Categories: SecurityWorkspace

Weak Passwords To Be Major Security Risk In 2013

At the start of a new year, two security specialists have highlighted the main areas of concern for corporate IT security in 2013.

The biggest security threats to companies in 2013 will depend on who is attacking the business: Opportunistic criminals will continue scanning for accounts with default or weak passwords, while targeted attackers will refine their attempts to fool employees, business services firm Verizon and security software firm McAfee stated in separate reports.

Weak Passwords

In the past year, about 90 percent of successful breaches analysed by Verizon started with a weak or default password, or a stolen and reused credential, which is a trend that will continue, said Wade Baker, managing principal for the company’s RISK team. The company analysed data gathered from incidents it investigated in 2012 to identify the causes of data breaches.

“Taking all the attacks that happened to larger corporations and government, about 90 percent had weak or stolen credentials,” Baker said. “We see no reason that that trend will change in 2013.”

A year ago, an analysis of the breach of global-intelligence firm Stratfor found that many of the site’s customers had selected weak passwords for their accounts, with one analysis breaking about 10 percent of the passwords in five hours. Other analyses of leaked passwords have found similarly poor password choices, as well as the reuse of passwords across sites.

Malware shows a different trend. Cyber-crime campaigns aimed at compromising specific businesses will become more refined, while broader campaigns will focus on narrower subsets of victims, said Ryan Sherstobitoff, a threat researcher with software-security firm McAfee.

He pointed to the Citadel Trojan as a good example. In October, the creators of Citadel released a new version – dubbed the “Rain Edition” – which allows botnet operators to customise attacks for specific victims. Citadel is a variant of the infamous Zeus banking Trojan, created after the Zeus code base was leaked to the Internet in 2011. In one case, a campaign using Citadel targeted victims that lived in Madrid.

“Things are becoming more targeted and more detailed: They are targeting specific populations and specific users,” Sherstobitoff said.

The tools are becoming more user-friendly for criminals as well. Citadel, for example, allows support, has a customer relationship management (CRM) tool and has a trouble-ticketing system.

The Citadel botnet is not just used for bank theft. In August, the FBI warned about criminals using the Citadel Trojan for ransomware attacks, where a victim’s system freezes unless they pay money.

BYOD Paranoia?

While bad passwords and targeted attacks will be problems for companies and their employees, businesses should also look to their Websites. About three-quarters of all attacks also used a Web exploit to gain access to sensitive data, Verizon’s Baker said.

Mobile malware, however, continues to pose a minimal threat, at least in the United States, he said. While companies are worried about employees bringing compromised devices inside the network, so far that threat has not materialized, said Baker.

“Consumers are very rapidly adopting their mobile devices,” he said. “Enterprises are going to be a bit more risk-adverse than the typical consumer, however.”

Are you a security pro? Try our quiz!

Originally published on eWeek.

Robert Lemos

Robert Lemos covers cyber security for TechWeekEurope and eWeek

Recent Posts

Boeing Starliner Set For First Crewed Flight After Delays

Boeing Starliner space capsule set for first crewed flight into orbit after years of delays,…

4 hours ago

Google, DOJ Closing Arguments Clash Over Search ‘Monopoly’

Google clashes with US Justice Department in closing arguments as government argues Google used illegal…

12 hours ago

Stanford AI Scientist Working On ‘Spatial Intelligence’ Start-Up

Prominent Stanford University AI scientist Fei-Fei Li reportedly completes funding round for start-up based on…

13 hours ago

Apple Shares Surge Ahead Of New AI Hardware Launches

Apple shares surge on optimism that new AI-focused hardware launches will drive renewed sales, starting…

13 hours ago

Biden Vetoes Republican Measure In Row Over Contractors’ Unions

Biden vetoes Republican-backed measure amidst dispute over 'joint employer' status for contract workers, affecting tech…

14 hours ago

Lawyers Say Strict Child Controls In China Show TikTok Could Do Better

Lawyers in US social media addiction action say strict controls on Douyin in China show…

14 hours ago