Newsletters Select newsletters below and click the button to sign up!
Internetnews BloggersRecent Entries
ArchivesMonthly ArchivesSearch The Blog
« MonitoringForge launches for open source network monitoring |
Sean Michael Kerner Blog
| Google Chrome 3 gets stable release, faster JavaScript »
Operating Systems not the key security risk anymore From the 'Security Stats' files:
The SANS Institute is out today with a new Cyber Security Risks report. Among their top conclusions is the assertion that operating systems are not the biggest IT security problem. Add-on applications and web application vulnerabilities, top SANS list for security vulnerabilities. "Waves of targeted email attacks, often called spear phishing, are exploiting client-side vulnerabilities in commonly used programs such as Adobe PDF Reader, QuickTime, Adobe Flash and Microsoft Office," the report states. "This is currently the primary initial infection vector used to compromise computers that have Internet access."This is not a surprising finding to me. Users are not updating apps as often as they should, whether it's Adobe Flash or Apple QuickTime. Other security researchers have pointed out the same issue, time and again as well. The other big issue is web application vulnerability, which again is something that is no surprise either. It's not all doom and gloom though. SANS did find that one type of attack that I used to see every so often has now declined. SANS reported that there has been a large decline in the number of "PHP File Include" attacks. The decline comes from improved processes used by developers and security pros, according to SANS. All this doesn't take the operating system vendors off the hook, in my view. What has happened is attackers are looking for the best route to compromise the most machines, regardless of OS. If a web app is vulnerable, all the attacker needs to do is infect the one server in order to propagate their attack to thousands (or millions of users). "There are few attacks against the operating system itself, and patching has become pretty robust when it comes to the operating system and its core components," SANS researchers Johannes B. Ullrich blogged. 1 TrackBacksListed below are links to blogs that reference this entry: Operating Systems not the key security risk anymore. TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/8913
» Making Sense of the SANS “Top Cyber Security Risks” Report from The New School of Information Security
The SANS Top Cyber Security Risks report has received a lot of positive publicity. I applaud the effort and goals of the study and it may have some useful conclusions. We should have more of this. Unfortunately, the report has some major problems. Th... Read More |
||
Leave a comment