Newsletters
Customer Relationship Management News NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home CRM Systems Customer Service Business Intelligence Sales & Marketing More Topics...
GET RECOGNIZED.
Let an ISACA® certification
elevate your career.

Register today and save
Network Security
Tame your scariest paperwork. Find Out How
Average Rating:
Rate this article:  
IBM X-Force Trend and Risk Report Offers More Good Security News than Bad
IBM X-Force Trend and Risk Report Offers More Good Security News than Bad

By Jennifer LeClaire
March 22, 2012 12:05PM

Bookmark and Share
"Computer Security is getting better. We're seeing less exploit code getting released on the Internet. We're seeing the quality of software improve. We're seeing software vendors get more diligent about patching security vulnerabilities," said Tom Cross on IBM's X-Force 2011 Trends and Risk Report.
 



IBM on Thursday released the results of its X-Force 2011 Trend and Risk Report -- and there is some good news and some bad news.

First the good news. The X-Force 2011 Trend and Risk Report revealed a 50 percent decline in spam e-mail compared with 2010, more diligent patching of security vulnerabilities by software vendors, and higher quality of software application code. However, attackers have countered with an increase in automated shell command injection attacks against Web servers.

"The most surprising result to me has been the two- to three-fold increase in shell command injection attacks. I would not have predicted that particular attack vector would grow so much in popularity at this stage of the game," said Tom Cross, manager of Threat Intelligence and Strategy for IBM X-Force.

"X-Force believes that this activity may be an adaptation to the fact that Web site operators are working to fix SQL Injection vulnerabilities and may be missing shell command issues that are also lurking within their Web applications."

A Mixed Bag of News

For years, SQL injection attacks against Web applications have been a popular vector for attackers of all types, IBM said. SQL injection vulnerabilities allow an attacker to manipulate the database behind a Web site.

As progress has been made to close those vulnerabilities, IBM reports some attackers have now started to target shell command injection vulnerabilities instead. These vulnerabilities allow the attacker to execute commands directly on a Web server. IBM said Web application developers should pay close attention to this increasingly popular attack vector.

Back to the good news. There was a 39 percent decline in the availability of exploit code. And although some security vulnerabilities are never patched, in 2011 this number was down to 36 percent from 43 percent in 2010. IBM also witnessed a 50 percent reduction in cross-site scripting (XSS) vulnerabilities due to improvements in software quality.

"Computer Security is getting better. We're seeing less exploit code getting released on the Internet. We're seeing the quality of software improve. We're seeing software vendors get more diligent about patching security vulnerabilities," Cross said.

"We've still got a lot of work to do. There are still many vulnerabilities out there and attackers are taking advantage of them, but our statistics show that progress is being made -- all of the work that is going on to make software more resilient is making a difference."

Cloud Computing Challenges

The IBM X-Force team also looked at new challenges associated with cloud computing. Cloud computing is moving rapidly from emerging to mainstream technology, and rapid growth is expected through the end of 2013, according to IBM.

X-Force pointed to the many high-profile cloud breaches affecting well-known organizations and large populations of their customers in 2011 and said IT security staff should carefully consider which workloads are sent to third-party cloud providers and what should be kept in-house due to the sensitivity of data.

"Many cloud customers using a service worry about the security of the technology. Depending upon the type of cloud deployment, most, if not all, of the technology is outside of the customer's control," said Ryan Berg, an IBM security cloud strategist. "They should focus on information security requirements of the data destined for the cloud, and through due diligence, make certain their cloud provider has the capability to adequately secure the workload."

To view the full X-Force 2011 Trend and Risk Report and watch a highlight video, visit www.ibm.com/security/xforce.
 

Tell Us What You Think
Comment:

Name:

Al:

Posted: 2012-04-05 @ 11:15am PT
It sure would be nice to have a LINK TO THE REPORT.



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 Network Security
1.   Banks Hit by Android-Skirting Malware
2.   New Technology Defeats Privacy Efforts
3.   Juniper DDoS for High-IQ Networks
4.   Big DDoS Attacks Hit Record in 2014
5.   Can Google Stop Zero Day Flaws?


advertisement
Android SMS Worm on the Loose
Malware lets bad actors cash in.
Average Rating:
Banks Hit by Android-Skirting Malware
34 institutions, four European countries
Average Rating:
New Technology Defeats Privacy Efforts
Study identifies 3 browser techniques.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
34 European Banks Hit by Android-Skirting Malware
Criminals have been finding gaping holes in Android-based two-factor authentication systems that banks around the world are using. The result: 34 banks in four European countries have been hit.
 
New Web Tracking Technologies Defeat Privacy Protections
Recently developed Web tracking tools are able to circumvent even the best privacy defenses, according to a new study by researchers at Princeton and the University of Leuven in Belgium.
 
Juniper DDoS Solution Aims at High-IQ Networks
In the face of more complex attacks, Juniper Networks is boosting its DDoS Secure solution to help companies mitigate the threats with more effective security intelligence throughout the network fabric.
 

Navigation
CRM Daily
Home/Top News | CRM Systems | Customer Service | Business Intelligence | Sales & Marketing | Contact Centers | Customer Data | CRM Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.