Symantec Global Internet Security Threat Report
Total Page:16
File Type:pdf, Size:1020Kb
INTERNET SECURITY THREAT REPORT 2011 Trends Volume 17 Published April 2012 INTERNET SECURITY THREAT REPORT Paul Wood Mathew Nisbet Executive Editor Malware Data Analyst Manager, Cyber Security Intelligence Security Technology and Response Security Technology and Response Nicholas Johnston Gerry Egan Sr. Software Engineer Sr. Director, Product Management Security Technology and Response Security Technology and Response Bhaskar Krishnappa Kevin Haley Sr. Software Engineer Director, Product Management Security Technology and Response Security Technology and Response Irfan Asrar Tuan-Khanh Tran Security Response Manager Group Product Manager Security Technology and Response Security Technology and Response Sean Hittel Orla Cox Principal Software Engineer Sr. Manager, Security Operations Security Technology and Response Security Technology and Response Eric Chien Hon Lau Technical Director Manager, Development Security Technology and Response Security Technology and Response Eric Park Candid Wueest Sr. Business Intelligence Analyst Principal Software Engineer Anti-Spam Engineering Security Technology and Response Mathew Maniyara David McKinney Security Response Analyst Principal Threat Analyst Anti-Fraud Response Security Technology and Response Olivier Thonnard Tony Millington Sr. Research Engineer Associate Software Engineer Symantec Research Laboratories Security Technology and Response Pierre-Antoine Vervier Benjamin Nahorney Network Systems Engineer Senior Information Developer Symantec Research Laboratories Security Technology and Response Martin Lee Joanne Mulcahy Sr. Security Analyst Technical Product Manager Symantec.cloud Security Technology and Response Daren Lewis John Harrison Principal Strategic Planning Specialst Group Product Manager Symantec.cloud Security Technology and Response Scott Wallace Thomas Parsons Sr. Graphic Designer Director, Development Security Technology and Response Andrew Watson Sr. Software Engineer Security Technology and Response 2 Symantec Corporation INTERNET SECURITY THREAT REPORT TABLE OF CONTENTS Introduction ..........................................................5 Consumerization And Mobile Computing: Balancing The Risks 2011 By Month ....................................................6 And Benefits In The Cloud .......................25 Risks With ‘Bring Your Own Device’ .......................25 ............................................... 2011 In Numbers 9 Threats Against Mobile Devices .............................25 Consumerization Of It And Cloud Computing .....26 Executive Summary .....................................12 Quick Response (QR) codes ....................................27 What Mobile Malware Does With Your Phone .....27 Confidence In The Cloud: Balancing Risks �����������28 Safeguarding Secrets: Industrial Espionage In Cyberspace ���������������������������������������������������14 Spam Activity Trends ..................................29 Spam In 2011 ............................................................ Cyber-Espionage In 2011 ........................................14 29 Impact Of Botnets On Spam ................................... Advanced Persistent Threats ..................................15 30 The Changing Face Of Spam ................................... Targeted Attacks .......................................................16 30 URL Shortening And Spam ...................................... Case Study .................................................................16 31 Where Attacks Come From ��������������������������������������19 Malicious Code Trends ...............................32 Against The Breach: Malware In 2011 .......................................................32 Securing Trust Website Malware .......................................................33 And Data Protection ....................................20 Email-Borne Malware ...............................................34 Data Breaches In 2011 ............................................21 Border Gateway Protocol (BGP) Hijacking .........................................................35 Certificate Authorities Under Attack .....................23 Polymorphic Threats ................................................35 Building Trust And Securing The Weakest Links ....................................................24 Dangerous Web Sites ...............................................36 Exploiting The Web: Attack Toolkits, Rootkits And Social Networking Threats ..............37 Macs Are Not Immune ..............................................38 Rootkits .......................................................................39 Social Media Threats ������������������������������������������������39 Symantec Corporation 3 INTERNET SECURITY THREAT REPORT Closing The Window Best Practice Guidelines Of Vulnerability: Exploits For Businesses .................................................44 And Zero-Day Attacks .................................40 Number Of Vulnerabilities ......................................40 Best Practice Guidelines Weaknesses in Critical For Consumers ................................................46 Infrastructure Systems ............................................41 Old Vulnerabilities Are Still Under Attack ............41 Web Browser Vulnerabilities ..................................41 More Information ..........................................48 New Zero-day Vulnerabilities Create Big Risks .......................................................42 About Symantec ..............................................48 Conclusion: What’s Ahead In 2012 .................................43 Endnotes ...............................................................49 FIGURES Figure 1 Figure 10 Targeted Attacks Trend Showing Average Key Functionality Of Mobile Risks..................................27 Number Of Attacks Identified Each Month, 2011 .........15 Figure 11 Figure 2 Percentage Of Email Identified As Spam, 2011 ............30 Targeted Email Attacks, By Top-Ten Industry Sectors, 2011 ��������������������������������16 Figure 12 Top Ten Spam Email Categories, 2010-2011 ................31 Figure 3 Attacks By Size Of Targeted Organization ....................17 Figure 13 Average Number Of Malicious Web Sites Figure 4 Identified Per Day, 2011 ................................................33 Analysis Of Job Functions Of Recipients Being Targeted .........................................18 Figure 14 Ratio Of Malware In Email Traffic, 2011 ........................34 Figure 5 Geographical Locations Figure 15 Of Attackers’ IP Addresses ���������������������������������������������19 Rise In Email-Borne Bredolab Polymorphic Malware Attacks Per Month, 2011 ................................35 Figure 6 Timeline Of Data Breaches Figure 16 Showing Identities Breached In 2011 ............................21 Most Dangerous Web Site Categories, 2011 .................36 Figure 7 Figure 17 Top-Ten Sectors Macdefender Trojan Screenshot ������������������������������������38 By Number Of Data Breaches, 2011 ������������������������������22 Figure 18 Figure 8 Total Number Of Vulnerabilities Identified, Top-Ten Sectors 2006-2011 .....................................................................40 By Number Of Identities Exposed, 2011 ........................22 Figure 19 Figure 9 Browser Vulnerabilities In 2010 And 2011 ...................41 Total Mobile Malware Family Count 2010-2012 ...........26 Figure 20 Web Browser Plug-In Vulnerabilities .............................42 4 Symantec Corporation INTERNET SECURITY THREAT REPORT Introduction ymantec has established some of the most comprehensive sources of Internet threat data in the world through the Symantec™ Global SIntelligence Network, which is made up of more than 64.6 million attack sensors and records thousands of events per second. This network monitors attack activity in more than 200 countries and territories through a combination of Symantec products and services such as Symantec DeepSight™ Threat Management System, Symantec™ Managed Security Services and Norton™ consumer products, and other third-party data sources. In addition, Symantec maintains one of the world’s most comprehensive vulnerability databases, currently consisting of more than 47,662 recorded vulnerabilities (spanning more than two decades) from over 15,967 vendors representing over 40,006 products. Spam, phishing and malware data is captured through a variety of sources, including the Symantec Probe Network, a system of more than 5 million decoy accounts; Symantec.cloud and a number of other Symantec security technologies. Skeptic™, the Symantec.cloud proprietary heuristic technology is able to detect new and sophisticated targeted threats before reaching customers’ networks. Over 8 billion email messages and more than 1.4 billion Web requests are processed each day across 15 data centers. Symantec also gathers phishing information through an extensive antifraud community of enterprises, security vendors, and more than 50 million consumers. These resources give Symantec’s analysts unparalleled sources of data with which to identify, analyze, and provide informed commentary on emerging trends in attacks, malicious code activity, phishing, and spam. The result is the annual Symantec Internet Security Threat Report, which gives enterprises and consumers the essential information to secure their systems effectively now and into the future. Symantec Corporation 5 INTERNET SECURITY THREAT REPORT 2011 BY MONTH MOBILE BOTNET THREAT SPAM SOCIAL HACKS