Tampilkan postingan dengan label virus update. Tampilkan semua postingan
Tampilkan postingan dengan label virus update. Tampilkan semua postingan

Minggu, 20 Februari 2011

Symantec and Disaster Preparedness

Small and medium sized businesses are not taking disaster preparedness for their computers and networks as seriously as they should, according to survey results released by Symantec.

The Symantec 2011 SMB Disaster Preparedness Survey found that that most SMBs don't take action to prepare for disasters until after they have experienced loss from downtime, and that this lack of preparation has a significant impact on their customers and their business.
Disaster Plans
Only half (50 percent) of the respondents to the global survey said they already have a plan in place to deal with an outage or disruption to their computer or technology resources. That's up slightly from 47 percent in the 2010 survey, but 14 percent do not have a plan, nor do they have any intention to create one.

Fifty-seven percent of small businesses don't have a plan, compared to 47 percent of medium businesses. Of the respondents who plan to implement a plan in the future, 16 percent plan to do so within 30 days, 34 percent plan to do so between one and three months and 25 percent plan to do so between three and six months. Even though only half of respondents have a plan, 81 percent of all respondents are somewhat/very satisfied with their plans to deal with outages or disruptions, whether formal or informal; indeed, 84 percent state that their computer systems are somewhat/completely protected.

When those who do not have a plan were asked why not, roughly half (52 percent) don't think computer systems are critical to the business. Forty-one percent said that it never occurred to them to put together a plan, and 40 percent said that disaster preparedness is not a priority.

It is alarming that more SMBs do not have plans to help them deal with disasters and keep their computer systems up and running, especially when one considers that 65 percent of SMBs reside in regions that they consider susceptible to natural disasters.

In fact, SMBs experienced a median of six outages in the past year. The top three reasons for downtime include cyber attacks, power outages, employee errors and upgrades, with each occurring a median of once per company in the last year.

Of SMBs with a disaster preparedness plan, half (50 percent) implemented the plan due to either an outage or data loss. Fifty-two percent put together their plans within the last six months. Again, there were some differences according to company size. Thirty-six percent of small businesses with a disaster preparedness plan implemented their plan within the last six months, compared to 58 percent of medium businesses.
Advice from Symantec: Don't Wait Until It's Too Late
It is critical for SMBs to not wait until after a disaster to think about what they should have done to protect their data. Not only is downtime costly from a financial perspective, but it could mean the complete demise of the business. SMBs can't wait until it is too late, and they need to begin mapping out a disaster preparedness plan today. A plan should include identification of key systems and data that is intrinsic to the running of the business. Basically, identify your critical resources.

Symantec also advises SMBs to test their disaster plan frequently. (Only 28 percent of respondents have actually tested their recovery plans.) If frequent testing is not feasible due to resources and bandwidth, SMBs should at least review their disaster preparedness plan on a quarterly basis.

After a disaster hits is the worst time to learn that critical files were not backed up as planned. Regular disaster recovery testing is invaluable. Test your plan anytime anything changes in your environment.
Information Protection
The survey also found that SMB information is not protected. Only half of companies surveyed back up at least 60 percent of their data, and less than half back up their data weekly or more frequently. Only 23 percent back up daily.

Of those surveyed, 31 percent do not back up email, 21 percent do not back up application data and 17 percent do not back up customer data. Respondents also reported that a disaster would cause information loss. Forty-four percent of SMBs said they would lose at least 40 percent of their data in the event of a disaster.
Advice from Symantec: Protect Information Completely
To reduce the risk of losing critical business information, SMBs must implement the appropriate security and backup solutions to archive important files, such as customer records and financial information for the long term. Natural disasters, theft and cyberattacks can all result in data and financial loss, so SMBs need to make sure important files are saved not only on an external hard drive and/or company network, but in a safe, off-site location.
The Consequences of Being Unprepared
Disasters can have a significant financial impact on SMBs. Downtime costs SMBs a median of $12,500 per day. It costs small businesses a median of $3,000 per day and medium businesses a median of $23,000 per day.

Outages also have a considerable effect on SMB customers. SMB customers reported that SMB outages cost them $10,000 per day, and 29 percent said they lost "some" or "a lot of" data as a result of disasters impacting their SMB vendors.

Downtime also causes customers to leave with 54 percent of SMB customer respondents reporting they have switched SMB vendors due to unreliable computing systems, a 12 percent increase compared with last year's survey.

