Perimeter
1/18/2011
12:40 PM
Commentary
Commentary
Commentary
Connect Directly
RSS
E-Mail
50%
50%
Repost This

The Relative Risk Of Malware

Trend Micro reports there are 3.5 new malware released every second, up from 1 new malware every 1.5 seconds a year ago. But what's your actual risk?

Throughout 2010, Trend Micro published figures stating there was 1 new malware threat every 1.5 seconds. Just last week, a blogger interpreted that as being at personal risk of encountering a whopping 19,200 new threats per day (based on eight hours of online time).

Earlier today, Trend Micro upped that figure substantially, twittering that 3.5 new threats were released every second -- a 450% increase. With the wrong interpretation, some might believe that translates to an individual encounter risk of 100,800 new threats per day (based on that same eight hours of online time).

Obviously whether it's actually 1 new threat per 1.5 seconds, or 3.5 new threats per second, neither translates to actual encounter risk for users. To gauge that risk, you'd have to monitor the same user population for an extended period of time and determine what the actual number of raw encounters was at specified, regular intervals.

Fortunately, ScanSafe (now Cisco ScanSafe) has been doing that since May 2007, so we can report on the actual encounter rates. Our user population is a 15,000-seat enterprise; following are the actual numbers of malware encountered:

>> May 2007: 205 encounters
>> May 2008: 669 encounters
>> May 2009: 1,719 encounters
>> May 2010: 4,111 encounters

In other words, if you're a 15,000-seat enterprise, then you probably average 5.5 malware encounters per day. That's still a lot, but it's definitely a lot less than 3.5 every second. The moral of the story: The overall rate of new malware does not equal the overall rate of encounter.

Mary Landesman is an antivirus professional and senior security researcher for ScanSafe, now part of Cisco. In 2009 she was awarded a Microsoft MVP for her work in consumer security.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web