April 12, 2004 11:14 AM PDT

Concern grows over browser security

Browser-based security threats are on the rise and may pose the next significant risk to information technology operations, according to a technology trade association.

The Computing Technology Industry Association (CompTIA) on Monday released its second annual report on IT security and the work force. The survey asked nearly 900 organizations to rank their top 15 security concerns. According to the results, 36.8 percent said they were plagued by one or more browser-based attacks in the last six months. That's up from 25 percent in last year's survey.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


"Browser-based attacks are a logical evolution," said Randall Palm, director of IT at CompTIA. "The better we get at stopping attacks, the more creative hackers get at writing new ones. Ten years ago, most viruses were distributed on floppy disks. Then came e-mail and instant-messaging software. Now, they are targeting browsers."

Browser-based attacks are typically unleashed when a person visits a Web page that appears harmless but actually contains hidden code intended to sabotage a computer or compromise privacy. Some attacks simply crash a browser, while others pave the way for the theft of personal information or the loss of confidential proprietary data.

One of the most common ways of disseminating these attacks is through e-mails that include a link to a malicious Web server. Because the attacks usually aren't launched until the user clicks on the link, many firewalls don't catch them. Traditional firewalls examine traffic coming into the network, but guarding against browser attacks requires that traffic leaving the network also be inspected.

Some companies are using products from start-ups such as SurfControl and Websense that are designed to monitor and control corporate Web usage in order to help protect against browser-based attacks. Firewall vendors, like Check Point Software Technologies and NetScreen Technologies, have also added some protection. But Palm said these companies still have a long way to go before they eliminate the problem.

"Stateful inspection of inbound vulnerabilities is not Check Point's or NetScreen's main focus," he said. "All the firewall vendors are playing catch-up, when it comes to protecting against this threat."

Browser vendors also are taking action to minimize the risk to their products. In January, Microsoft said it would release software updates to Internet Explorer and Windows Explorer designed to protect Web surfers from being lured to Web sites that could contain malicious code. In December, a Danish security firm alerted the security community to an IE bug that would let hackers display false Web addresses.

While concern over browser-based security threats is growing, companies still view computer viruses and worm attacks as the most threatening security risk. But these threats are significantly less common than they were a year ago, according to the survey. Last year, 80 percent of organizations identified worm and virus attacks as their most common IT security threat. This year, that number is 68.6 percent.

Last year, network intrusion issues were the second-most common security threat, garnering 65.1 percent of the vote. This year, network intrusion issues dropped significantly, falling to 39.9 percent. This drop could be attributed to the high percentage of companies using antivirus applications to fight viruses and worm attacks. According to CompTIA, 95.5 percent of organizations use some form of antivirus technology.

Firewalls and proxy servers are the second-most commonly used antivirus technology, employed by 90.8 percent of respondents. Companies also are doing more security audits and penetration testing. They were used by 61 percent of respondents, up from 53 percent.

See more CNET content tagged:
Check Point Software Technologies Ltd., CompTIA, worm attack, security threat, corporate security

Add a Comment (Log in or register) 3 comments
Which browsers?
by powerclam April 12, 2004 2:38 PM PDT
This article only mentions IE, and only says that they're adding in fixes to alleviate these problems.
This gives the impression that ALL browsers are vulnerable and that only M$ is doing antyhing to address the problem.
But isn't it true that 95% of all browser-vulnerabilities/exploits are ONLY dangerous to users of M$'s shoddy POS-ware?
(hint: yes...)
Reply to this comment View reply
Agree with Bob
by schief April 13, 2004 2:37 PM PDT
This story is misleading in that it seems to indict all browsers when in fact it is only IE that has been endowed with the ability to breach OS kernel security. This was done deliberatly back during the browser wars so MS could prove that IE was an integral part of the OS and not just an add-on. MS has a record of tweaking their software and apps to quash competition reardless of consequences.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    Report: More competitive processors due from AMD

    AMD will bring out processors by early next year that appear to be much more competitive with Intel offerings.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Ad trade group opposes Yahoo-Google search deal

    Association of National Advertisers announces it has sent a letter to the top antitrust chief for the U.S. Department of Justice, issuing its objections to the controversial Yahoo-Google search ad partnership.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    DemoFall preview: 10 to watch

    If you can only watch 10 pitches from DemoFall, these would be good ones.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.