Corporate keylogger infections up 50 percent

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The number of companies reporting spyware infestation has increased by just under 50 percent over the past 12 months, according to a survey released by Internet security specialists Websense.

According to the annual Websense Web@Work survey, published on Tuesday, 17 percent of companies with more than 100 employees have spyware — such as a keylogger — on their network.

"This is almost 50 percent growth in the instances of keyloggers that organisations are reporting back," Joel Camissar, country manager for Websense said. "Despite the organisations having a best of breed antivirus, anti spyware and firewall, we are still detecting a huge amount of backchannel spyware communication".

One reason for this growth in spyware infestation is a massive increase in the number of spyware-making toolkits being sold online, said Camissar, who referred to some research that was conducted in partnership with the Anti-Phishing Working Group, earlier this year.

"In April 2005 there were 77 unique password stealing applications. In the latest March report there were 197. Unique Web sites hosing keyloggers in the same timeframe have gone up from 260 to 2157 — almost a 10 times growth," said Camissar.

The survey also discovered that survey respondents did not have much faith in their staff being able to distinguish between genuine and phishing Web sites.

"Forty-seven percent of IT decision makers said their employees have clicked on phishing emails and 44 percent believe employees cannot accurately identify phishing sites.

"I am surprised that the results are not showing a larger growth in the number of organisations hit by this kind of threat," added Camissar.

Talkback

With the amount of danger now escalating to companies from this sort of treat it will come as no surprise that businesses will be forced to remove general internet access from emplyees to protect themselves. It is inevitable unless ISP's and governments(that's ajoke) get together to stop the internet turning onto a no go zone

via Facebook 16 May, 2006 12:55
Reply

Problem is that the entire security landscape is still seriously underestimated. Most decision makers still think that they're almost there, safe enough or label it a next year problem. Most of them basing their conclusions on commercially sponsored opinion, sales talk and what their peers are doing. Which underlines a serious lack in liability in places that matter.

Another thing is that the bad guys are constantly and rapidly evolving. Customized penetration and information gathering is nothing new under the sun and the average "off the shelf" security solution won't catch it. Certainly not in the way most of those are implemented, configured, maintained and monitored (outsourced and all). Couple that with the masses of organizations that never fail to bring in the latest and greatest gadgets that seriously weaken overall security (smartphones, PDA's, smart watches, WiFi, VPN, USB devices, iR, BlueTooth. Not to mention social engineering, bribed co-workers, smart PABX systems, consolidated centralization, waste bins, etc, etc) without giving too much thought on keeping on top of things, if any (most IT departments are overflooded with following support questions and incidents anyway, or worse: go the 'not my problem' route), and get their act together.

In other words, as long as the right people don't take responsibility or are not made responsible enough we're condemned to do what we've done the last ten years or so: carrying water to the sea while thinking we're not there yet but almost anyway.
Nothing short of a few worldwide disasters in a row will wake us from that dream state. And we've had a few in the mean time. Just not enough serious enough ones in a short enough amount of time. How quickly people forget.

Oh right, we've got politicians and commercial lobbiests bringing us new laws and technologies as the one and only answer to all the problems they in fact shoved down our throats. And for some reason or another we're not to believe that's mostly to protect self interest at the cost of various consumer and citizens rights, budgets and choices. DRM to the rescue? Who's rescue anyway? Updated IP laws for protection? Who's protection anyway? More power to the powerfull? Who's power anyway?

Back to the practical part. Either way, by following the commercially preferred way in solving the latest security issues and then the next and then the next and so on, or doing a root cause analysis and opt for more lasting solutions on the basis of a solid foundation, most organizations are facing yet again huge investments (time, budget, resources) to get things modernised because not doing anything will increase their risk of becoming a victim (including falling too far behind) as time goes by. Nothing new under the sun. Next year we'll know if they've learned anything or are setting themselves up to repeat the same mistakes in creative new ways.

via Facebook 16 May, 2006 23:46
Reply

The keyboard hardware manufacuturers need to get together with the OS programmers and set up a hardware public/private key encryption. Set by the keyboard, all text sent to the computer would need to be decoded to be processed.

Bump, no problem, ever again.

via Facebook 20 May, 2006 23:45
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

37 minutes ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

2 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

3 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

4 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

4 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

5 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

7 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

13 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

15 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

15 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

16 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

17 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

18 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

18 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

18 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

19 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

19 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

20 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

20 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

20 hours ago by Moley on ACTA: Facts, misconceptions and questions