Perimeter
Guest Blog // Selected Security Content Provided By Sophos
What's This?
10/27/2011
11:56 AM
Security Insights
Security Insights
Security Insights
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Microsoft Research Shows Malware Infections Mostly 'Your Fault'

User vigilance is key to securing data, digital identities

Microsoft’s latest Security Intelligence Report (PDF) was released recently, and it showed a surprising finding: Nearly 45 percent of all malware infections cleaned up by its Malicious Software Removal Tool required a human to make a bad decision.

Am I surprised? Not exactly ... There has been a major shift toward social engineering in the past 24 months for cybercriminals. As we all do a better job of securing and updating our computers, the lowest-hanging fruit becomes ourselves.

In its 168-page report, the software giant describes phishing schemes, spam e-mail, assorted malware, and threats associated with social engineering as “entry mechanisms” for malware and a hacker having complete control of an infected computer.

While most of our Windows pain in recent years has resulted from poor security design and practices in the early days, Microsoft has taken security must more seriously in recent times. When all is said and done, it’s humans who respond to spam e-mail and announcements of free gift cards on Facebook.

Most of us aren’t great at reading a digital face over the Internet to determine whether we are being scammed: We have a lot to learn to be as good at it as we are in the real world.

Microsoft also provided evidence that despite all of the widespread, often corrosive media coverage about it, only about 0.1 percent of successful attacks resulted from so-called “zero-day” exploits -- which, theoretically, Microsoft can’t do much about because patches for them haven’t yet been developed. In its report, Microsoft found that those fears are mostly misplaced, arguing that the vast majority of zero-day vulnerabilities are immediately patched once discovered and are not commonly exploited.

This isn’t to say that Microsoft is innocent on all counts. We all have a role to play in protecting our digital identities, and with more than 80 percent market share, Microsoft needs to continue to proactively find its own flaws and make it even easier for the public to make the right decisions. With great power comes great responsibility.

Chester Wisniewski is a senior security adviser at Sophos Canada

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-0460
Published: 2014-04-16
The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.

CVE-2011-0993
Published: 2014-04-16
SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.

CVE-2011-3180
Published: 2014-04-16
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.

CVE-2011-4089
Published: 2014-04-16
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.

CVE-2011-4192
Published: 2014-04-16
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."

Best of the Web