Newsletters
Customer Relationship Management News NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home CRM Systems Customer Service Contact Centers Business Intelligence More Topics...
UCS Invicta: Integrated Flash
Deploy flash memory technology to
deliver peak workload performance.

Find out more>>
Network Security
Real-time info services with Neustar
Average Rating:
Rate this article:  
IBM X-Force Trend and Risk Report Offers More Good Security News than Bad
IBM X-Force Trend and Risk Report Offers More Good Security News than Bad

By Jennifer LeClaire
March 22, 2012 12:05PM

Bookmark and Share
"Computer Security is getting better. We're seeing less exploit code getting released on the Internet. We're seeing the quality of software improve. We're seeing software vendors get more diligent about patching security vulnerabilities," said Tom Cross on IBM's X-Force 2011 Trends and Risk Report.
 


IBM on Thursday released the results of its X-Force 2011 Trend and Risk Report -- and there is some good news and some bad news.

First the good news. The X-Force 2011 Trend and Risk Report revealed a 50 percent decline in spam e-mail compared with 2010, more diligent patching of security vulnerabilities by software vendors, and higher quality of software application code. However, attackers have countered with an increase in automated shell command injection attacks against Web servers.

"The most surprising result to me has been the two- to three-fold increase in shell command injection attacks. I would not have predicted that particular attack vector would grow so much in popularity at this stage of the game," said Tom Cross, manager of Threat Intelligence and Strategy for IBM X-Force.

"X-Force believes that this activity may be an adaptation to the fact that Web site operators are working to fix SQL Injection vulnerabilities and may be missing shell command issues that are also lurking within their Web applications."

A Mixed Bag of News

For years, SQL injection attacks against Web applications have been a popular vector for attackers of all types, IBM said. SQL injection vulnerabilities allow an attacker to manipulate the database behind a Web site.

As progress has been made to close those vulnerabilities, IBM reports some attackers have now started to target shell command injection vulnerabilities instead. These vulnerabilities allow the attacker to execute commands directly on a Web server. IBM said Web application developers should pay close attention to this increasingly popular attack vector.

Back to the good news. There was a 39 percent decline in the availability of exploit code. And although some security vulnerabilities are never patched, in 2011 this number was down to 36 percent from 43 percent in 2010. IBM also witnessed a 50 percent reduction in cross-site scripting (XSS) vulnerabilities due to improvements in software quality.

"Computer Security is getting better. We're seeing less exploit code getting released on the Internet. We're seeing the quality of software improve. We're seeing software vendors get more diligent about patching security vulnerabilities," Cross said.

"We've still got a lot of work to do. There are still many vulnerabilities out there and attackers are taking advantage of them, but our statistics show that progress is being made -- all of the work that is going on to make software more resilient is making a difference."

Cloud Computing Challenges

The IBM X-Force team also looked at new challenges associated with cloud computing. Cloud computing is moving rapidly from emerging to mainstream technology, and rapid growth is expected through the end of 2013, according to IBM.

X-Force pointed to the many high-profile cloud breaches affecting well-known organizations and large populations of their customers in 2011 and said IT security staff should carefully consider which workloads are sent to third-party cloud providers and what should be kept in-house due to the sensitivity of data.

"Many cloud customers using a service worry about the security of the technology. Depending upon the type of cloud deployment, most, if not all, of the technology is outside of the customer's control," said Ryan Berg, an IBM security cloud strategist. "They should focus on information security requirements of the data destined for the cloud, and through due diligence, make certain their cloud provider has the capability to adequately secure the workload."

To view the full X-Force 2011 Trend and Risk Report and watch a highlight video, visit www.ibm.com/security/xforce.
 

Tell Us What You Think
Comment:

Name:

Al:

Posted: 2012-04-05 @ 11:15am PT
It sure would be nice to have a LINK TO THE REPORT.



UCS Invicta: Integrated Flash Why wait for the future? Unlock the potential of your applications and create new business opportunities today with UCS Invicta Series Solid State Systems. Take advantage of the power of flash technology. See how it can help accelerate IT, eliminate data center bottlenecks, and deliver the peak application performance and predictability your users demand. Click here to learn more.


 Network Security
1.   Microsoft Ruling Raises Privacy Concern
2.   Twitter Buys Password Manager Mitro
3.   Gov't User Data Requests Skyrocket
4.   Retailers Hacked by New Malware
5.   IBM Beefs Up Identity Intelligence


advertisement
Twitter Buys Password Manager Mitro
Startup to release code as open source.
Average Rating:
Gov't User Data Requests Skyrocket
Twitter: From U.S. and around the globe.
Average Rating:
IBM Beefs Up Identity Intelligence
To offer biz better security products.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Ruling Against Microsoft Raises E-Mail Privacy Concern
Microsoft has been ordered to hand over e-mails to law enforcers in the United States as part of a criminal investigation, even though the e-mail is stored at a data center in Dublin,Ireland.
 
Twitter Buys Password Manager Startup Mitro
Following on the heels of another acquisition earlier this week, Twitter is adding to its fold a password-manager security startup called Mitro, which in turn is releasing its code as open source.
 
Government Requests for Customer Data Skyrocket
Requests for customer data from the government jumped 50 percent in the first half of 2014, according to Twitter, which received more than 2,000 requests for user info from gov't agencies.
 

Navigation
CRM Daily
Home/Top News | CRM Systems | Customer Service | Contact Centers | Business Intelligence | Sales & Marketing | Customer Data | CRM Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.