CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Commvault Simpana® 10
Protect, manage, access, and
realize the untapped value of data.

www.commvault.com
Tuesday, June 18th 
Panasonic Toughbook® mobile computers
Home
Enterprise Software
Enterprise Hardware
Network Security
Cloud & Virtualization
CRM Systems
Data Storage
Unified Communications
Operating Systems
CIO Issues
Mobile Tech
Chips & Processors
Small Business
World Wide Web
Business Briefing
After Hours
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement


Network Security

IBM X-Force Trend and Risk Report Offers More Good Security News than Bad

IBM X-Force Trend and Risk Report Offers More Good Security News than Bad
March 22, 2012 12:05PM

Bookmark and Share
"Computer Security is getting better. We're seeing less exploit code getting released on the Internet. We're seeing the quality of software improve. We're seeing software vendors get more diligent about patching security vulnerabilities," said Tom Cross on IBM's X-Force 2011 Trends and Risk Report.

Forrester Research Inc., Report from AT&T: As employees bring a wide range of devices to work, 54% of companies are turning to Bring-Your-Own-Device programs. The result: rising productivity, efficiency, and even morale. But can the obvious benefits justify the hidden costs and challenges? Find out by clicking here.

IBM on Thursday released the results of its X-Force 2011 Trend and Risk Report -- and there is some good news and some bad news.

First the good news. The X-Force 2011 Trend and Risk Report revealed a 50 percent decline in spam e-mail compared with 2010, more diligent patching of security vulnerabilities by software Relevant Products/Services vendors, and higher quality of software application code. However, attackers have countered with an increase in automated shell command injection attacks against Web servers.

"The most surprising result to me has been the two- to three-fold increase in shell command injection attacks. I would not have predicted that particular attack vector would grow so much in popularity at this stage of the game," said Tom Cross, manager of Threat Intelligence and Strategy for IBM X-Force.

"X-Force believes that this activity may be an adaptation to the fact that Web site operators are working to fix SQL Injection vulnerabilities and may be missing shell command issues that are also lurking within their Web applications."

A Mixed Bag of News

For years, SQL injection attacks against Web applications have been a popular vector for attackers of all types, IBM said. SQL injection vulnerabilities allow an attacker to manipulate the database behind a Web site.

As progress has been made to close those vulnerabilities, IBM reports some attackers have now started to target shell command injection vulnerabilities instead. These vulnerabilities allow the attacker to execute commands directly on a Web server. IBM said Web application developers should pay close attention to this increasingly popular attack vector.

Back to the good news. There was a 39 percent decline in the availability of exploit code. And although some security vulnerabilities are never patched, in 2011 this number was down to 36 percent from 43 percent in 2010. IBM also witnessed a 50 percent reduction in cross-site scripting (XSS) vulnerabilities due to improvements in software quality.

"Computer Security is getting better. We're seeing less exploit code getting released on the Internet. We're seeing the quality of software improve. We're seeing software vendors get more diligent about patching security vulnerabilities," Cross said.

"We've still got a lot of work to do. There are still many vulnerabilities out there and attackers are taking advantage of them, but our statistics show that progress is being made -- all of the work that is going on to make software more resilient is making a difference." (continued...)

1  |  2  |  Next Page >

 

Tell Us What You Think
Comment:

Name:

Al:

Posted: 2012-04-05 @ 11:15am PT
It sure would be nice to have a LINK TO THE REPORT.

Advertisement



 Network Security
1. Prism's Secret: Bigger Data Seizure
2. Keeping Your Data Safe from Spying
3. Google Uses Secure FTP for NSA
4. Google Reports Iran Phishing Attacks
5. Is Snowden Traitor or Public Servant?


advertisement


 Most Popular Articles
1. New Nvidia Chip Boosts Citrix Graphics for Remote Workers
2. Verizon Enters Cloud Storage Wars with a Wisp
3. Dell Kills Its Public Cloud Effort, Will Offer Partner Marketplace
4. What's in Store for Apple's iOS 7?
5. Will BlackBerry Fans Flock to the Q10 and Its Keyboard?

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Huawei Phone Is a Quarter-Inch Thin
  Yahoo, Apple Disclose Data Requests
  Free Video Messaging Comes to Skype
  Prism's Secret: Bigger Data Seizure
  Judge in Microsoft Antitrust Case Dies

 Technology Marketplace

BYOD & MDM
Forrester Research Inc., Report: BYOD from AT&T. Make everyone more efficient.
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
Improve your customer relationships with Microsoft Dynamics
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
Improve your customer relationships with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Hardware
Panasonic Toughbook® mobile computers are built to keep you running.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Hardware
The best document scanner for you? Try KODAK's scanner selector
 
Innovation
The best document scanner for you? Try KODAK's scanner selector
 
Laptops & Tablets
Panasonic Toughbook® mobile computers are built to keep you running.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Mobile Enterprise Spotlight

Why Google's Project Loon is Smart Business
Google is once again proving that it's much more than a search engine or even a mobile-device company, with Project Loon. The initiative aims to bring "balloon-powered Internet" to isolated areas of the world.

Authorities Want Smartphone 'Kill Switch' To Fight Thefts
Law enforcement authorities are calling on the smartphone industry to adopt "kill switch" technologies that would deter theft by squeezing the market for selling stolen devices, which would be worthless if "bricked."

Small Business Gets Boost from Mobile Marketing
Aside from the requisite e-commerce tricks, small businesses are turning their attention to the mobile arena to engage social media-savvy customers, as mobile marketing tools offer more channels.

Advertisement
Enterprise Hardware Spotlight

Samsung Offers Tiny, Superfast PCIe SSDs for Ultrabooks
Solid-state drives are continuing their march forward. On Monday, Samsung Electronics announced it has started to mass produce the first PCI-Express 3.0 SSDs for the new wave of Ultrabooks.

Amazon.com Joins 3D Printer Craze, Enabling Wide Availability
Commercially available 3D printers have recently moved from being expensive hobbyist devices to being pricey but accessible consumer and manufacturing machines. And now, Amazon.com will sell 3D printers & supplies online.

New Facebook Data Center Uses All Home-Grown Servers
Facebook has opened its new data center in Lulea, Sweden. The data center is a first in two ways: the first in Europe and the first to be equipped with all Facebook-designed, Open Compute servers.

Advertisement
Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Network Security | Cloud & Virtualization | CRM Systems | Data Storage
Unified Communications | Operating Systems | CIO Issues | Mobile Tech | Chips & Processors | Small Business | World Wide Web
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 CIO Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.