Picture of padlock
Finjan: Malicious code resides much more in the UK and US than previously thought

UK and US top malware hosting sites

Ninety per cent of the URLs containing malicious code resided on servers in UK or US

Written by Tom Young

Malicious code is more likely to be hosted on local servers in the US and UK than in countries with less developed e-crime law enforcement policies, according to research from vendor Finjan.

Over 80 per cent of the malicious code detected by Finjan was obfuscated, making it virtually invisible to pattern-matching and signature-based methods used by anti-virus products.

Ninety per cent of the URL’s containing malicious code that were discovered resided on servers located in the US or UK.

'The results of this study shatter the myth that malicious code is primarily being hosted in countries where e-crime laws are less developed,' said Yuval Ben-Itzhak, chief technology officer at Finjan.

'Our research shows that malicious content is much more likely to show up on a local server than one in Asia or Eastern Europe. Unfortunately this means that the traditional location-based reputation heuristics are decreasingly effective against modern attacks.'

The research also found increasing sophistication of embedding malicious code within legitimate content (e.g., ad delivery and translation services) and less dependence on outlaw servers in unregulated countries.

Advertising is the leading category for URLs containing malicious code, representing 80 per cent of all instances. Attackers have discovered that the multiple parties involved and the complex structure of business relationships involved in online advertising make it relatively easy to inject malicious content into generally legitimate ad delivery streams.

Similarly, when analysing malicious content in terms of the URL web site categories, Finjan found that malicious code is just as likely to be accessed through legitimate web sites as through what might be considered disreputable  sites.

'The fact that malicious code is just as likely to be found in legitimate categories as in questionable categories means that security products that rely solely on URL categories to block access to malicious sites are no longer effective,' said Ben-Itzhak.

reader comments

related articles

Malware spreading via Skype

Beware URLs bearing gifts 23 Mar 2007

 

Dorf storms the malware charts

Accounts for almost 50 per cent of all malware seen during January 31 Jan 2007

Symantec clears Vista on malware

Not a secure system, just more sturdy than previous Windows versions 01 Mar 2007

Hacked page hauls estimated at $10,000 a day

Referral scams netting big bucks for criminals 23 Mar 2009

Massive UK and US botnet uncovered

Finjan finds Ukraine-controlled network of nearly two million compromised PCs 22 Apr 2009

Finjan tracks huge botnet

Sophisticated botnet infiltrates government departments around the world 22 Apr 2009

related whitepapers

today's top stories

What does Windows 7 mean for Microsoft?

With the sting of Vista still fresh, Redmond has to make next Windows work 10 Jul 2009

A smarter way to use BI

Getting the most from business intelligence systems requires not only careful management on the part of IT leaders, but also the committed involvement of decision-makers across the organisation 08 Jul 2009

The truth behind the Google/Microsoft/NHS rumours

Before Monday 6 July, did you know that Google and Microsoft had services for storing health records? Thanks to an article in... 10 Jul 2009

Quenching a thirst for IT modernisation

A substantial restructure at soft drink supplier Nichols -­ purveyor of Vimto - ­led the company to update its software to Sage 1000 to replace its in-house application. This resulted in the streamlining of the IT department and an opportunity to customise the system 08 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will Google Chrome OS be a genuine alternative to Windows?

Will Google Chrome OS be a genuine alternative to Windows?

Tell us your views on the new operating system rivalry

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation