Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Commvault Simpana® 10
Protect, manage, access, and
realize the untapped value of data.

www.commvault.com
Saturday, May 18th 
Introducing Simpana® 10 software
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Mac
Mobile Tech
World Wide Web
Tech Trends
Data Storage
Applications
Hardware
Unified Communications
Spam & Hackers
Chips & Processors
Cloud & Virtualization
Personal Tech
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement

Cloud & Virtualization

IBM X-Force Trend and Risk Report Offers More Good Security News than Bad

IBM X-Force Trend and Risk Report Offers More Good Security News than Bad
March 22, 2012 12:05PM

Bookmark and Share
"Computer Security is getting better. We're seeing less exploit code getting released on the Internet. We're seeing the quality of software improve. We're seeing software vendors get more diligent about patching security vulnerabilities," said Tom Cross on IBM's X-Force 2011 Trends and Risk Report.

Panasonic Toughbook® mobile computers are engineered to withstand drops, spills, dust and grime, and to perform in the harshest environments. Rugged reliability, low cost of ownership and accolades from reviewers are just a few of the reasons why Toughbook computers keep winning over the world's toughest users. Click here to learn more.

IBM on Thursday released the results of its X-Force 2011 Trend and Risk Report -- and there is some good news and some bad news.

First the good news. The X-Force 2011 Trend and Risk Report revealed a 50 percent decline in spam e-mail compared with 2010, more diligent patching of security vulnerabilities by software Relevant Products/Services vendors, and higher quality of software application code. However, attackers have countered with an increase in automated shell command injection attacks against Web servers.

"The most surprising result to me has been the two- to three-fold increase in shell command injection attacks. I would not have predicted that particular attack vector would grow so much in popularity at this stage of the game," said Tom Cross, manager of Threat Intelligence and Strategy for IBM X-Force.

"X-Force believes that this activity may be an adaptation to the fact that Web site operators are working to fix SQL Injection vulnerabilities and may be missing shell command issues that are also lurking within their Web applications."

A Mixed Bag of News

For years, SQL injection attacks against Web applications have been a popular vector for attackers of all types, IBM said. SQL injection vulnerabilities allow an attacker to manipulate the database behind a Web site.

As progress has been made to close those vulnerabilities, IBM reports some attackers have now started to target shell command injection vulnerabilities instead. These vulnerabilities allow the attacker to execute commands directly on a Web server. IBM said Web application developers should pay close attention to this increasingly popular attack vector.

Back to the good news. There was a 39 percent decline in the availability of exploit code. And although some security vulnerabilities are never patched, in 2011 this number was down to 36 percent from 43 percent in 2010. IBM also witnessed a 50 percent reduction in cross-site scripting (XSS) vulnerabilities due to improvements in software quality.

"Computer Security is getting better. We're seeing less exploit code getting released on the Internet. We're seeing the quality of software improve. We're seeing software vendors get more diligent about patching security vulnerabilities," Cross said.

"We've still got a lot of work to do. There are still many vulnerabilities out there and attackers are taking advantage of them, but our statistics show that progress is being made -- all of the work that is going on to make software more resilient is making a difference." (continued...)

1  |  2  |  Next Page >

 

Tell Us What You Think
Comment:

Name:

Al:

Posted: 2012-04-05 @ 11:15am PT
It sure would be nice to have a LINK TO THE REPORT.

Advertisement



 Cloud & Virtualization
1. Cloud Computing Gains Another Rival
2. Investors Funding Cyberwarfare
3. HP Boosts Data Center IT Automation
4. Involuntary IT Managers Cost a Bundle
5. Hospitals Lose $8.3B Using Old Tech


advertisement


 Most Popular Articles
1. Best of Interop Award Winners Announced
2. HP Teams with Avaya To Take Contact Centers Virtual
3. Sony Vaio Fit Notebooks Aim for Sweet Spot
4. 3D Printers Go Mass Retail at Staples
5. Salesforce Sees End to Legacy Portals with Its Communities

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Windows 8.1: No Cost, Big Pressure
  Google Glass Raises Privacy Concerns
  Pentagon Gives iOS 6 Security OK
  Should Enterprises Skip Windows 8?
  Financial Times Latest Hacking Target

 Technology Marketplace

BYOD & MDM
Build a business case for a BYOD program.
 
CRM Systems
Free Download: Understanding the Voice of the Customer
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
Riverbed Stingray Traffic Manager on Amazon Web Services
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
 
Customer Data
Free Download: Understanding the Voice of the Customer
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Hardware
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Laptops & Tablets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Mobile Apps
Build great mobile apps that drive engagement.
 
Mobile Gadgets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Mobile Enterprise Spotlight

Google Glass Raises Congressional Privacy Concerns
The buzz around Google Glass continues, but it's not all good. Some in Congress have questions. "We are curious whether this new technology could infringe on the privacy of average Americans," their letter to Google says.

Windows Phone Now No. 3 in Market, BlackBerry No. 4
Has Microsoft Phone moved into a coveted though distant third place for smartphone platforms behind Google's Android and Apple's iOS? A new report says yes, while BlackBerry has slipped to No. 4.

Intel Going Mobile with Its New CEO
In his first speech as Intel's CEO, Brian Krzanich said he plans to focus on beefing up Intel's presence in mobility. The next step: a world tour showing mobile devices based on Intel chips, from PCs to phones and tablets.

Advertisement
Enterprise Software Spotlight

Should Enterprises Skip Over Windows 8?
Because of the interface changes and compatibility issues, most businesses will not adopt Windows 8 as their standard, but must be prepared to meet employee BYOD demand for it, Forrester Research says.

HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.

Revlon Saving Millions with Microsoft Dynamics
The cosmetics giant is reporting millions of dollars in savings thanks to consolidating its enterprise resource planning by using Microsoft Dynamics ERP. Revlon CIO David Giambruno recently shared his story.

Advertisement
Enterprise Hardware Spotlight

U.S. Defense Department Gives iOS 6 Security OK
In a vote of confidence for Apple's iOS devices, the Defense Department has given the all-clear for employees to use iPads and iPhones for work. But only those running iOS 6, and only if issued by the government.

Cisco Surges After Profit Exceeds Analysts' Estimates
Networking equipment giant Cisco's net income jumped 14 percent in the latest quarter as revenue at all four of its divisions rose for the first time in a year and a half, as tech spending increases.

HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.

Advertisement
Enterprise Security Spotlight

Syrian Electronic Army Hacks Financial Times
The Financial Times is the latest victim of the Syrian Electronic Army, a group that supports Syrian President Bashar al-Assad. The U.K.-based newspaper said a blog and its Twitter accounts were hacked.

Patch Tuesday Hyper Focuses on IE 8
Microsoft on Tuesday issued 10 security bulletins that fix 33 vulnerabilities. These updates include MS13-038, which will address the Internet Explorer 8 issue described in Security Advisory 2847140.

Surge of Venture Capital Buoys Tech Security Sector
With companies and governments spending billions to repel cyberthreats, a surge of venture capital is pouring into companies developing cybersecurity technologies, the front line of the conflict.

Advertisement
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Mac | Mobile Tech | World Wide Web
Tech Trends | Data Storage | Applications | Hardware | Unified Communications | Spam & Hackers | Chips & Processors
Cloud & Virtualization | Personal Tech | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Top Tech News. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.