Security Intelligence Report
Total Page:16
File Type:pdf, Size:1020Kb
Microsoft Security Intelligence Report July–December 2006 An in-depth perspective of software vulnerabilities, malicious code threats, and potentially unwanted software, focusing on the second half of 2006 Microsoft Security Intelligence Report The information contained in this document represents the current view of Microsoft Corporation on the issues discussed as of the date of publication. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information presented after the date of publication. This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, AS TO THE INFORMATION IN THIS DOCUMENT. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, no part of this document may be reproduced, stored in or introduced into a retrieval system, or transmitted in any form or by any means (electronic, mechanical, photocopying, recording, or otherwise), or for any purpose, without the express written permission of Microsoft Corporation. Microsoft may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Microsoft, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. Copyright © 2007 Microsoft Corporation. All rights reserved. Microsoft, the Microsoft logo, Active Directory, ActiveX, Forefront, Internet Explorer, OneCare, the Security Shield logo, SmartScreen, Win32, Windows, Windows Live, Windows Live OneCare, Windows Server, and Windows Vista are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners. Authors Vinny Gullotto Ziv Mador Microsoft Security Research & Response Microsoft Security Research & Response Jeff Jones George Stathakopoulos Trustworthy Computing Microsoft Security Response Center Mary Landesman Jeff Williams Microsoft Security Research & Response Microsoft Security Research & Response Contributors Chuck Bassett Yuhui Huang Microsoft Forefront Client Security Microsoft Security Research & Response Dave Berkowitz Aaron Hulett Trustworthy Computing Microsoft Security Research & Response Subratam Biswas Jonathan Keller Microsoft Security Research & Response Microsoft Security Research & Response Daniel Bohm David Kennedy Exchange Hosted Services (EHS) Microsoft Legal and Corporate Affairs Matthew Braverman Jimmy Kuo Microsoft Security Research & Response Microsoft Security Research & Response Christopher Budd Mady Marinescu Trustworthy Computing Microsoft Security Research & Response Alexandru Carp Charles McColgan Microsoft Security Research & Response Exchange Hosted Services (EHS) Doug Cavit Mark Miller Trustworthy Computing Trustworthy Computing Brendan Foley Michael Mitchell Microsoft Security and Access Product Marketing Microsoft Legal and Corporate Affairs Jason Garms Gina Narkunas Windows Engineering Microsoft Online Services Group Jason Geffner Adam Overton Microsoft Security Research & Response Microsoft Security Research & Response Kjersti Gunderson Tim Rains Waggener Edstrom Trustworthy Computing Jim Hahn Bo Rohlfsen Windows Client Windows Live OneCare Brett Harris Stephen Toulouse Microsoft Security Research & Response Trustworthy Computing Richard Harrison Pat Winkler Content Master Microsoft Security Research & Response Rob Hensing Jaime Wong Microsoft Security Technology Unit Microsoft Security Research & Response Microsoft Security Intelligence Report Table of Contents About This Report 1 Scope . 1 Reporting.Period . ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... 1 Data.Sources. ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... 1 Executive Foreword 4 Executive Summary 5 Software.Vulnerabilities.Highlights. ... ... ... ... ... ... ... ... ... ... ... ... 5 Malicious.Software.Highlights. ... ... ... ... ... ... ... ... ... ... ... ... ... 6 Potentially.Unwanted.Software.Highlights. ... ... ... ... ... ... ... ... ... 7 Vulnerability Trends for 2006 7 Vulnerability.Disclosures.by.Year. ... ... ... ... ... ... ... ... ... ... ... ... 8 Vulnerability.Disclosures.by.Month. ... ... ... ... ... ... ... ... ... ... ... ... 9 Vulnerability.Disclosures.by.Week.. .. .. .. .. .. .. .. .. .. .. .. ...9 Vulnerability.Disclosures.by.Day.of.the.Week. ... ... ... ... ... ... ... ... ..10 Vulnerability.Disclosures.by.Severity .. .. .. .. .. .. .. .. .. .. .. ...11 Complexity.to.Exploit.. .. .. .. .. .. .. .. .. .. .. .. .. .. .. ...13 Operating.System.(OS).vs ..Non-OS.Disclosures. ... ... ... ... ... ... ... .....14 Summary.and.Conclusion. 