Microsoft study finds Trojans are biggest threat

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Vulnerabilities are decreasing but becoming easier to exploit; Trojans are the biggest threat; and Chinese computers are infected with more browser-based exploits than anywhere else. Those are the findings of the Microsoft Security Intelligence Report, due to be released on Monday.

Covering the first half of this year, the report provides statistics compiled from Microsoft's Malware Protection Center that reveal trends about threats, breaches and infection rates.

"Industry-wide, we've seen a decrease in the last 12 months in vulnerabilities across products, [down nearly 20 percent from the year-ago period]," George Stathakopoulos, general manager of Microsoft's Trustworthy Computing Group, said in an interview.

Meanwhile, the percentage of disclosed vulnerabilities that are easiest to exploit increased, with 56 percent requiring a low complexity exploit, according to the report.

Operating system vulnerabilities continued to decline, representing about six percent of disclosed vulnerabilities with more than 90 percent found in applications.

And vulnerabilities in Microsoft software continued to trend down, by about one-third from the second half of 2007. About one-third of vulnerabilities disclosed in Microsoft software had publicly available exploit code.

Microsoft released patches for 77 security vulnerabilities during the first half of 2008, with 25 having publicly available exploit code.

The total amount of malware and unwanted software removed from computers worldwide in the first half of the year increased more than 43 percent from the second half of last year. Trojan downloaders accounted for more than 30 percent of that.

Of the computers serviced by Microsoft's Malicious Software Removal Tool, which runs on every PC that gets Windows updates, an average of 10 out of 1,000 are found to be infected worldwide, Stathakopoulos said. In the US, the infection number is 11.2 per 1,000. The lowest infection rate is in Japan, at 1.8 infected computers per 1,000, and at the other end is Afghanistan at 76 machines per 1,000, he said.

Downloaders or droppers, software that drops back doors on to computers, remained the most prevalent threat category. More than 96 percent of the computers cleaned in this category were attributed to two Trojan families: Win32/Zlob and Win32/Renos, the report said.

"Defences against viruses and spyware work pretty well," said John Pescatore, an analyst at Gartner. "But the numbers are growing for Trojans; things are getting right through the antivirus and spyware software. It's not stopping the targeted malicious executables."

The changing landscape of vulnerabilities, with social engineering attacks plaguing PCs means companies should change their strategy for how they protect the corporate network, said Don Retallack, an analyst at Directions on Microsoft.

"Companies and organisations may want to do some employee training rather than counting on [software] configuration management," he said.

The report also has some interesting statistics specific to different countries. For instance, China has a high level of browser-based exploits, accounting for 47 percent of all incidents, followed by the US with 23 percent of incidents, the report found.

China is at the top of the list because the software developers there are not as disciplined in writing code with security in mind and the huge market is an attractive target for malware writers, Stathakopoulos said.

In Brazil, password stealers dominate; viruses are big in Spain; in Italy it's unwanted software led by the peer-to-peer client Wi32/BearShare; while in Korea viruses are the biggest threat.

Microsoft Security Intelligence Report
China gets more browser-based exploits than any other country, according to the Microsoft Security Intelligence Report for the first half of 2008
 

Talkback

"Companies should change their strategy for how they protect the corporate network".
How about the OS manufacturer change the way their OS is constructed to prevent trojans from getting in?

ator1940 4 November, 2008 13:13
Reply

We can manage this problem by restricting which applications can execute on an endpoint or server - by using Application Control.

Application Control keeps out malware by proactively controlling the applications that can execute on a network servers, terminal services servers, thin clients, laptops or desktops.

By employing a whitelist approach, Application Control enables only authorised applications to run on a network, laptop or PC - facilitating security and systems management, while providing the necessary flexibility to the organisation.

lumension 5 November, 2008 11:54
Reply

It is true that antivirus software plays an important part on organizations network security.
It is also true that in many cases it’s not, for example industrial networks (clients not connected to internet) virus signatures are not updated quickly enough leaving the systems with a false sense of protection. (+ the resources consumption)
The truth is that if you are only blocking endpoint data extractions and not usage (read-execution) your network is vulnerable to be infected by the simple use of a CD or USB removable drive at any endpoint.
So, if you have in place antivirus software (signatures not up to date) or your network is unlucky enough to be a virus debutant (get it before its known) and you have endpoint security that allows usage of CDs for example. Your real protection value against trojans is 0. (+ the resources consumption)
Therefore the importance of endpoint security software in preventing virus or Trojans entrance without the luck factor.

Endpoint security software solutions should not provide one way security (meaning block only extractions) pseudo read-only because execution is also allowed.
The truth is that to be able to allow usage of removable storage devices the only method that makes sense is to authorize specific storage device to operate at a specific client for a specific duration, and monitor file extractions. Or completely disallow usage when not required.
To provide options that diminish the protection value of the software regarding Trojans or virus entrance to minus 0 does not make sense. (And is misleading by nature)
Regarding removable storage devices, effective network endpoint protection should only provide the following options to be straightforward:
a) Block (protected)
b) Authorize specific a device and monitored (block all other devices of the kind except the approved device)
c) No action taken. (Unprotected)
One could argue that as long as one way “protection” is provided as an option its fine. (You don’t have to use it)
Have you wonder how unnecessary options affect the protection value of your solution. The truth is that options always bring compromise at development.
If you need to protect your organizations assets implement endpoint security that is straightforward to your real needs and not resources consuming ,blotted, weakened by options solutions.

usb-lock-rp 5 November, 2008 15:56
Reply

ator1940 is correct that the operating system design is at fault for the majority of Trojan attacks/infestations simply because so many programs and operating options require Admin or near-admin privileges in Windows. I find though that most of the issues related to security of the OS are actually the results of bad decisions made by Microsoft management.

