Cloud Security Authors: Elizabeth White, Pat Romanski, Liz McMillan, Peter Silva, Ed Featherston

Related Topics: Cloud Security

Cloud Security: Article

The Growth of Cybercrime

More people participate in cybercrime; threats continue to grow and evolve

Cybercrime saw significant growth in 2009. It increased in prevalence and geographic spread. The only thing that didn't grow was the skill level required to participate. It was easier for non-skilled attackers to conduct sophisticated attacks because of the availability of toolkits. The increase in manpower has led to an increase in most areas of cybercrime.

The growth of cybercrime has come despite a global recession that has stunted the growth of almost every other industry. The growth of cybercrime has been fueled by an increase in Internet users, especially those in developing countries.

However, businesses can protect their information from these pervasive dangers. Understanding the threat landscape is the first step. The following highlights from the Symantec Internet Security Threat Report XV can help organizations understand just what they're up against.

Cybercrime Keeps Growing
Malicious code is as prominent as ever. In 2009, Symantec identified more than 240 million distinct new malicious programs - a 100 percent increase over 2008. Last year Symantec blocked an average of 100 potential attacks per second.

Compromised confidential information continues to be an issue. Sixty percent of all data breaches that exposed identities were the result of hacking. This problem is not limited to a few larger enterprises. According to the Symantec State of Enterprise Security Report, 75 percent of all companies surveyed experienced some sort of cyber attack during the last year.

Cybercrime is a universal problem. Attackers have moved from using simple scams to launching highly sophisticated campaigns targeting some of the world's largest corporations and government entities. The scale of these attacks and the fact that they come from all over the world makes this an international problem requiring the cooperation of the private sector and global governments.

Less Skill Is Required to Engage in Cybercrime
The emergence of attack toolkits has made cybercrime available to anyone regardless of their computer knowledge and expertise. Novice computer users can purchase a kit and almost immediately begin deploying sophisticated and varied threats. Toolkits such as Zeus can be purchased for as little as $700. Some toolkits allow customization, resulting in many variants being created. Because there are an increasing number of cybercriminals entering the space, the number of threats is increasing and the number of people being affected is increasing as well.

Underground Economy a Bull
Credit cards and bank accounts continued to be the most advertised items on the underground economy in 2009 - illustrated in part by a notable increase in credit card dumps. Such dumps, which are sometimes referred to as cloned credit cards, increased by 150 percent from 2008 to 2009.

Social engineering tactics have changed to take advantage of the evolving financial landscape. More malicious messages incorporate themes such as refinancing loans, consolidating debt, reducing credit card interest rates, etc.

Enterprises Subject to More, Targeted Attacks
Cyber attacks are not just more sophisticated, they're also much more targeted. Many of them are full-fledged yet subtle campaigns. Cyber attacks remain undetected to penetrate deeply into the corporate network. While these targeted attacks have been occurring for several years, they have taken center stage recently, with incidents such as Hydraq.

Targeted attacks use zero-day vulnerabilities and spear-phishing type attacks. Attackers usually research a company and its employees by gathering information from corporate websites, news articles, social networks and other sites. Many targeted attacks aim to steal information about the organization's customers and employees, but other information - like intellectual property and corporate strategies - are also targeted.

Web-Based Attacks Are the Biggest Threat - and Are Getting Bigger
Four out of the top five attacks in 2009 targeted client-side vulnerabilities in widely used applications such as Internet Explorer and PDF readers. Suspicious PDF file downloads were the largest threat and accounted for 49 percent of all Web-based attacks, up from 11 percent in 2008.

Web browsers are also vulnerable - of the 374 vulnerabilities documented in Web browsers in 2009, 14 percent of them remain unpatched by the vendors. Firefox had the most vulnerabilities, but Internet Explorer was the most attacked. That difference illustrates cybercriminals' infatuation with market share.

What It Means
This data, as well as other information in the Symantec Internet Security Threat Report, offers a perspective that can change the way users and businesses operate. It is a framework for understanding what's out there and how to navigate it.