14 Malicious Software 15 Malicious.Software.Categories. ... ... ... ... ... ... ... ... ... ... ... ... .....15 Malicious.Software.Activity. ... ... ... ... ... ... ... ... ... ... ... ... ... .....16 Microsoft Security Intelligence Report i Potentially Unwanted Software 38 Windows.Defender.Arrives . ... ... ... ... ... ... ... ... ... ... ... ... ... .....39 Software.Detected.by.Windows.Defender . ... ... ... ... ... ... ... ... .....39 Categories.of.Potentially.Unwanted.Software. ... ... ... ... ... ... ... ... ..42 Geographic.Data . ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... .....44 A.Focus.on.Rogue.Security.Software.. .. .. .. .. .. .. .. .. .. .. ...46 Executive Afterword 50 Conclusion . 52 Appendix A: Microsoft Antimalware Offerings 54 Windows.Malicious.Software.Removal.Tool. 54 Windows.Defender.. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. ...54 Windows.Live.OneCare . 55 Windows.Live.OneCare.Safety.Scanner.. .. .. .. .. .. .. .. .. .. ...56 Microsoft.Exchange.Hosted.Filtering . ... ... ... ... ... ... ... ... ... ... .....57 Microsoft.Forefront.Client.Security. ... ... ... ... ... ... ... ... ... ... ... ..58 Microsoft.Forefront.Security.for.Exchange.Server . ... ... ... ... ... ... .....59 Microsoft.Forefront.Security.for.SharePoint. 60 Appendix B: Windows Vista Security Features 62 Microsoft Security Intelligence Report About This Report Scope The last Security Intelligence Report published by Microsoft® focused on data and trends observed in the first half of 2006 specific to malicious software or potentially unwanted software. That report can be found at http://go.microsoft.com/?linkid=6543860. We continue to focus on malicious software data and trends in this report, but we have also expanded the scope of the report to include data and trends for software vulnerabilities. Note On November 30, 2006, Windows Vista™ was made available to business customers with volume license agreements. Windows Vista became generally available on January 30, 2007. Although this report does make reference to Windows Vista, a full analysis of relevant data from Windows Vista will be included in a future version of this report. Reporting Period This Security Intelligence Report contains data and trends observed over the past several years, but focuses on the second half of 2006 [2H06]. The nomenclature used throughout the report to refer to different reporting periods is nHYY, where nH refers to either the first (1) or second (2) half of the year, and YY denotes the year. For example, 1H06 represents the period covering the first half of 2006 (January 1 through June 30), while 2H05 represents the period covering the second half of 2005 (July 1 through December 31). Data Sources Software Vulnerabilities The efforts to identify and fix vulnerabilities lacked a common naming mechanism until a consortium led by The Mitre Corporation began publishing the Common Vulnerabilities and Exposure (CVE) list, which drives a common naming mechanism that can be leveraged by multiple vulnerability databases and security products. The CVE naming conventions provide the most comprehensive list of vulnerabilities worldwide, across software products of all types. This report uses the CVE naming conventions when identifying individual vulnerabilities. Microsoft Security Intelligence Report The analysis in this report uses a set of data that has been created by compiling, customizing, and cross-checking several sources of data available on the Internet: ■ Common Vulnerabilities and Exposures Web site (http://cve.mitre.org). A large portion of the data analyzed originates from the CVE list maintained at this site, which is currently sponsored by the United States Department of Homeland Security (DHS). The naming mechanisms and external references to sources for additional information were particularly valuable. ■ National Vulnerability Database (NVD) Web site (http://nvd.nist.gov/). This database superset of the CVE list, which provides additional objective information concerning vulnerabilities, was the source used to determine severity ratings and to exploit complexity assessment. The NVD is also sponsored by the United States DHS, and their data is downloadable in an XML format at http://nvd.nist.gov/download.cfm. ■ Security Web sites. The following sites, as well as many others, were utilized for detailed verification and validation of vulnerability specifics: ■ http://www.securityfocus.com ■ http://www.securityfocus.com/archive/1 (Bugtraq mailing list) ■ http://www.secunia.com ■ http://www.securitytracker.com