Online criminals looking for new areas to attack in the next few years will find green fields in the Internet infrastructure and the digital home, researchers with McAfee's AVERT labs said this week.
McAfee offered its take on the top security trends for 2007, at a press event in San Francisco, saying that well-known problems like phishing, spam, bots and rootkits are on the rise.
But in the years ahead, new areas will be top concerns, said Craig Schmugar, virus research manager at McAfee's Anti-Virus Emergency Response Team (AVERT) labs. "In the short-term, it will be the infrastructure side of things," he said. "In the long term, it will be digital entertainment."
Schmugar said that the recent flaw in Windows Domain Name System (DNS) servers, which was exploited in a small number of online attacks, is a good example of things to come. These servers are a critical part of the Internet's infrastructure, used to convert the domain names users type into their browsers into the IP (Internet Protocol) addresses used to identify computers on the Internet.
Microsoft patched the DNS flaw in April, shortly after the attacks began.
McAfee also expects to see hackers focus more on Wi-Fi attacks as PC users become accustomed to connecting to wireless networks wherever they go. "We haven't heard of any real-world attacks, but that's likely to become a bigger issue, especially with municipal Wi-Fi," Schmugar said.
Some security experts have warned that public Wi-Fi could be used to set up "man-in-the middle" attacks, where a criminal sets up a malicious wireless network and then intercepts online communication between the victims and any of the Internet servers they try to reach.
Researcher Christopher Soghoian recently demonstrated how such an attack could be used to install malicious software on a Firefox browser.
And the digital home will eventually attract home invaders too, Schmugar predicted. As consumers get more comfortable downloading and playing movies and games on home entertainment computers, that may also give hackers a new way to attack, he said.
McAfee says that video on the Web is already being hit with attacks. In March, the company reported that the MySpace page for the French band Mamasaid had been infected and was downloading malicious code hidden in a QuickTime file.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Simplify and Secure: Managing User Identities Throughout their Lifecycles
Still Sneaking In: The Threats Your Security Tools Aren't Telling You About
Achieving the impossible: Unlimited application scalability
Simplify, Integrate and Secure: Providing Secure Access to Server-based Information and Resources Across Platforms
Radicati Market Quadrant 2008 on Corporate Web Security
Discover the advantages of an open architecture multi-vendor network solution
BT saves more than £15 million and improves customer services with comprehensive Identity & Access Management
Everything you need to know about email and web security (but were afraid to ask)
Zones provide focussed content from Computerworld and leading technology partners.Security Management
Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our IT security solutions.
IT Security as a business enabler?
Download Whitepaper
|
Success Stories
Australian Unity minimises costs and maximises productivity with single sign-on for 1,400 users
Australian Unity needed to address its business and security risks including user management and application security management. The company chose an enterprise single sign-on (ESSO) solution and discovered increased employee productivity, reduced help desk costs and elevated data protection.
Download the full Success Story
BT saves more than £15 million and improves customer services with comprehensive Identity & Access Management
To enable future growth and ensure its services remain competitive, BT needed to build closer relationships with its customers and suppliers. Discover how the company is now performing over 36 million transactions a day with their improved Identity & Access Management Solution.
Download the full Success Story
Identity & Access Management
Simplify and Secure: Managing User Identities Throughout their Lifecycles
Organisations are constantly challenged to keep pace with ongoing changes to users and their roles, responsibilities and requirements. Discover how CA can help you create a unified approach for managing users identities, providing them with timely and appropriate access to applications and information.
Download Whitepaper
Simplify, Integrate and Safeguard Your Business with Secure Web Business Enablement
Modern organisations are required to aggressively expand the number and type of Web applications and services provided to customers, partners and employees. Discover how to automate, delegate and centralise your key processes and services including user administration, access policies, auditing and compliance by reading on.
Download Whitepaper
Simplify, Integrate and Secure: Providing Secure Access to Server-based Information and Resources Across Platforms
Distributed servers are a powerful asset in any company’s infrastructure. Over time, most organisations have acquired a variety of different platforms and are relying on them to house an increased amount of critical applications, processes and data. Read on to discover how you can achieve a consistently higher level of server access security across multiple platforms including virtual hosts and guest operating systems.
Download Whitepaper