For businesses, such navigation includes employing strategies designed to give in-depth defense, including multiple, overlapping and mutually supportive defensive systems to guard against single-point failures in any specific technology or protection methodology. Security provided by solutions such as antivirus software, firewalls and intrusion detection are crucial if an organization wants to protect its assets and its employees.

Besides ensuring personal computers and networks are protected, individual users also need to use good judgment. If websites are untested or seem questionable, users need to be alert and perhaps even stay away from those sites. Another precaution to consider is disabling scripting and active content when casually browsing the Web.

Cybercriminals are getting more sophisticated, but knowing what they are up to allows businesses and individuals to place themselves strategically in the safest position possible. If you implement the right policies within your organization and use the tools that exist, you can help guard against malicious software and keep your organization's infrastructure, and the information within, safe from cybercriminals.

More Stories By Marc Fossi

Marc Fossi manages research and development for Symantec Security Response where his primary role is executive editor of the Symantec Internet Security Threat Report. The Internet Security Threat Report offers analysis and discussion of Internet threat activity and covers Internet attacks, vulnerabilities, malicious code, phishing, spam and security risks, as well as future trends.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.

@ThingsExpo Stories
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering Cloud Expo and @ThingsExpo will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at Cloud Expo. Product announcements during our show provide your company with the most reach through our targeted audiences.
@ThingsExpo has been named the Top 5 Most Influential Internet of Things Brand by Onalytica in the ‘The Internet of Things Landscape 2015: Top 100 Individuals and Brands.' Onalytica analyzed Twitter conversations around the #IoT debate to uncover the most influential brands and individuals driving the conversation. Onalytica captured data from 56,224 users. The PageRank based methodology they use to extract influencers on a particular topic (tweets mentioning #InternetofThings or #IoT in this ...
"We've discovered that after shows 80% if leads that people get, 80% of the conversations end up on the show floor, meaning people forget about it, people forget who they talk to, people forget that there are actual business opportunities to be had here so we try to help out and keep the conversations going," explained Jeff Mesnik, Founder and President of ContentMX, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
There is growing need for data-driven applications and the need for digital platforms to build these apps. In his session at 19th Cloud Expo, Muddu Sudhakar, VP and GM of Security & IoT at Splunk, will cover different PaaS solutions and Big Data platforms that are available to build applications. In addition, AI and machine learning are creating new requirements that developers need in the building of next-gen apps. The next-generation digital platforms have some of the past platform needs a...
Intelligent machines are here. Robots, self-driving cars, drones, bots and many IoT devices are becoming smarter with Machine Learning. In her session at @ThingsExpo, Sudha Jamthe, CEO of IoTDisruptions.com, will discuss the next wave of business disruption at the junction of IoT and AI, impacting many industries and set to change our lives, work and world as we know it.
Bert Loomis was a visionary. This general session will highlight how Bert Loomis and people like him inspire us to build great things with small inventions. In their general session at 19th Cloud Expo, Harold Hannon, Architect at IBM Bluemix, and Michael O'Neill, Strategic Business Development at Nvidia, will discuss the accelerating pace of AI development and how IBM Cloud and NVIDIA are partnering to bring AI capabilities to "every day," on-demand. They will also review two "free infrastruct...
More and more brands have jumped on the IoT bandwagon. We have an excess of wearables – activity trackers, smartwatches, smart glasses and sneakers, and more that track seemingly endless datapoints. However, most consumers have no idea what “IoT” means. Creating more wearables that track data shouldn't be the aim of brands; delivering meaningful, tangible relevance to their users should be. We're in a period in which the IoT pendulum is still swinging. Initially, it swung toward "smart for smar...
In past @ThingsExpo presentations, Joseph di Paolantonio has explored how various Internet of Things (IoT) and data management and analytics (DMA) solution spaces will come together as sensor analytics ecosystems. This year, in his session at @ThingsExpo, Joseph di Paolantonio from DataArchon, will be adding the numerous Transportation areas, from autonomous vehicles to “Uber for containers.” While IoT data in any one area of Transportation will have a huge impact in that area, combining sensor...
