Tuesday, March 8, 2011

Our Digital Life Deciphered

comScore always has some very interesting statistics when measuring the digital world and these recent reports are no different.  The 2010 U.S. Digital Year in Review has great info both in understanding media trends and knowing what the end user is actually doing out there.  The 2010 Mobile Year in Review is also interesting in looking at mobile device and OS trends and the differences worldwide, both in models and what users are utilizing them for.  There are tons of graphs and analysis covering areas like U.S. Retail E-Commerce Spending, Percent of Time Spent for Top 5 U.S. Web Properties,  U.S. Unique Visitor Trend for Leading Social Networking Sites, Percent Share of Searches Among U.S. Core Search Engines, Growth in Total U.S. Online Video Market, Top Mobile Activities in the U.S. and many more.

These were a few that I found interesting - taken directly from the reports.

* 9 out of every 10 U.S. Internet users now visit a social networking site each month.

* Facebook now accounts for 12.3% of time spent online in the US - up 7.2% just a year ago. 

image

* After Portals, Social Networking now ranks as the next most engaging activity at 14.4 percent of time spent online (up 3.8 percentage points), while Entertainment ranks third at 12.6 percent (up 0.8 percentage points). As communication continues to shift to other channels, including social media and mobile, usage of web-based email declined 1.5 percentage points to 11.0 percent of time spent.

* An average of 179 million Americans watch video each month and the average American spent more than 14 hours watching online video in December, a 12-percent increase from last year, and streamed a record 201 videos, an 8-percent increase.

image

* In September 2010, smartphone ownership crossed the 25 percent threshold, marking a significant milestone in smartphone adoption in the U.S. By December 2010, smartphone penetration had reached 27 percent of the mobile market.

* Samsung unseated last year’s OEM (original equipment manufacturer) leader, Motorola, to rank as top OEM provider with 24.8 percent of devices owned by mobile subscribers in December 2010, up 3.6 percentage points from the previous year.

ps

Related:

Technorati Tags: blog, social media, comscore, music, statistics, blog traffic, web traffic, digital media, mobile device, analytics, video

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, March 2, 2011

Where Do You Wear Your Malware?

The London Stock Exchange, Android phones and even the impenetrable Mac have all been malware targets recently.  If you’re connected to the internet, you are at risk.  It is no surprise that the crooks will go after whatever device people are using to conduct their life – mobile for example, along with trying to achieve that great financial heist….’if we can just get this one big score, then we can hang up our botnets and retire!’  Perhaps Homer Simpson said it best, ‘Ooh, Mama!  This is finally really happening.  After years of disappointment with get-rich-quick schemes, I know I'm gonna get Rich with this scheme...and quick!  Maybe we call this the Malware Mantra!

Malware has been around for a while, has changed and evolved over the years and we seem to have accepted it as part of the landmines we face when navigating the internet.  I would guess that we might not even think about malware until it has hit us….which is typical when it comes to things like this.  Out of sight, Out of mind.  I don’t think ‘absence makes the heart grow fonder’ works with malware.  We certainly take measures to guard ourselves, anti-virus/firewall/spoof toolbars/etc, which gives us the feeling of protection and we click away thinking that our sentinels will destroy anything that comes our way.  Not always so.

It was reported that the London Stock Exchange was delivering malvertising to it’s visitors.  The LSE site itself was not infected but the pop-up ads from the site delivered some nice fake warnings saying the computer was infected and in danger.  This is huge business for cybercriminals since they insert their code with the third-party advertiser and never need to directly attack the main site.  Many sites rely on third-party ads so this is yet another area to be cautious of.  One of the things that Web 2.0 brought was the ability to deliver or feed other sites with content.  If you use NoScript with Firefox on your favorite news site (or any major site for that matter), you can see the amazing amount of content coming from other sources.  Sometimes, 8-10 or more domains are listed as content generators so be very careful as to which ones you allow.

