Technology Sectors

Market Sectors

Fortinet’s 2010 security trends predictions already ring true

Fortinet’s FortiGuard Labs threat researchers issued a report in January 2010 giving their predictions for the top ten security trends of the year. Six months later, they decided to have a halfway review.

In a special interview with GSN: Government Security News, Derek Manky, project manager for cyber-security and threat researcher at Fortinet of Sunnyvale, CA, a IT security provider, reviewed one by one the ten threats and gave his insight on them.

Manky first highlighted the risks of having several computers linked to one server, because in the event of a server being attacked, then all the computers might be compromised. He also mentioned the hazard of controlling any information the user stores on a server when the information is shared.

 Manky also explained the risks linked to cloud-based services – or applications used by multiple persons. If the cloud is compromised, then the user’s information is compromised as well, which causes security problems. (GSN reported May 10 on a recent cloud attack that shut the Treasury Department website down for days).

The next problem concerns malware applications on social networks, like MySpace or LinkedIn, which are used by a large audience. For instance, Facebook suggests applications that might contain a malicious code. Therefore, administrators need to control application based traffic to prevent the use of these malicious codes. Fortinet experts say they continue seeing more vulnerabilities discovered and exploited in legitimate applications all the time.

Another thought-provoking point Makey made concerned the evolution of the Internet. Today the Internet is more complex, used by a more people, and it directs more traffic, more services and more software. “How do you address that from a security viewpoint?” asked Manky. “The amount of malware volume, compared to 10 years ago, is overwhelming.” A consolidated solution limits the risk of having one device badly configured if one has several to install.

Another trendy threat is Crime as a Service (CaaS). “Cyber-crime is becoming very service-oriented,” explained Manky. “Before, cyber-criminals were on their own. Now there are many more cyber-criminals and they hire services to do the dirty work for them. It’s easy even for a beginner to hire someone.” Several of these attacks have already surfaced in 2010.

The report also points out the hazard of “scare ware,” also known as fake antivirus. “Software creators develop fake security solutions. They try to scare you into thinking your system is infected and that you need to clean it for a certain amount of money that they will charge you. Their fake security solution will actually fix nothing on your computer so this is a pure scam,” Manky informed GSN. An estimated two to three percent of the victims of this type of scam actually purchase the fake antivirus. “It seems a small number. But some of the cyber criminals make $100,000 in ten days,” said Manky. Several variations of ransomware have appeared in these past few months.

Another threat that proved to be true during 2010 are “money mules.” Cyber criminals hire a middle man to do financial transactions. “The concern is that the person hired might not even know that he is hired to do illegal transactions,” Manky pointed out. “And yet, the law falls on him.”

Cyber-criminals also attack users on new platforms. They used to target computers using Microsoft Windows because of its large number of users, but now they can even target smart phones, ‘fingerprinting’ to customize their attacks according to the user. This increase the mobile threat activity is one of the more recent trends.

Finally, the most important evolving threat, according to Fortinet’s researchers, are the new botnets. Botnets used to be used for a single attack, but not anymore. “Botnets are now used as a service and the attacker keeps them alive longer. Cyber-criminals use new techniques: change of communication, encryption to evade detection, and so on,” Manky tolf GSN. “Botnets have different capabilities; they can create their own Trojan on thousands of computers. And thanks to the Trojans, they have access to all the information they want on those computers.”

 

Recent Webinars

Thu, 04/26/2012 - 2:00pm - 3:00pm

Extracting real-time intelligence from Big Data with deep analytics is valuable but dif

Upcoming Events

Event Details Dates of Event
SANS Security West 2012 May 10 - 18
SANS Toronto 2012 May 14 - 19
SANS Secure Indonesia 2012 May 14 - 19
Emergency Management Seminar May 15 - 15
Counter Terror Expo US May 16 - 17
Emergency Management Seminars May 17 - 17
SANS at iTWeb Security Summit 2012 May 17 - 18
New Fire & Emergency Communications Codes Educational Seminar May 18 - 18
Managing Your Physical Security Program: Collaborate and Manage Smarter May 21 - 24
SANS Brisbane 2012 May 21 - 26
CEIC 2012 (Computer and Enterprise Investigations Conference) May 21 - 24
NERC CIP Compliance Training May 24 - 24
NESCO Town Hall: Security Risk Management Practices for Electric Utilities May 30 - 31
Advanced Hands-On CAMEO Training Jun 4 - 6
Security Program Design: A Critical Infrastructure Protection Model Jun 4 - 5
Facility Security Design Jun 4 - 6
SANS Rocky Mountain 2012 Jun 4 - 9
F5 Government Technology Symposium Jun 6 - 6
SEL Modern Solutions Power Systems Conference Jun 6 - 8
Second Annual Citizen Engagement Seminar Jun 12 - 12
ASIS Assets Protection Course: Functional Management (APC III) Jun 18 - 21
SANS Malaysia 2012 Jun 18 - 23
Data Center Brainstorm 2012 Jun 19 - 19
SANS Forensics and Incident Response Summit 2012 Jun 21 - 27
Vanguard Security & Compliance 2012 Jun 25 - 28
SANS Canberra 2012 Jul 2 - 10
SANSFIRE 2012 Jul 7 - 15
Executive Protection Jul 9 - 10
Military Vehicles Exhibition & Conference Jul 10 - 13
NERC CIP Compliance Training Jul 12 - 12
Security Force Management Jul 16 - 17
Physical and Logical Security: Advanced Applications and Economics Jul 16 - 19
Investigative Interviewing Methods Jul 18 - 19
SANS Thailand 2012 Jul 23 - Aug 4
SANS San Francisco 2012 Jul 30 - Aug 6
College & University Police & Investigators Conference Jul 31 - Aug 3