Welcome!

Cloud Security Authors: Allwyn Sequeira, Pat Romanski, Liz McMillan, Jim Hansen, Peter Silva

Related Topics: Cloud Security

Cloud Security: Article

The Growth of Cybercrime

More people participate in cybercrime; threats continue to grow and evolve

Cybercrime saw significant growth in 2009. It increased in prevalence and geographic spread. The only thing that didn't grow was the skill level required to participate. It was easier for non-skilled attackers to conduct sophisticated attacks because of the availability of toolkits. The increase in manpower has led to an increase in most areas of cybercrime.

The growth of cybercrime has come despite a global recession that has stunted the growth of almost every other industry. The growth of cybercrime has been fueled by an increase in Internet users, especially those in developing countries.

However, businesses can protect their information from these pervasive dangers. Understanding the threat landscape is the first step. The following highlights from the Symantec Internet Security Threat Report XV can help organizations understand just what they're up against.

Cybercrime Keeps Growing
Malicious code is as prominent as ever. In 2009, Symantec identified more than 240 million distinct new malicious programs - a 100 percent increase over 2008. Last year Symantec blocked an average of 100 potential attacks per second.

Compromised confidential information continues to be an issue. Sixty percent of all data breaches that exposed identities were the result of hacking. This problem is not limited to a few larger enterprises. According to the Symantec State of Enterprise Security Report, 75 percent of all companies surveyed experienced some sort of cyber attack during the last year.

Cybercrime is a universal problem. Attackers have moved from using simple scams to launching highly sophisticated campaigns targeting some of the world's largest corporations and government entities. The scale of these attacks and the fact that they come from all over the world makes this an international problem requiring the cooperation of the private sector and global governments.

Less Skill Is Required to Engage in Cybercrime
The emergence of attack toolkits has made cybercrime available to anyone regardless of their computer knowledge and expertise. Novice computer users can purchase a kit and almost immediately begin deploying sophisticated and varied threats. Toolkits such as Zeus can be purchased for as little as $700. Some toolkits allow customization, resulting in many variants being created. Because there are an increasing number of cybercriminals entering the space, the number of threats is increasing and the number of people being affected is increasing as well.

Underground Economy a Bull
Credit cards and bank accounts continued to be the most advertised items on the underground economy in 2009 - illustrated in part by a notable increase in credit card dumps. Such dumps, which are sometimes referred to as cloned credit cards, increased by 150 percent from 2008 to 2009.

Social engineering tactics have changed to take advantage of the evolving financial landscape. More malicious messages incorporate themes such as refinancing loans, consolidating debt, reducing credit card interest rates, etc.

Enterprises Subject to More, Targeted Attacks
Cyber attacks are not just more sophisticated, they're also much more targeted. Many of them are full-fledged yet subtle campaigns. Cyber attacks remain undetected to penetrate deeply into the corporate network. While these targeted attacks have been occurring for several years, they have taken center stage recently, with incidents such as Hydraq.

Targeted attacks use zero-day vulnerabilities and spear-phishing type attacks. Attackers usually research a company and its employees by gathering information from corporate websites, news articles, social networks and other sites. Many targeted attacks aim to steal information about the organization's customers and employees, but other information - like intellectual property and corporate strategies - are also targeted.

Web-Based Attacks Are the Biggest Threat - and Are Getting Bigger
Four out of the top five attacks in 2009 targeted client-side vulnerabilities in widely used applications such as Internet Explorer and PDF readers. Suspicious PDF file downloads were the largest threat and accounted for 49 percent of all Web-based attacks, up from 11 percent in 2008.

Web browsers are also vulnerable - of the 374 vulnerabilities documented in Web browsers in 2009, 14 percent of them remain unpatched by the vendors. Firefox had the most vulnerabilities, but Internet Explorer was the most attacked. That difference illustrates cybercriminals' infatuation with market share.

What It Means
This data, as well as other information in the Symantec Internet Security Threat Report, offers a perspective that can change the way users and businesses operate. It is a framework for understanding what's out there and how to navigate it.

For businesses, such navigation includes employing strategies designed to give in-depth defense, including multiple, overlapping and mutually supportive defensive systems to guard against single-point failures in any specific technology or protection methodology. Security provided by solutions such as antivirus software, firewalls and intrusion detection are crucial if an organization wants to protect its assets and its employees.

Besides ensuring personal computers and networks are protected, individual users also need to use good judgment. If websites are untested or seem questionable, users need to be alert and perhaps even stay away from those sites. Another precaution to consider is disabling scripting and active content when casually browsing the Web.

Cybercriminals are getting more sophisticated, but knowing what they are up to allows businesses and individuals to place themselves strategically in the safest position possible. If you implement the right policies within your organization and use the tools that exist, you can help guard against malicious software and keep your organization's infrastructure, and the information within, safe from cybercriminals.