For many SMBs, disasters could also put them out of business. Forty-four percent of SMB customers stated that their SMB vendors have temporarily shut down due to a disaster.
Advice from Symantec: Get Employees Invested in Protection
SMB employees play a key role in helping to prevent downtime and should be educated on computer security best practices and what to do if information is accidentally deleted or cannot easily be found in their files. Since SMBs have few resources, all employees should know how to retrieve the businesses' information in times of disaster.

Jumat, 18 Februari 2011

Scareware Scam

Scammers are apparently using Google's URL shortening service, goo.gl, to distribute bogus links. The links take users to a scareware sight that purports to find malicious software on the user's computer, then offers to sell the user an AV product to solve the supposed problem. URL shorteners are commonly used in Twitter, but they can disguise a malicious link's true nature.Twitter has been hit by fast-spreading spam using Google's (Nasdaq: GOOG) goo.gl URL shortening service.

The attack sends malicious links that take recipients clicking on them to a website hosting the "Security Shield" antivirus software program.

When users land on that site, they are essentially tricked into downloading and paying for the Security Shield application.

Twitter is resetting the passwords of accounts that are spreading the malicious link.
The Anatomy of the Fake AV Attack

The attackers send out tweets containing a link from the goo.gl shortened link service. This service and others like it compress long URLs into shorter ones, making them easier to fit into services like Twitter, which places a strict limit on the number of characters each tweet may contain. However, the services can also disguise the true nature of a link by hiding its actual URL.

Anyone clicking on the link is taken through two bounces to a website hosting the "Security Shield" fake antivirus program. Visitors are told they have suspicious applications running on their PCs and are urged to run a scan.

The scan shows the victim's PC is infected, and the website then asks the user to download and pay for the Security Shield application.

There's some uncertainty as to how the attacks were launched in the first place.

"It probably began by phishing of some sort," Adam Wosotowsky, principal engineer at McAfee Labs, told TechNewsWorld. "Possibly a social media worm like Koobface."

Variants of the Koobface worm have been used to attack Twitter for some time. This worm was initially targeted at Facebook, which it has attacked repeatedly over the years.

"It's not a worm," Graham Cluley, a senior technology consultant at Sophos, told TechNewsWorld. "It's a spam campaign that points to malicious software."

The attack could have occurred because users were using the same passwords on another website that was compromised, Cluley said.
Dynamite Comes in Small Packages

This fake AV attack is the latest in a series of attacks hitting Twitter in which shortened URLs were used.

In December, a Twitter worm using the goo.gl URL shortening service hit Twitter. In that attack, victims were reportedly first redirected to the compromised website of a French furniture company before being redirected to other domains.

In February of 2010, Twitter users were flooded with short URLs prefaced with the message "This you???" that led them to a fake Twitter login page, according to Andrew Brandt, a member of Webroot's threat research team.

"Twitter almost always involves shortened URLs -- whether they be good or bad," Sophos' Cluley said. "Shortened URLs can, of course, obscure from the unwary user the eventual destination that they will be taken to."

In November, a Symantec (Nasdaq: SYMC) blog post warned that hackers were substituting legitimate shortened URLs included in tweets with different ones pointing to malicious websites after scanning the Twitter homepage to pick the most trendy topics.
Between the Devil and the Deep Blue Sea

It's not as if people are oblivious to the danger posed by shortened URLs.

At least as early as 2009, security Enterprise Payment Security 2.0 Whitepaper from CyberSource experts were warning about the danger of URL shortening.

In September, McAfee launched a secure short URL service.

In December, University of Tulsa computer science student Ben Schmidt created his own URL shortening service, d0z.me, which he dubbed "The Evil URL Shortener," that doubles as a weapon for issuing distributed denial-of-service attacks as a proof-of-concept project.

McAfee Labs warned in its threat predictions for 2011 that social media sites with URL-shortening services will lead all other such sites in terms of cybercriminal activity.

"Shortened URLs can be a danger sign," David Harley, an ESET senior research fellow, told TechNewsWorld. "Black hats do use them to hide the real destination in a number of contexts."

Black hats are malicious hackers.

However, it's not feasible to ban shortened URLs outright.

"Shortened URL sites are not 100 percent malicious, so blocking the domain outright can cause false positives, which researchers generally try to avoid," McAfee's Wosotowsky pointed out. "Goo.gl is an example of a site that's associated with Google, which might frown upon blocking the domain. This allows spammers to continually abuse the site."

