phishing remained a significant threat in the second half of 2007, eroding peopleโs trust in the internet and harming the reputations of the institutions victimised by phishing sites. In more detail: phishing attempts are increasingly being posted to social networks, exploiting the trust that victims place in these networks and in the friends connected through them. One recent attack on a large social networking site involved obtaining login credentials from victims through phishing messages posted to their profiles; the phishers then used an automated programme to log into the victimsโ accounts and post additional phishing messages to all of the victimsโ contacts, repeating the phishing. Some of the most persistent malicious software, the IT firm’s authors add, is updated dozens of times a day by its creators in a continual effort to stay one step ahead of the security software that attempts to remove them, ‘contributing to an ever-escalating arms race’. According to the Anti-Phishing Working Groupโa cross-industry association of which Microsoft is a founding memberโbetween 75 and 150 million phishing e-mails are sent out every day.
Like the UK infosecurity survey from auditors PwC and the Department for Trade and Industry, featured in the May issue of Professional Security, Microsoft warns that social engineering attacks are on the rise and can often trick the user into taking action that bypasses or lessens security measures already in place.
Several jurisdictions around the world now require that companies and other organizations publicly disclose security breaches that put personally identifiable information (PII) at risk. Analysing these notifications offers insights into how and why such breaches occur.
Microsoft adds that it has filed nearly 250 legal actions worldwide against spammers, often work-ing with law enforcement officials in the United States, Europe, the Asia-Pacific region,
and South America. Microsoft was the first private-sector participant in the London Action Plan, a coalition of international agencies that supports global cooperation on network security, law enforcement, and improved consumer awareness to combat spam.
"Malware has evolved into a profit-driven criminal enterprise, and attackers infect computers in order to use them later for their purposesโstealing information, sending spam, installing spyware or adware, and so on. After the attackers have gained access to a victimโs computer through social engineering or a vulnerability exploit, they typically expect to run additional programs to serve these purposes." Typical social engineering ploys are offers of free beta-test software; or YouTube-themed or ‘salacious’ messages. Or there are what are termed traditional unsolicited e-mails offering home working or other scams. The report authors recomend coputer users avoid opening attachments or clicking on links in e-mail or instant messages that are received unexpectedly or from an unknown source. a spam campaign can send as many as five million messages in less than an hour, usingtens of thousands of hijacked computers worldwide.
You can download the document from the โsecurityโ part of the Microsoft website:





