|

Read more>> Threats and Trends Mars 2009(Stockholm 2009-03-30) After the alert statistic showed that most alerts occur in Intra LAN last month, we now see that Internet is the most targeted zone. Intra LAN is still targeted by severe alerts, and many reported incidents are generated in this zone. The reason for this severe traffic is the Downadup/Conficker virus. There has been a slight increase in the number of reconnaissance attacks. The traffic mostly targets well known Microsoft ports, and the service port 5900 (VNC). We also see an increase in the number of reconnaissance attacks towards port 3306 (MySQL). Some of the Microsoft ports may be used for the Downadup virus. Among spam/worm we continue to see an increase in the traffic towards port 445. This is due to the Downadup worm targeting this port.
Focus of The Month: IDS TECHNOLOGY Threats and Trends is produced by personnel in Secode's Operations Centre, and the report is based upon events registered during the specified period. The report contains events deemed to be of public interest, as they are registered by Secode and the vaious sensors and observation points in different networks. All specific and identifiable information about companies and Secode customers is removed in this report. The reports are published on these pages monthly. The reports only contain observations, and Secode will not accept any responsibility for interpretations, theories or conclusions based on this material by any third party. No further comments on material presented in the reports will normally be given by Secode. Copyright Secode AB 2007 - 2009. |