Tag Archives: March 2011

March 2011 MessageLabs Intelligence Report – Rustock Goes Down, Bagle Botnet Picks Up The Slack

imageThere’s been much more discussion recently as to whether infected computers should be allowed unrestricted access to the Internet. Despite the fact we’ve been around the horn on this question for years, there’s still little consensus on this thorny issue.

Since infected computers, linked together in botnets, form the backbone of spam distribution networks – according to the March 2011 MessageLabs Intelligence Report, botnets sent an average of 88.2% of global spam during 2010 – this question needs to be taken off the back burner and dealt with much more aggressively.

Frankly, I’m tired of making excuses for people who are too damn lazy, too damn stupid, too damn inconsiderate, ………. to take the time to learn the basics of computer security. And, as a consequence cause me, and you incidentally, to have to deal with volumes of spam that are beyond the pale.

image

Graphic courtesy of Symantec (Click to expand to original)

According to the March 2011, MessageLabs Intelligence Report (released yesterday), the recently taken down Rustock botnet “had been sending as many as 13.82 billion spam emails daily, accounting for an average of 28.5% of global spam sent from all botnets in March.”

A little math suggests, that during March enough Spam was emailed that conceivably, every person on the Planet received 7 spam emails EVERY DAY! Since every person on the Planet is not connected, the abuse takes on another magnitude. I can’t think of another finite resource – and the Internet is a finite resource – that could be continuously abused in this way, without some kind of strong kickback.

Are we making any headway against botnets and the cyber criminals behind them? Not according to the MessageLabs Intelligence Report we’re not. Sure, Rustock has bitten the dust (at least for the moment), but the Bagle botnet has stepped into the breech, bumped up its output, and is now sending 8.31 billion spam emails each day, mostly tied to pharmaceutical products.

Report highlights:

Spam: In March 2011, the global ratio of spam in email traffic from new and previously unknown bad sources decreased by 2 percent (1 in 1.26 emails).

Viruses: The global ratio of email-borne viruses in email traffic from new and previously unknown bad sources was one in 208.9 emails (0.479 percent) in March, an increase of .134 percentage points since February. In March, 63.4 percent of email-borne malware contained links to malicious websites, a decrease of .1 percentage points since February.

Endpoint Threats: The endpoint is often the last line of defense and analysis. The threats found here can shed light on the wider nature of threats confronting businesses, especially from blended attacks. Attacks reaching the endpoint are likely to have already circumvented other layers of protection that may already be deployed, such as gateway filtering.

Phishing: In March, phishing activity was 1 in 252.5 emails (0.396 percent), a decrease of 0.065 percentage points since February.

Web security: Analysis of web security activity shows that an average of 2,973 websites each day were harbouring malware and other potentially unwanted programs including spyware and adware, a decrease of 27.5% since February. 37 percent of malicious domains blocked were new in March, a decrease of 1.9 percentage points since February. Additionally, 24.5 percent of all web-based malware blocked was new in March, a decrease of 4.2 percentage points since last month.

Reading this type of report (or at least the highlights), is certainly educational, and can be a major step in expanding that sense of threat awareness that active Internet users’ require.

The full MLI Report is available here in PDF.

Symantec’s MessageLabs Intelligence is a respected source of data and analysis for messaging security issues, trends and statistics. MessageLabs Intelligence provides a range of information on global security threats based on live data feeds from control towers around the world scanning billions of messages each week.

About Symantec:

Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.

If you found this article useful, why not subscribe to this Blog via RSS, or email? It’s easy; just click on this link and you’ll never miss another Tech Thoughts article.

2 Comments

Filed under bots, Cyber Crime, Cyber Criminals, cybercrime, Don't Get Scammed, Don't Get Hacked, email scams, Interconnectivity, MessageLabs, spam, Symantec, Windows Tips and Tools

OPSWAT’s Latest Quarterly Report Breaks Down Antivirus Market Share, Windows Usage By Version, And More

imageIf you’re a techie then you’re very likely familiar with AppRemover, a free powerful anti-malware, antivirus application remover from OPSWAT. Beyond this direct connection however, you might not be familiar with OPSWAT.

So, who are OPSWAT, and what do they do?

From the site:

OPSWAT offers software manageability solutions to streamline technology partnerships between leading technology solutions and software vendors. By enabling seamless compatibility and easy management capabilities, we make connecting your solutions with other software applications effortless.

As a Blogger, information gatherer, and distributor, there is an additional area of OPSWAT’s expertise that I find invaluable, and that is – the regular reports which the company releases on vendor market share for antivirus, hard disk encryption, backup clients, and peer to peer applications.

In its latest quarterly report, (to be released later today), OPSWAT has focused on Worldwide and North American Antivirus vendors market share, with additional data breaking down Windows usage by version and, bonus data on Peer to Peer application usage.

Here’s a few teasers from this report:

The avast! Antivirus product line has helped AVAST Soware maintain its position as the top antivirus vendor worldwide for the last two quarters, despite a slight drop to 16.19% global market share in this report.

Avira GmbH and AVG Technologies are second and third in global market share with 13.22% and 11.47% respectively. In comparison to the worldwide data from our December 2010 report, Avira GmbH shows a considerable increase of 4.96%, which could result from a higher percentage of the current data originating from countries where they have a stronger hold on the market.

The only other worldwide market share increases were by AVG, with a 1.76% gain from the December report, Lavaso, with a 0.82% rise, and Comodo, with a minimal increase of 0.06%.

Worldwide Antivirus Market Share

image

Graphic courtesy OPSWAT

North American Antivirus Market Share

image

Graphic courtesy OPSWAT

The following graphic might hold some surprises for those who insist that Windows XP is dead. If you were to Google “Windows XP is dead”, for example, you might be surprised to see 25 Million search results.

I’m continuously amazed at the gullibility of consumers, particularly here in North America, who are so easily convinced to discard workable solutions in favor of “the latest and greatest”.

As one who continues to happily run Windows XP on an older machine, I must admit to a certain sense of satisfaction when more than half of Worldwide users continue to resist Microsoft’s planned obsolescence cycle.

And yes, I’m quite familiar with the so called “security issues” inherent in running XP. What I find curious is – on the one hand we (those of us involved in system security), extoll users to develop situational awareness while on the Internet, while on the other hand, there’s a tendency to lay the blame for system intrusion based, in large part, on older operating system deficiencies. Marketing gone mad, anyone?

Windows OS Usage – by Version

Click on the graphic to expand to original.

image

Graphic courtesy OPSWAT

P2P Application Market Share

image

If you found this article useful, why not subscribe to this Blog via RSS, or email? It’s easy; just click on this link and you’ll never miss another Tech Thoughts article.

7 Comments

Filed under Anti-Malware Tools, Myths, Opinion, Peer to Peer, Point of View, Reports, Software, Windows Tips and Tools