More Stories By Marc Fossi

Marc Fossi manages research and development for Symantec Security Response where his primary role is executive editor of the Symantec Internet Security Threat Report. The Internet Security Threat Report offers analysis and discussion of Internet threat activity and covers Internet attacks, vulnerabilities, malicious code, phishing, spam and security risks, as well as future trends.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
Who are you? How do you introduce yourself? Do you use a name, or do you greet a friend by the last four digits of his social security number? Assuming you don’t, why are we content to associate our identity with 10 random digits assigned by our phone company? Identity is an issue that affects everyone, but as individuals we don’t spend a lot of time thinking about it. In his session at @ThingsExpo, Ben Klang, Founder & President of Mojo Lingo, discussed the impact of technology on identity. Sho...
"Operations is sort of the maturation of cloud utilization and the move to the cloud," explained Steve Anderson, Product Manager for BMC’s Cloud Lifecycle Management, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
"I think that everyone recognizes that for IoT to really realize its full potential and value that it is about creating ecosystems and marketplaces and that no single vendor is able to support what is required," explained Esmeralda Swartz, VP, Marketing Enterprise and Cloud at Ericsson, in this SYS-CON.tv interview at @ThingsExpo, held June 7-9, 2016, at the Javits Center in New York City, NY.
The buzz continues for cloud, data analytics and the Internet of Things (IoT) and their collective impact across all industries. But a new conversation is emerging - how do companies use industry disruption and technology enablers to lead in markets undergoing change, uncertainty and ambiguity? Organizations of all sizes need to evolve and transform, often under massive pressure, as industry lines blur and merge and traditional business models are assaulted and turned upside down. In this new da...
Bert Loomis was a visionary. This general session will highlight how Bert Loomis and people like him inspire us to build great things with small inventions. In their general session at 19th Cloud Expo, Harold Hannon, Architect at IBM Bluemix, and Michael O'Neill, Strategic Business Development at Nvidia, discussed the accelerating pace of AI development and how IBM Cloud and NVIDIA are partnering to bring AI capabilities to "every day," on-demand. They also reviewed two "free infrastructure" pr...
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo 2016 in New York. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place June 6-8, 2017, at the Javits Center in New York City, New York, is co-located with 20th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry p...
It is one thing to build single industrial IoT applications, but what will it take to build the Smart Cities and truly society changing applications of the future? The technology won’t be the problem, it will be the number of parties that need to work together and be aligned in their motivation to succeed. In his Day 2 Keynote at @ThingsExpo, Henrik Kenani Dahlgren, Portfolio Marketing Manager at Ericsson, discussed how to plan to cooperate, partner, and form lasting all-star teams to change the...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @CloudExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.
SYS-CON Events announced today that IoT Now has been named “Media Sponsor” of SYS-CON's 20th International Cloud Expo, which will take place on June 6–8, 2017, at the Javits Center in New York City, NY. IoT Now explores the evolving opportunities and challenges facing CSPs, and it passes on some lessons learned from those who have taken the first steps in next-gen IoT services.
SYS-CON Events announced today that WineSOFT will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Based in Seoul and Irvine, WineSOFT is an innovative software house focusing on internet infrastructure solutions. The venture started as a bootstrap start-up in 2010 by focusing on making the internet faster and more powerful. WineSOFT’s knowledge is based on the expertise of TCP/IP, VPN, SSL, peer-to-peer, mob...
The explosion of new web/cloud/IoT-based applications and the data they generate are transforming our world right before our eyes. In this rush to adopt these new technologies, organizations are often ignoring fundamental questions concerning who owns the data and failing to ask for permission to conduct invasive surveillance of their customers. Organizations that are not transparent about how their systems gather data telemetry without offering shared data ownership risk product rejection, regu...
The Internet of Things can drive efficiency for airlines and airports. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Sudip Majumder, senior director of development at Oracle, discussed the technical details of the connected airline baggage and related social media solutions. These IoT applications will enhance travelers' journey experience and drive efficiency for the airlines and the airports.
With billions of sensors deployed worldwide, the amount of machine-generated data will soon exceed what our networks can handle. But consumers and businesses will expect seamless experiences and real-time responsiveness. What does this mean for IoT devices and the infrastructure that supports them? More of the data will need to be handled at - or closer to - the devices themselves.
SYS-CON Events announced today that Dataloop.IO, an innovator in cloud IT-monitoring whose products help organizations save time and money, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Dataloop.IO is an emerging software company on the cutting edge of major IT-infrastructure trends including cloud computing and microservices. The company, founded in the UK but now based in San Fran...
Big Data, cloud, analytics, contextual information, wearable tech, sensors, mobility, and WebRTC: together, these advances have created a perfect storm of technologies that are disrupting and transforming classic communications models and ecosystems. In his session at @ThingsExpo, Erik Perotti, Senior Manager of New Ventures on Plantronics’ Innovation team, provided an overview of this technological shift, including associated business and consumer communications impacts, and opportunities it m...
In his keynote at @ThingsExpo, Chris Matthieu, Director of IoT Engineering at Citrix and co-founder and CTO of Octoblu, focused on building an IoT platform and company. He provided a behind-the-scenes look at Octoblu’s platform, business, and pivots along the way (including the Citrix acquisition of Octoblu).
"delaPlex is a software development company. We do team-based outsourcing development," explained Mark Rivers, COO and Co-founder of delaPlex Software, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
SYS-CON Events announced today that CA Technologies has been named “Platinum Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. CA Technologies helps customers succeed in a future where every business – from apparel to energy – is being rewritten by software. From ...
SYS-CON Events announced today that Fusion, a leading provider of cloud services, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Fusion, a leading provider of integrated cloud solutions to small, medium and large businesses, is the industry’s single source for the cloud. Fusion’s advanced, proprietary cloud service platform enables the integration of leading edge solutions in the cloud, including cloud...
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, provided an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settle...