SQL Injection, Active X on decline: IBM X-Force

By Kathleen Lau, ComputerWorld Canada |  Security, ActiveX, SQL injection Add a new comment

IBM's X-Force 2009 Trend and Risk report shows an 11 per cent drop in discovered vulnerabilities compared to 2008, including a decline in the largest categories like SQL Injections and ActiveX.

SQL Injection gained a lot of popularity as "proverbial flavour of the month," and was subsequently exploited to the point that there were few who didn't know what it was, said Nick Bradley, manager with IBM's managed security services intelligence centre. "Now the awareness has saturated the industry. More are actively looking to protect against it," said Bradley.

The 11 per cent decline in vulnerabilities is "really a drop in the bucket" in terms of the overall number of vulnerabilities, noted Bradley. Some contributing factors, he said, could be the retirement of two of the most "prolific discoverers of vulnerabilities" -- r0t and rgod -- and the disappearance of a well-known site for vulnerability publication, milw0rm.

That aside, Bradley acknowledges the increased awareness among software vendors regarding the value of security in the products they build.

The report also found a significant increase in attacks using obfuscation, often launched using automated exploit toolkits, to hide from security software. Since security awareness goes both ways, Bradley said it's natural that malware creators will strive to exploit the very same vulnerabilities that the security industry tries to stop.

"It's like a game of cyber cat and mouse, now that the mouse is aware that the cat is watching, it's going to look for new hiding places and safer modes of travel," said Bradley.

The report also states that new malicious Web links increased by 345 per cent compared to 2008, indicating that hackers are getting better at hosting malicious sites. And phishing scams still continue to target the financial industry, with 61 per cent of overall phishing e-mails.

Brian O'Higgins, an Ottawa-based security consultant, finds it quite surprising that there should be a decline in SQL injections, which he calls a "best seller," and in ActiveX vulnerabilities. O'Higgins said the drop is likely attributable to software developers getting better at patching, debugging, and overall building applications.

Moreover, these days, there are more tools to help developers scan for possible vulnerabilities before software gets pushed out, said O'Higgins. "That's a good sign that the industry is improving," he said.

O'Higgins said he does expect an increase in attacks using obfuscation, because malware authors are very aware of how anti-malware software works and design their malicious creations around it. He wasn't surprised by the 345 per cent rise in new malicious Web links either. "It's an attack vector of choice, so it works and it's ready and there are all kinds of social engineering (tricks) to get you to click on a link that's malicious," said O'Higgins.

Follow Kathleen Lau: @KathleenLau

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question