Malware Is on the Move

Mobile operating systems are the new favorite target of malware, and social engineering remains the favorite old standby for launching attacks. Tried-and-true preventive care works best. "Never give information via email, smartphone or on the Web, and verify independently before you click on any unknown text or email message, game, application or security update," advises UVa security expert Karen McDowell.Cybercriminals are following innocent consumers away from email Increase sales with VerticalResponse. Free trial. and toward more popular, smartphone-style platforms, McAfee reported Tuesday.

"New mobile malware in 2010 increased by 46 percent compared with 2009," noted McAfee spokesperson Joris Evers.

Among the likeliest targets in 2010, Symbian and Android platforms were splattered by Trojans and bots with names like "SymbOS/Zitmo.A" and "Android/Geinimi."

"Consumers need to realize that mobiles, whether smartphone or tablet, are mini computers," said David Gorodyansky, CEO of AnchorFree. "This means all the vulnerabilities of a computer exist, often with a less-protected OS."

"From a hacker's point of view, the large user base created by wide scale adoption of iOS (iPhone) and Android will increasingly make these platforms a target, and I definitely expect to see some high-profile mobile attacks in the coming year," Cenzic CMO Mandeep Khera told TechNewsWorld.

"Smartphone access should be a concern to corporations that don't want employees accessing company secrets via unsecured mobile networks," Khera told TechNewsWorld. "For consumers, as banks and e-commerce sites deploy apps that give customers unprecedented access to their bank accounts, security Enterprise Payment Security 2.0 Whitepaper from CyberSource becomes more important than ever."

Unlike their mobile partners in crime, spam bots -- including Bredolab, Lethic, Xarvester, and parts of the Zeus botnet -- have gone dormant in droves this year,.

"Concurrently, spam accounted for 80 percent of total email traffic in Q4 2010, the lowest point since the first quarter of 2007," McAfee's Evers told TechNewsWorld.
The Bot Pack

Like a flu pandemic, botnet infections were particularly acute in Q4 2010, with Rustock, Cutwail and Bobax leading the bot pack. Social media sites, like mosquitoes, often acted as disease vectors.

"Whether we are using smartphones or computers, social engineering attacks are still the primary attack vector, and a major vector in the spread of botnet infections," University of Virginia information security analyst Karen McDowell, PhD, GCIH, told TechNewsWorld.

McAfee advises tablet and smartphone users to watch out for Zeus-Murofet, Conficker, and Koobface botnets specifically, and more generally, phishing URLs from the IRS, gift cards, rewards accounts, and social networking accounts.

Phishing vectors spread bot diseases when users click on phishing emails, answer phishing phone calls, or click on text messages that "appear to come from your carrier," McDowell explained, adding that tried-and-true preventive care works best. "Never give information via email, smartphone or on the Web, and verify independently before you click on any unknown text or email message, game, application or security update."

More preventive options: "Don't log onto unprotected WiFi, and use a VPN to encrypt and secure your browsing, which acts as a secure, encrypted tunnel for your communications," AnchorFree's Gorodyansky told TechNewsWorld.
Malware's Mantra

Twenty million new pieces of malware -- nearly 55,000 new malware threats every day -- plastered the cybersphere in 2010, migrating toward smartphones because "cybercriminals are keeping tabs on what's popular and what will have the biggest impact from the smallest effort," said Vincent Weafer, senior vice president of McAfee Labs.

"Think globally, act locally" might be malware's new mantra, with threats that "now tend to match the types of users, habits and events that are specific to a region," McAfee's Evers added. Global criminal favorites include AutoRun malware such as Generic!atr; banking Trojans and downloaders such as PWS or Generic.dx; and Web-based exploits such as StartPage and Exploit-MS04-028, the McAfee report claims.

To avoid malware, treat search terms and Adobe (Nasdaq: ADBE) products with extra care, McAfee advises. Of the top 100 search results, 51 percent led to malicious sites. And throughout 2010, malware developers exploited weaknesses in Flash and PDF, a trend McAfee sees continuing.

Despite the advice, pests will persist, driven to infect by "a general lack of awareness towards the need for security," Gorodyansky explained.

"This is the same as it was for computers, when most people thought they were completely safe once they installed an antivirus program," he recalled.

"It really doesn't matter what type of device is used -- the steps to secure a Web application haven't changed," Sam Shelby, e-government coordinator for the City of Columbia, Missouri, told TechNewsWorld. "You can never trust input: always authenticate, validate and sanitize input data."