The Thalo Creative Blog

This is our voice, our outlet, our connection with the world at large. We strive to provide the online community valuable information on a daily basis. It all fits in with your philosophy of transparency. As we learn, grow, and evolve into what we are destined to be you, our viewer, will have 50 yard line tickets to the best game in town!

Posted by Joe Gilreath
Joe Gilreath
I have been in Systems Administration for 9 years, working in the IT department
User is currently offline
on Wednesday, 18 January 2012
in IT Services

Top Seven Internet Security Trends

IID (Internet Identity®), a provider of technology and services that help organizations secure their Internet presence, recently released its list of the top security trends from 2011. Some specific trends that IID saw emerge over the past year include the extended enterprise coming under assault, the emergence of dangerous mobile applications, and cyber criminals increasingly harnessing the power of social media. This highlights IID's list of the top Internet security incidents and trends from 2011 (in no particular order).

 

  1. From Epsilon to RSA Security SecurID to Sony, IID has witnessed criminals concentrating on organizations that house proprietary data for millions of customers. In each case, cyber criminals targeted and attacked these organizations in particular in order to gain access to vital personal information (like email addresses, shopping habits, etc.) that could lead to broader consumer and employee attacks (better known as spear phishing). IID estimates that by the number of reported events, 2011 was likely the worst year ever for data breach incidents, and the forecast does not look any better for 2012.
  2. As was predicted last year, the security industry has tracked a rapid rise of malicious software (malware) for applications, with a trend towards targeting Google’s Android mobile phones. This malware has popped up both on unofficial marketplaces or even with “good” apps becoming infected and repurposed as bad ones. When malware is downloaded onto a phone, criminals can essentially take over that phone and gain access to any information that is shared on it from emails to text messages to bank login information, without the phone’s owner even knowing it.
  3. As opposed to utilizing secret chat rooms, some cyber crime organizations like LulzSec and Anonymous are boldly using social networking sites to promote and coordinate their efforts. For example, June’s Operation Anti-Security, a joint effort by LulzSec and Anonymous, was advertised on Twitter and involved cyber attacks on the FBI and affiliated agencies.
  4. Public-private partnerships have resulted in the takedown of numerous online criminal networks. For example, on November 8, the FBI, in partnership with various private sector entities, executed one of the largest coordinated cyber-takedown efforts ever with Operation Ghost Click. The target of this takedown, malware dubbed DNSChanger, is estimated to have infected over 4 million machines in 100 countries. And in September, Microsoft took down the Kelihos botnet, a network of private computers infected with malware unknowingly to those computers’ owners. That botnet reportedly consisted of a network of 41,000 infected computers capable of sending billions of spam emails per day.
  5. Criminals are publicly stating that foiled cyber attacks have prompted them to turn to targeting the "domain name company," otherwise known as a registrar. For example, in the September hijacking of ups.com, theregister.co.uk and other major Internet properties, cyber criminals targeted their registrars to indirectly hijack the domains. By targeting the registrar, cyber criminals have access to their original target through this extended enterprise connection that is often overlooked. And in the case of a domain hijacking, that means complete control of the targeted organization’s Web presence, email and Internet-based transactions.
  6. Continuing a major trend from 2010, malware is no longer being used just for the thrill of a takeover, or as a means of ripping off credit card numbers. Criminals are purposefully targeting enterprises in order to gain access to proprietary organizational assets. For instance, researchers found the “Duqu” Remote Access Trojan was built as a weapon for espionage and targeted attacks against certificate authorities (CAs). By gaining access to these CAs, cyber criminals then have the key to access vital data from enterprises through its infrastructure. Industries previously thought to be insulated from cyber threats, like CAs, have clearly been caught in the criminal crosshairs.
  7. While there may be nothing wrong with encryption technology itself, the September breach of Netherlands-based CA Diginotar showed that blind trust placed in SSL certificate providers must be examined. The breach showed that even the foremost experts in Internet security can have their proprietary information hijacked just like any other company.

Protect yourself out there...

0 votes
I have been in Systems Administration for 9 years, working in the IT department of many different organizations. I hope to bring my vast knowledge, education and experience gained in that time to our clients. Some of my past experience includes working with retailers, churches, restaurants, law offices, medical practices, engineering firms, non-profits, transportation businesses, and insurance companies, just to name a few.


As the resident tech guru at Thalo Creative Studios I assist people and their businesses with the technology they use everyday. From getting the servers at work migrated over to virtual machines to getting that virus off your computer. I work to smoothly integrate these technologies in your personal and business lives and resolve any issues that arise in the process. I'm very passionate about the service we offer, service designed so that you can spend your time doing those things you're most passionate about!
Trackback URL for this blog entry

Comments

No comments made yet. Be the first to submit a comment

Leave your comment

Guest
Guest Thursday, 17 May 2012
©2012 Thalo Creative Studios | Custom Joomla Website Design By: Thalo Creative | An Atlanta Georgia Website Design Company.