With the success of the Android platform, it also becomes a target.  This particular mobile malware looks and acts like the actual app.  The problem is that it also installs a backdoor to the phone and asks for additional permissions.  Once installed, it can connect to a command server and receive instructions; including sending text messages, add URL’s/direct a browser to a site along with installing additional software.  The phone becomes part of a botnet.  Depending on your contract, all these txt can add up leading to a bill that looks like you just bought a car.  In fact, Google has just removed 21 free apps from the Android Market saying its malware designed to get root access to the user’s device.  They were all masquerading as legitimate games and utilities.  If you got one of these, it’s highly recommended that you simply take your phone back to the carrier and swap it for a new one, since there’s no way of telling what has been compromised.  As malware continues to evolve, the mobile threat is not going away.  This RSA2011 recap predicts mobile device management as the theme for RSA2012.  And in related news, F5 recently released our Edge Portal application for the Android Market – malware free.

Up front, I’m not a Mac user.  I like them, used them plenty over the years and am not opposed to getting one in the future, just owned Windows devices most of my life.  Probably due to the fact that my dad was an IBM’r for 30 years.  Late last week, stories started to appear about some beta malware targeting Macs.  It is called BlackHole RAT.  It is derived from a Windows family of trojans and re-written to target Mac.  It is spreading through torrent sites and seems to be a proof-of-concept of what potentially can be accomplished.  Reports say that it can do remote control of an infected machine, open web pages, display messages and force re-boots.  There is also some disagreement around the web as to the seriousness of the threat but despite that, criminals are trying.

Once we all get our IPv6 chips installed in our earlobes and are able to take calls by pulling on our ear, a la Carol Burnett style, I wonder when the first computer to human virus will be reported.  The wondering is over, it has already happened.

ps

Resources:

Technorati Tags: F5, mobile, android, Pete Silva, security, malware, education, technology, apple, mac, cloud, trojan, virus, blackhole, web, internet, cybercrime, identity theft, scam, google, data breach

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, February 24, 2011

RSA 2011 Wrap and Blooper Reel

I had a great time in San Francisco last week seeing and interviewing many of our security partners.  Special thanks goes out to Jerry Skurla and Kara Hutchins of NitroSecurity, Chris Poulin with Q1 Labs, Jeremiah Grossman of WhiteHat Security, F5’s Andy Oehler, Benny Czarny and Steven Ginn from OPSWAT and Steve Dispensa of PhoneFactor.  We covered a whole range of topics including token less multi-factor authentication, USB key checkers, BIG-IP Edge Client on iPad, WASC, XSS attacks, OWASP, SIEM, incident response, security reporting, integration and more.  I seem to get lucky at RSA since I was able to again interview many of the respective company’s C-level folks and truly appreciate their time and involvement. 

What’s become a tradition after a week of video interviews is my Blooper Reel.  There are always outtakes from any video shoot and while they usually end up on the cutting room floor, I like sharing many of the behind-the-scenes flubs since some are actually humorous.  I’ve also included a little homage to Robot Chicken if you are a fan.  Enjoy.

ps

Resources:

Technorati Tags: F5, RSA, Pete Silva, security, business, education, technology, internet, cybercrime, phonefactor, nitrosecurity, q1labs, opswat, ipad, rsa

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, February 17, 2011

RSA2011 F5 Partner Spotlight–NitroSecurity

I meet with Jerry Skurla, EVP of Marketing for NitroSecurity to discuss integration, SIEM, and the importance of these types of reporting systems. Kara Hutchins, Product Manager, gives a demo of their cool NitroView report and management GUI

ps

Resources:

Technorati Tags: F5, RSA, Pete Silva, security, business, education, technology, internet, cybercrime

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

RSA2011 - Interview with Jeremiah Grossman

I have a great chat with security expert Jeremiah Grossman, Founder & CTO of WhiteHat Security. The interesting discussion touches on WASC, XSS attacks, OWASP and a few other security topics. Fun and informative.

ps

Resources:

Technorati Tags: Technorati Tags: F5, RSA, Pete Silva, security, business, education, technology, internet, cybercrime, grossman

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

RSA2011 F5 Partner Spotlight - Q1 Labs

I meet with Chris Poulin, Chief Security Officer with Q1 Labs. We talk integration, SIEM, and what CSO's do.

ps

Resources:

Technorati Tags: F5, RSA, Pete Silva, security, business, education, technology, internet, cybercrime

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]