You can't operate Windows XP Pro even with SP3 on it without having Admin level access to an awful lot of the system. The alternative Microsoft OS, Vista was worse because it aggravated the user to such an extent and more than the Trojan infestation! Instead of sticking with it, users turn off the security features due to the freaking annoyances. Perhaps with SP1 Vista operates better but I'm not willing to go through evaluating Vista again after my experiences with the RCs and the public Beta.

The second operating system defect issue is the apparent ease at which malware seems to be able to elevate its privilege level even if the user isn't operating at Admin level. There is a fundamental problem with the OS if a downloaded script or HTA program can elevate itself above the security level of the current user. I point the finger straight at Internet Explorer as the guilty party. The decision made by Bill Gates and others to push the browser into the OS was the biggest freaking "pointy-haired Boss" mistake of all software management time.

Operating ANY browser on the Internet is a security risk and as such it should be isolated as much as possible from the rest of the operating system perhaps even to the extent that it operates in its own VM. If Microsoft wants to win me back as a supporter, one thing they could do is to do exactly that. That can be done right now today EXCEPT for some previous bad decisions made by Microsoft.

They need to offer a FREE special configuration of IE8 or 9 that operates totally isolated in its own VM and operable on XP Pro, Vista and Windows 7 when its released. That would require that they open up the EULA terms enough to allow a user to run two instances of the same XP or Vista license on the SAME system, something that VPC2007 doesn't currently allow. (Again a STUPID move Microsoft!) Two more tools to stick into the mix would be the Vista firewall and the Windows Defender into the IE configuration with the VM. That likely would allow the users that cared, a means to prevent their systems from becoming netbots.

Xwindowsjunkie 17 November, 2008 04:11
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

7 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

13 hours ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

14 hours ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

14 hours ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

19 hours ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

20 hours ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

23 hours ago by awbMaven on US indicts Romanian over NASA climate change hack
subhorup

It simultaneously worries me and uplifts me that a self-proclaimed group of internet activists name themselves after Indian mythical figures....

1 day ago by subhorup on Anonymous activists release PCAnywhere source code
naviathan

It's actually far easier to work anonymously on the internet than you think. With tools like Tor bouncing your traffic around the world before...

1 day ago by naviathan on Anonymous activists release PCAnywhere source code
Agnostic_OS

1000272134 and bluedalmatian with you both there but then I'm still in 10.04 land (and happy with it)

1 day ago by Agnostic_OS on Ten factors that make Ubuntu 11.10 a hit
apexwm

Interesting article and definitely see your points on the products mentioned. One of the top products for our Help Desk (approximately 20% of all...

2 days ago by apexwm on Ten flawed products that derail productivity
Paul Hutchinson

Absolutely - this should obviously not be handled my isp - but handled by their hosting operator. What's been suggested here is that my isp police...

2 days ago by Paul Hutchinson via Facebook on MPs urge ISPs to take down terrorist material
Techs UK

Looks like a great phone. I don't notice any deficiencies in WP7. used IOS before, that's pretty good. I don't spend much time in Apps, all i need...

2 days ago by Techs UK on Nokia pins US 're-entry' hopes on Lumia 900
Larry Bloggy

Now with the help of these apps you are always synced with MS outlook while on the move. Just download apps like xobni or outlookreflex and get...

2 days ago by Larry Bloggy via Facebook on Outlook Social Connector beta 2 and the LinkedIn connector
mike40g123

Your details are wrong. The version currently being made is the one with 2 USB ports, 256MB RAM and a network port. This is the Model B. The...

2 days ago by mike40g123 on Raspberry Pi boards set to go on sale
Moley

The thing that has been puzzling me for quite a while is how Anonymous can remain anonymous whilst not only being active on the Internet but also...

3 days ago by Moley on Anonymous activists release PCAnywhere source code
Don Dilly

If what Semantec is saying is rue, that is even worse and shows a complete disregard for thier users. If what Anonymous claims is true and the...

3 days ago by Don Dilly via Facebook on Anonymous activists release PCAnywhere source code
MattChurchy

Didn't seem particularly biased to me either. Oh though you might have mentioned some other competitors with free search and email services...

3 days ago by MattChurchy on Time for an evil umpire: Google, Microsoft & privacy
Simon Bisson and Mary Branscombe

James - exactly as much as anyone paid you for your comment; I don't feel that I need to say that I'm independant and unbiased, but just for you...

3 days ago by Simon Bisson and Mary Branscombe on Time for an evil umpire: Google, Microsoft & privacy
Carl White

Once they realise symantec are willing to pay real money, they will simply keep extorting, unless of course symantec/authorities can use the...

3 days ago by Carl White via Facebook on Symantec offered hackers $50k in source code sting