Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Malware Writer's Trying to Stay Ahead | Main | Web 2.0 Small but Still Weak on Security »

Resources and Tools for Measuring Security Threats

Accurate numbers about security are tough to come but I still like to find and track them as much as possible. We can tell from war stories shared with colleagues that malware, spyware and phishing seem to be getting worse, but I want to know how much worse. There's an old adage in management that if you can't measure it, you can't manage it. I don't think this is totally true for security but I think it's still useful to keep in mind.

So, where can we get the measurements? Here are some pointers:

Thanks to Infosecwriters.com for posting about Daniel James' Statistical Analysis of Internet Security Threats. It's a good overview and not too technical. I like this one because it is written for the average Internet user, not the security or IT professional. This can help with user awareness.

For more up to date tracking of threats on the Internet, the is the Microsoft Malware Protection Center. It's new and more will be coming, but it gives a quick summary of what most active threats. McAfee, sponsor of this community, has a similar site; I especially like the global virus map.

What I'd like to see, but haven't found yet, it up to date information on malware infected Web sites and P2P networks. I've wondered before if Google would get into the business of tracking malware infected sites and I just found a company called Robot Genius which has a Web crawler building a database of malicious executables on the Internet. Good luck. Maybe their software with Googles hardware could do a decent job of it. I think this is an area we need more concentrated effort. We need for options for identifying threat-hosting sites. Daniel James' paper argues for safer surfing to control the spread of spyware but we need tools.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/296

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net