Home

Microsoft Maps 10 Years Of Malware

Comments | Kelly Jackson Higgins, Dark Reading | March 06, 2012 11:47 AM


RSA CONFERENCE 2012--San Francisco-- A lot can happen in 10 years, and that's an understatement when it comes to malware: According to new data released by Microsoft this week, the number of malware variants went from 1,000 in 1991 to millions in 2011.

In celebration of the 10-year anniversary of the launch of its Trustworthy Computing initiative, Microsoft published a special edition of its Security Intelligence Report (SIR). "What we wanted to do from the Security Intelligence Report was look at the past 10 years and how the threat landscape" has evolved, said Tim Rains, director of Microsoft's TwC. "A lot of these samples were new variants of a same family."

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Among the more telling trends was the near disappearance of worms and the continued surge in socially engineered malware threats and Trojans. Rains said as companies such as Microsoft build better and less buggy software, the bar gets raised for attackers. Hence the jump in socially engineering attacks that lure users into opening infected attachments or clicking on malicious links that spread Trojans, he said. "Social engineering is probably a mainstay now," Rains said.

The report looks at the "cleanest" countries malware infection-wise. Finland had the lowest rate of infected machines in 2011, with just over one infected machine per 1,000 machines. Japan had just over two per 1,000 machines; followed by Norway, Switzerland, and Australia, all of which had fewer than four. On average, Microsoft cleans up 10 machines per 1,000 globally.

Turkey (57); Korea (20); Brazil (just under 20); Taiwan (more than 15); and Spain (just over 10) didn't fare as well. "We wondered why Finland and others were so low," Raines said, so Microsoft did a case study on one of Finland's largest ISPs, TeliaSonera.

Rains saidTeliaSonera wanted security to be a competitive differentiator in its services. In the wake of the Rustock botnet takedown and Microsoft's Digital Crimes Unit giving Finland's CERT a list of Rustock-infected IP addresses, TeliaSonera found that it was taking an average of 40 minutes per customer to clean up the machines. So they automated the process, and used the Rustock data from Microsoft's DCU to identify infected machines on its network and kept them quarantined until they were cleaned up.

Read the rest of this article on Dark Reading.

SSL is widely deployed, yet enterprises still struggle to manage it and ensure its effectiveness. Companies must understand the threats, know how to use SSL internally, and assure it functions properly and protects their data. In our SSL Authentication report, we show you how to address the security and operational issues inherent in creating and managing internal SSL certificate authorities. (Free registration required.)



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events