Many people think that most malware gets into your system through sofware vulnerabilities that haven't yet been discovered and fixed by the manufacturer. These kinds of attacks (called "zero-day vulnerabilities") make headlines and can lead you to believe there's not much you can do to stop them. If the software manufacturer hasn't discovered the threat and issued a patch to fix it, what can you do?
A recent study by Microsoft found that such beliefs are largely unfounded. Using software tools they deploy to track such events, they found that only 0.01% of all attacks exploit zero-day vulnerabilities. Nearly 50% of attacks use social engineering techniques to trick the user into clicking a link or revealing private information (see my last blog entry for more on this story). What can you do to protect yourself? Besides the obvious of not clicking on suspicious links or disclosing private information to strangers, you should also make sure you are running the most recent versions of your applications. According to outside tests, for example, Internet Explorer 9 is more resistant to malware attack than any other browser. Here's a link to an Information Week story about the Microsoft study: Zero-Day Threats Exaggerated, Says Microsoft Report.
No comments:
Post a Comment