A year ago, one out of every 909 e-mails was infected with malicious code. In the first quarter of 2008, only one out of every 2,500 was infected. Good news? Not really. All it means is that the attackers have changed tactics to overcome the defenses you’re building, according to security company Sophos.
“As companies implement better e-mail defenses, the hackers are looking for new avenues of attack. E-mail also lacks some of the flexibility that Web-based attacks can offer,” said Richard Wang, U.S. SophosLabs Manager.
A study done by Sophos that examines the security events and trends of the first quarter of this year showed that the decline in attacks against e-mail was balanced by what the company calls “an unprecedented number of threats” targeting Web pages. Last year, the company detected an average of roughly 5,000 infected Web pages a day; this quarter, the average is 15,000 per day. That’s one new infected Web page every five seconds.
And these are sites you may well visit: 79 percent are legitimate sites, not sites set up specifically to host malicious attacks.
Web Threats Based in the United States
“The Web gives hackers an easy way to deliver software to their victims,” Wang said. “It also allows them to change the software they are using at a moment’s notice. This makes the Web far more flexible as an attack vector than e-mail.”
Companies in the United States are taking the worst beating from the switch in tactics, with domestic companies now unwittingly hosting the greatest number of malicious content. (Last year, the number-one spot was held by China.)
“The most likely cause of this is the hackers’ move away from purpose-built malicious Web sites. The vast majority of sites that we now see hosting malware are legitimate sites that hackers have broken…