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, will discuss how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team a...
Join IBM November 2 at 19th Cloud Expo at the Santa Clara Convention Center in Santa Clara, CA, and learn how to go beyond multi-speed it to bring agility to traditional enterprise applications. Technology innovation is the driving force behind modern business and enterprises must respond by increasing the speed and efficiency of software delivery. The challenge is that existing enterprise applications are expensive to develop and difficult to modernize. This often results in what Gartner calls...
Although it has gained significant traction in the consumer space, IoT is still in the early stages of adoption in enterprises environments. However, many companies are working on initiatives like Industry 4.0 that includes IoT as one of the key disruptive technologies expected to reshape businesses of tomorrow. The key challenges will be availability, robustness and reliability of networks that connect devices in a business environment. Software Defined Wide Area Network (SD-WAN) is expected to...
The explosion of new web/cloud/IoT-based applications and the data they generate are transforming our world right before our eyes. In this rush to adopt these new technologies, organizations are often ignoring fundamental questions concerning who owns the data and failing to ask for permission to conduct invasive surveillance of their customers. Organizations that are not transparent about how their systems gather data telemetry without offering shared data ownership risk product rejection, regu...
The Internet of Things (IoT), in all its myriad manifestations, has great potential. Much of that potential comes from the evolving data management and analytic (DMA) technologies and processes that allow us to gain insight from all of the IoT data that can be generated and gathered. This potential may never be met as those data sets are tied to specific industry verticals and single markets, with no clear way to use IoT data and sensor analytics to fulfill the hype being given the IoT today.
@ThingsExpo has been named the Top 5 Most Influential M2M Brand by Onalytica in the ‘Machine to Machine: Top 100 Influencers and Brands.' Onalytica analyzed the online debate on M2M by looking at over 85,000 tweets to provide the most influential individuals and brands that drive the discussion. According to Onalytica the "analysis showed a very engaged community with a lot of interactive tweets. The M2M discussion seems to be more fragmented and driven by some of the major brands present in the...
Personalization has long been the holy grail of marketing. Simply stated, communicate the most relevant offer to the right person and you will increase sales. To achieve this, you must understand the individual. Consequently, digital marketers developed many ways to gather and leverage customer information to deliver targeted experiences. In his session at @ThingsExpo, Lou Casal, Founder and Principal Consultant at Practicala, discussed how the Internet of Things (IoT) has accelerated our abil...
19th Cloud Expo, taking place November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Meanwhile, 94% of enterpri...
SYS-CON Events announced today that Streamlyzer will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Streamlyzer is a powerful analytics for video streaming service that enables video streaming providers to monitor and analyze QoE (Quality-of-Experience) from end-user devices in real time.
You have great SaaS business app ideas. You want to turn your idea quickly into a functional and engaging proof of concept. You need to be able to modify it to meet customers' needs, and you need to deliver a complete and secure SaaS application. How could you achieve all the above and yet avoid unforeseen IT requirements that add unnecessary cost and complexity? You also want your app to be responsive in any device at any time. In his session at 19th Cloud Expo, Mark Allen, General Manager of...
Established in 1998, Calsoft is a leading software product engineering Services Company specializing in Storage, Networking, Virtualization and Cloud business verticals. Calsoft provides End-to-End Product Development, Quality Assurance Sustenance, Solution Engineering and Professional Services expertise to assist customers in achieving their product development and business goals. The company's deep domain knowledge of Storage, Virtualization, Networking and Cloud verticals helps in delivering ...
SYS-CON Events announced today that 910Telecom will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Housed in the classic Denver Gas & Electric Building, 910 15th St., 910Telecom is a carrier-neutral telecom hotel located in the heart of Denver. Adjacent to CenturyLink, AT&T, and Denver Main, 910Telecom offers connectivity to all major carriers, Internet service providers, Internet backbones and ...