This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Shaun Nichols
17 Jul 2012
An increasingly elusive and sophisticated class of online attack kits is posing a far greater threat to enterprises than most realise, according to researchers with HP.
Jason Jones, an ASI team lead for HP's DV Labs security division, told V3 that exploit tools, such as the Blackhole platform, are becoming harder to track and detect for security researchers and anti-malware vendors.
Through the use of techniques such as obfuscated code in Javascript, attackers are able to hide their activities and target recently disclosed vulnerabilities which have yet to be patched on many systems.
In some cases, researchers are finding attacks capable of infecting as much as 80 per cent of the systems targeted.
"They are able to hide the exploit code from detection while its passing over the wire," Jones explained.
Further complicating matters, said Jones, was the growing complexity and sophistication of the malware market. As cybercriminals invest more money in attack kits, the malware developers are able to provide improved management and support systems, such as regular software updates, analytics and web management portals.
The growth is occurring at a time when many firms are preoccupied with the growth in advanced persistent threat (APT) attacks. With incidents such as the Shady RAT and Flame outbreaks dominating headlines,
Jones believes that by fixating on APTs and zero-day attacks, many firms are leaving themselves open to infections from the far more prevalent crop of web-based exploit kits.
IT chiefs often worry about the threat of so-called zero-day attacks but forget to install patches for known vulnerabilities, leaving them at far greater risk of attack, he said.
"Making sure you are patched first and then worrying about the unknown would be a better mindset."
Latest stories from Security
Related articles
Related jobs
Poll
How concerned are you by the rising tide of cyber threats?
BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
Project Manager - OMS - Trading Systems Project Manager...
Software Developer ( ASP.NET C# ) Urgently needed...
Web / .NET Developer ( ASP.NET, VB.NET, HTML, CSS, SQL...
Tester / Software Tester / QA Analyst ( Black & White...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree