antispyware etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
antispyware etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

23 Eylül 2011 Cuma

DDoS attacks

All statistical data presented in this report were obtained using Kaspersky Lab’s botnet monitoring system and Kaspersky DDoS Prevention.
The quarter in figures

The most powerful attack repelled by Kaspersky DDoS Prevention in Q2: 500 Mbps
The average power of the attacks repelled by Kaspersky DDoS Prevention: 70 Mbps
The longest DDoS attack in Q2: 60 days, 1 hour, 21 minutes and 9 seconds
The highest number of DDoS attacks against a single site in Q2: 218.

DDoS and protests

Distributed denial-of-service attacks are no longer being carried out simply to make a profit. Cybercriminals are increasingly targeting government resources or the sites of big companies to show off their skills, demonstrate their power or, in some cases, as a form of protest. These are exactly the sort of attacks that get maximum publicity in the media.

The most active hacker groups in the second quarter of 2011 were LulzSec and Anonymous. They organized DDoS attacks on government sites in the US, the UK, Spain, Turkey, Iran and several other countries. The hackers managed to temporarily bring down sites such as cia.gov (the US Central Intelligence Agency) and www.soca.gov.uk (the British Serious Organized Crime Agency (SOCA)). This shows that even government sites safeguarded by specialist agencies are not immune to DDoS attacks.

Attacking government sites is a risky business for hackers because it immediately attracts the attention of law enforcement authorities. In Q2 of 2011, for example, more than 30 members of Anonymous were arrested on suspicion of launching DDoS attacks on government sites. More arrests are likely to follow as authorities continue their investigations. However, not all those involved are likely to be convicted because participation in the organization of a DDoS attack is still not considered illegal in many countries.

One big corporation subjected to a major attack was Sony. At the end of March, Sony brought legal action against several hackers accusing them of breaching the firmware of the popular PlayStation 3 console. In protest at Sony’s pursuit of the hackers, Anonymous launched a DDoS attack that crippled the company’s PlayStationnetwork.com sites for some time. But this was just the tip of the iceberg. According to Sony, during the DDoS attack the servers of the PSN service were hacked and the data of 77 million users were stolen. Whether or not it was done intentionally, the DDoS attack by Anonymous served as a diversionary tactic for the theft of huge volumes of data and which, at the end of the day, affected Sony’s reputation.
DDoS attacks on social media

The second quarter of 2011 is likely to be remembered by Russian Internet users for the series of attacks on LiveJournal. The resource is popular with a variety of people, with housewives, photographers, pilots and even politicians posting blogs on the site. According to our botnet monitoring system, the mass attacks on LiveJournal began by targeting journals of a political nature, in particular, that of the anti-corruption and political activist Alexey Navalny.

Our botnet monitoring system has been tracking a botnet named Optima which was used in the DDoS attacks on LiveJournal. In the period between 23 March and 1 April Optima received commands to attack the anti-corruption site http://rospil.info, http://www.rutoplivo.ru and http://navalny.livejournal.com as well as the furniture factory site http://www.kredo-m.ru. On certain days only http://navalny.livejournal.com was attacked. At the beginning of April the botnet received a command to attack a long list of LiveJournal addresses mostly belonging to popular bloggers who cover a wide range of subjects.

The Optima botnet has been known on the market since late 2010. From the type of code used, it is safe to say that Optima bots are developed by Russian-speaking malware writers and they are mostly sold on Russian-language forums. It is difficult to determine the size of the botnet because it is highly segmented. However, our monitoring system has recorded instances of the Optima bots that attacked LiveJournal receiving commands to download other malicious programs. This suggests the Optima botnet includes tens of thousands of infected machines because such downloads are considered unprofitable for small botnets.

The motive for the attacks on LiveJournal remains unclear as nobody has yet claimed responsibility. Until the cybercriminals behind the attacks are identified, it will be difficult to say whether the attacks were ordered or just a show of force.

DDoS attacks on social media are becoming more frequent because these services allow the immediate exchange of information between tens of thousands of users. Blocking this process, even if it is just for a short time, can only be achieved with the help of DDoS attacks.

We expect to see a further growth in these types of attack in the future.
Commercial DDoS attacks

Ordinary criminals also continue to make active use of DDoS attacks. However, information about attacks that aim to extort or blackmail organizations is rarely made public and when it is, it is usually related to the subsequent criminal investigation.

In April, a court in Dusseldorf handed down a sentence to a cybercriminal who tried to blackmail six German bookmakers during the 2010 World Cup. The culprit used the familiar routine of: intimidation, a trial attack on the victim’s site, and a message containing a ransom demand. Three of the six offices agreed to pay off the attacker. According to the bookmakers, a few hours of website downtime can result in the loss of significant sums – 25-40,000 euros for large offices and 5-6,000 euros for smaller offices. Surprisingly, the scammer only demanded 2000 euros. He received money in U-cash vouchers – a method which had already been used by the author of the well-known GpCode Trojan program. The court sentenced the defendant to nearly three years in prison – the first time in German legal history that someone has been imprisoned for organizing a DDoS attack. Such attacks are now classified by the country’s courts as computer sabotage and are punishable by up to 10 years in jail.

In June, the Russian judicial system also addressed the subject of DDoS attacks. On 24 June, a Moscow court sanctioned the arrest of Pavel Vrublevsky, the owner of ChronoPay, Russia’s biggest Internet payment service provider. Vrublevsky was accused of organizing a DDoS attack against competitor firm Assist in order to undermine its chances in a tender for a lucrative contract to process payments for Aeroflot, Russia’s largest airline. Sources close to the investigation said Vrublevsky was also considered the owner of the Rx-Promotion affiliate network which specializes in spreading pharmaceutical spam.

12 Eylül 2011 Pazartesi

Trend Micro Titanium Antivirus+ 2012

The software designers at Trend Micro identified three main pain points for security software users: complexity, intrusiveness, and overuse of resources. With Trend Micro Titanium Antivirus+ 2012 ($39.95, direct; three licenses for $59.95) they aim to avoid those pain points and offer an antivirus that's safe, lightweight, and easy to use. It succeeds at those goals, but PCMag's tests and independent lab tests agree that its actual protection capabilities lag behind the competition.

Changes for 2012
Bitdefender Antivirus Plus 2012 ($39.95 direct for three licenses, 4 stars) and Kaspersky Anti-Virus 2012 ($59.95 direct for three licenses, 3.5 stars) both got a full makeover this year, a new, simpler interface. Trend Micro's interface didn't need a change, as it was already super-simple. Interestingly, the latest edition lets you personalize the product by selecting a skin or using one of your own photos.


Specifications
Type
Business, Personal, Professional
OS Compatibility
Windows Vista, Windows XP, Windows 7
Tech Support
Free email, chat, and phone support plus online forum and videos.
More View Slideshow See all (16) slides

More
Action-wise this edition promises better protection against fake antivirus, better behavioral protection, and new technology to resist botnets and standard viruses. It also adds better detection and removal of rootkits, automatically offering a bootable rescue CD if needed to eradicate rootkits.

Trend Micro's Smart Protection Network (SPN) blocks 5 billion threats daily. About 80 percent of the antivirus's signature data resides in the cloud with SPN, to keep the product's footprint small. It's so quiet and unobtrusive that some users wondered if it was even working. The current edition offers a security report once a month, so you can see what it's doing for you. Of course, you can view the report any time you wish.

But wait! There's more! Whether you purchase one license or three of the PC-based antivirus, you get a free copy of Trend Micro Smart Surfing for Mac, which would normally cost $49.95.

Not Fond of the Labs

Trend Micro's researchers feel that many of the antivirus testing labs aren't doing their testing quite right. This product is designed to block malware at many levels, starting with the initial download of the file, and few labs test at all levels. Trend Micro stopped participating in Virus Bulletin's tests some while ago, and more recently withdrew from the retrospective tests performed by AV-Comparatives.org. In the latest on-demand malware cleanup test by AV-Comparatives, Trend Micro rated STANDARD, the lowest passing rating.

The company also declines to participate in testing by ICSA Labs. West Coast Labs certifies the product for both virus detection and virus removal.

All of the tests mentioned to this point are static tests in which the product is presented with thousands of inactive malware files and challenged to identify them. Trend Micro contends, quite reasonably, that dynamic testing of the whole product with active malware is more representative of the user's real-world experience.

Each quarter AV-Test.org runs a dynamic virus certification test under Windows 7, Vista, or XP. Products can earn up to six points in three areas: Protection, Repair, and Usability. A total of 11 points is required for certification. Trend Micro did make the cut, but just barely. Its last three scores were 12.5, 13.5, and 12.5. Bitdefender's technology averaged 16 point on the last three tests, the highest of any tested. and Kaspersky came in second with an average of 15.17.

In the dynamic whole product test by AV-Comparatives, Trend Micro impressively took the top rating, ADVANCED+.

AVG Anti-Virus Free 2012

AVG Technologies is best known for antivirus protection, but in recent years the company has branched out, adding system tune-up, parental control, online backup, and more. But have no fear; you can still get the powerful protection of AVG Anti-Virus Free 2012 without spending a penny. In my tests and in tests by independent labs it beats many of its for-pay competition. Do note that it's specifically free for personal use; business users must pay for AVG's antivirus protection.

The 2012 edition's main screen collapses the previous edition's ten component icons down to six, but adds three new ones to integrate the company's other products. If you use AVG Family Safety ($19.95 direct for three licenses, 4.5 stars), AVG PC Tuneup 2011 ($29.99/year direct, 4 stars), or AVG LiveKive online backup, you can click the icon to link your products. If you don't, naturally the antivirus includes an option to get them.


More
Specifications
Type
Personal
Free
Yes
OS Compatibility
Windows Vista, Windows XP, Windows 7
Tech Support
FAQ, forum, videos, email; free phone support in US, UK, Canada.
More Good Lab Results
All of the labs I follow test AVG's technology and give it generally good ratings. ICSA Labs and West Coast Labs certify it for virus detection; West Coast adds checkmark certification for virus removal as well. In all of the last ten tests by Virus Bulletin, AVG has received VB100 certification.

AVG participates in the on-demand test by AV-Comparatives.org, but not in the retrospective test, which simulates zero-day protection by using old virus signatures. In the on-demand test AVG rated STANDARD, the lowest passing grade.

AV-Comparatives also runs a whole-product dynamic test, challenging products to protect test systems from real-world up-to-the-minute threats. In this test AVG rated ADVANCED, a cut above STANDARD.

The ongoing antivirus certification tests by AV-Test.org are also dynamic tests, emulating a user's real-world experience. Products can receive up to 6 points for protection, repair, and usability, with a total of 11 points required for certification. In the most recent tests under Windows 7, Vista, and XP, AVG averaged 13.17 points.

The article How We Interpret Antivirus Lab Tests explains how I boil down results from the various labs to create the following chart.


AVG Anti-Virus Free 2012 lab tests chart

Very Good Malware Cleanup
AVG installed quickly on my twelve malware-infested test systems. Resistant malware on one system interfered with installation, but installing in Safe Mode solved that one. On half of the test systems AVG detected active threats immediately and requested a reboot to finalize cleanup.

A full scan on my standard clean test system took just 16 minutes, and a repeat scan finished in less than two minutes. That's plenty fast. The average scan time for recent products on this same system is 25 minutes.

I always find it odd that AVG separates rootkit scanning from the whole computer scan. For the test systems infested with rootkits I ran the separate rootkit scan, which added about three minutes.

When I tallied the results I was quite impressed. AVG detected 88 percent, the same as TrustPort Antivirus 2012 ($39.95 direct, 3.5 stars). Of the products tested with this current threat collection, only G Data AntiVirus 2012 ($29.95 direct, 3.5 stars), with 91 percent, detected more.

AVG didn’t clean up perfectly. It left behind executable files for some threats, and even left a few processes running. However, its score of 6.5 points for malware removal is a new high for the current crop of antivirus products, beating out the 6.4 point record held by Malwarebytes' Anti-Malware Free 1.51 (Free, 4 stars).

AVG detected all of the threats that use rootkit technology and scored 6.7 points for rootkit removal, a tie for top score with ZoneAlarm Antivirus + Firewall 2012 ($59.95 direct for three licenses, 3 stars). Bitdefender Antivirus Plus 2012 ($39.95 direct for three licenses, 4 stars) was the next-best rootkit remover, with 6.0 points.

The majority of current products detected all of my scareware samples. Malwarebytes scored a perfect 10, thoroughly cleaning up scareware. AVG was close behind with 9.5 points, the same as BitDefender, Panda Cloud Anti-Virus 1.5 Free Edition (Free, 3.5 stars), and several others.

This is quite an impressive showing, and it parallels the dynamic test results from the labs. For a full explanation of how I come up with these scores see How We Test Malware Removal.

Spyware Stoppers

Illustration: Doug FraserNot long ago, Web- and e-mail-borne viruses were a computer user's worst enemy. Though viruses and worms still cause more damage in compromised or lost data, a newer menace, popularly known as spyware, steals users' productivity and peace of mind. The "spyware" label can apply to legitimate but annoying programs that users consent (perhaps unwittingly) to have installed on their PCs, or it can describe programs that install themselves without permission. Both types of applications can drain your computer's resources, slow your Internet connection, spy on your surfing, and even forcibly redirect your Web browser. For the purposes of this story, we'll call the former category adware and the latter spyware. Adware clearly spells out its intent, comes with an uninstaller, and can be readily removed from a system. Spyware, in contrast, installs itself surreptitiously and can be nearly impossible to remove without assistance.

A crop of anti-spyware programs has sprung up to provide that assistance. We evaluated ten current anti-spyware utilities designed to detect and remove spyware and adware from PCs, looking at their rates of detection, scanning speed, ability to prevent unwanted applications from installing themselves, and ease of use. We were pleased to find that a couple of the programs did a very effective job of cleaning an infected system and preventing new infestations with effective real-time protection.

PC World tested seven products in the $20 to $40 range from big and small vendors: Allume Systems' (formerly Aladdin Systems') Internet Cleanup, Aluria Software's Spyware Eliminator, Computer Associates' ETrust PestPatrol Anti-Spyware, InterMute's SpySubtract Pro, McAfee's AntiSpyware, Sunbelt Software's CounterSpy, and Webroot Software's Spy Sweeper. In addition, we tested two popular free programs--Lavasoft's Ad-Aware SE Personal and Safer Networking's Spybot Search & Destroy--and a third free program that operates very differently but no less effectively, Merijn.org's HijackThis. (You can get all three free products here.) We did not include HijackThis in our charts because, unlike the others, it does not scan for infections. We also tested one product in beta, Microsoft's new Windows AntiSpyware, which was until late last year Giant Software's AntiSpyware.