Cyber-Attackers Most Often Target Nine Business Apps: Research Report

執筆者
Robert Lemos
Robert Lemos
Published: Feb 23, 2013
Updated: Feb 2, 2021
3 minute read
Cyber-Attackers Most Often Target Nine Business Apps: Research Report
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

An analysis of exploit and malware traffic inside corporate networks found that social networks account for few attacks, while 97 percent of exploit traffic focused on 10 applications, nine of which were critical business applications.

The analysis of log data from 3,056 companies underscores that internal corporate applications, not multimedia and social-networking applications, are the focus of attackers, said Matt Keil, a senior research analyst with Palo Alto Networks, which compiled the report.

Attackers directed most of their malicious traffic at ports used for communication with Microsoft’s SQL and remote procedure calls (RPC), Web browsers and the Server Message Block (SMB) protocol, a common way of sharing access to file servers and printers, according to the report.

The other network and application access protocols include Active Directory, Domain Name System (DNS), Microsoft Office Communicator, Microsoft SQL Monitor and Session Initiation Protocol (SIP).

“When you compare social networking to the volume in the logs aimed at the internal applications … it indicates that security is somewhat crunchy on the outside and tender on the inside,” Keil said. “Somehow the exploits and malware are bypassing your perimeter security and targeting the business applications.”

The companies that took part in the survey contributed more than 260 million log entries detailing the communications of approximately 5,300 threats.

Each company had an average of 17 social networking, 19 file-sharing and 30 photo or video applications being used by employees. But attacks on those programs remained rare. Those types of programs accounted for a quarter of the applications whose communications were found in the log files and 20 percent of the bandwidth consumers. But they accounted for only 0.4 percent of all attack data in the logs.

Surveys have shown that IT managers worry about malware spreading through Facebook and other social applications. But Palo Alto’s data appears to show that such attacks are uncommon. Anecdotal evidence has supported both claims. In 2011, the Koobface worm stopped using Facebook to spread in 2011. However, Microsoft claimed the same year that phishing scams and adware had increasingly used social networks to spread.

Advertisement

More than 2,000 exploits targeted the applications internal to corporate networks. The lion’s share, however, were targeted at employees’ Web browsers. More than 1,550 different attack types focused on the browser, while the SMB file services ranked a distant second with 222 exploits.

“SQL databases, SMB file services, Active Directory and RPC all represent the soft underbelly of the corporate business infrastructure where the intellectual property, corporate information, credit card data, or perhaps social security numbers are stored,” the report stated.

About a tenth of all traffic on the network is considered unclassified or custom. While some malicious programs communicate with command-and-control servers using Web browsing or Domain Name System (DNS) queries, more than half use a custom UDP protocol, according to the Palo Alto report. The ZeroAcess botnet, Conficker, the Poison Ivy remote-access Trojan, and other malicious programs use custom communication protocols.

“The analysis clearly shows that customized or modified traffic is highly correlated with threats,” the company stated in the report. “This indicates that proactively controlling or blocking ‘unknown’ traffic could easily provide a powerful and untapped strategy for controlling modern threats.”

Robert Lemos

Robert Lemos is an award-winning journalist who has covered information security, cybercrime and technology's impact on society for almost two decades. A former research engineer, he's written for Ars Technica, CNET, eWEEK, MIT Technology Review, Threatpost and ZDNet. He won the prestigious Sigma Delta Chi award from the Society of Professional Journalists in 2003 for his coverage of the Blaster worm and its impact, and the SANS Institute's Top Cybersecurity Journalists in 2010 and 2014.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。