Although solutions evolve, so do the mechanisms, technologies, and ways to infect users. The variety of devices and the increase in the use of mobile devices represents a new challenge when it comes to curbing malicious files.
By Alejandra García Vélez
Advances in technology, the increase in the penetration of all types of devices and the increasing presence of the Internet in the region are the breeding ground for users to be increasingly vulnerable to computer attacks that manifest themselves in data theft and the growing number of viruses, malware and spyware that spread through the network every day.
This was stated by Jesús Calle, systems engineer for the Andean, Central American and Caribbean Region of Kaspersky Lab, in conversation with this magazine. "Malware in general is growing day by day. In Kaspersky laboratories, up to 200,000 samples of possibly infected files have been received in high-work days and the amounts of malware detected exceed 7,200,000 types. The growth is exponential from 2004," explained the expert.
For his part, Andrés Valcárcel CEO of Frontech Ltda., explained that the mode of operation of the Malware has varied. It is currently more stealthy and tries to go unnoticed, which is unfortunate for the victims of these attacks who look more vulnerable.
Security Sales also consulted with Gonzalo Erroz, sales manager for South America at Norton Symantec, said that in recent years the way criminal Internet networks operate has changed and they no longer only send malicious files through emails, but also use new trends such as social networks to deceive Internet users. As a result of this, attacks have multiplied and more threats have been recorded.
Faced with this scenario, it has also been necessary to improve the detection and elimination systems of these malicious files. Calle explained that in the face of the growing threat of malware, traditional methods fall short.
These methods are the Signatures, which allow to verify if the file in question has been detected and cataloged, the Heuristics in which it is verified that although it is not in the list of Signatures the file is suspicious and the Proactive Protection, which monitors the behavior of the applications.
For the protection system to be really effective, the trend is to rely on cloud protection, which allows you to compare in real time the files that may be malicious with databases and information in the cloud.
Despite the above, basic prevention care remains the same. "End users should be careful about the sites they browse, have a good antivirus and try to keep up with the operating system patches and the applications they use. As well as not using USB sticks, or storage devices in public places, "said Calle.
The user is especially vulnerable to the lack of patches, sometimes due to ignorance the equipment is not updated as necessary. In addition, trust and the non-use of antivirus is a latent risk. "The best tool is knowledge, if you are aware of the risks you can take the necessary measures," the Kaspersky official reiterated.
Valcárcel makes an interesting analogy, highlighting that the use of a licensed anti-malware product will always be ideal, but that the best protection that a user can handle is and will continue to be prevention coupled with caution in their browsing habits. "The alarm of a house is useless, if its owner comes out and leaves a door open," he said.
The Frontech official also highlights that the main threat remains Social Engineering, which is also one of the most common methods of violation. "From this deception derive infections with Trojans and one of the consequences is that many computer equipment end up being zombies, that is, they become part of a bonnet network and can be controlled at the will of cybercriminals without the victim quickly noticing it," he said.
Risk is mobile
With the growing trend to use mobile devices and cloud services, new questions arise: How can these systems be protected? Are mobile devices and cloud services more, equally, or less vulnerable to these threats?
In this regard, Calle explained that system patches and a good antivirus are the answers. "The Internet is an excellent tool but at the same time a source of infections. If we understand mobile devices as smartphones, every day the threats and malware against them increase."
And he added that "protection is always necessary, the risks for mobile devices are not only on the network but come from the use of them, theft, loss of identity, loss of confidential information, unwanted messages and calls. Against all these threats there are specific products that protect efficiently."
When inquiring Valcárcel on this subject, the interviewee said that denerally the servers that work providing services in the cloud, must be protected by their respective provider, but this does not guarantee the protection of a mobile computer, as the threats for this type of devices is also growing exponentially, there are already antivirus solutions for this type of devices that also help them protect against theft.
"I do not want to be insistent but the best protection is a recognized and licensed antimalware, combined with the prudence of the user in the use of these devices on the Internet," Valcárcel said.
Faced with this issue, the Symantec executive said that "today, the growing use of mobile devices and the cloud generates a new scenario for threats that, far from being reduced, are renewed to adapt and become more dangerous. In this field, smartphones are a weak point since they are not only used to simplify work activity, but also have an increasing impact on people's leisure moments".
And he concluded by pointing out that "the greatest alert of vulnerability in terms of security is located in the download of applications and in banking transactions, which leaves us exposed to the risk of losing our valuable data or falling into specialized hands. The advice for users is to keep in mind that smartphones are small computers, consequently, we have to take the same care that we have on the PC."
The trend
To better understand the current landscape of malware aimed at this type of equipment, we take as a reference the report "Trends 2012: Mobile malware" prepared by the ESET Latin America Laboratory.
The first conclusion of this report is that "threats to mobile devices, both in terms of new malicious code and Internet scams; will be the most relevant for next year (2012), in addition to the appearance of new types of attacks, as well as new variants of existing ones".
As explained, the second half of 2011 showed a trend towards the development of new threats designed especially for operating systems used in mobile devices, and it is expected that in 2012 this reality will continue to increase.
In addition, in the analyses carried out by the ESET Latin America Laboratory, 15 of the 41 suspicious mobile applications analyzed were used as SMS Trojans, a modality that has established itself as one of the main threats for this type of device.
Similarly, 60% of the malicious codes analyzed by the company had botnet-like characteristics. Faced with the above, it is striking that many of these are mobile versions of codes already existing on PC.
"Clearly different malware variables have been migrating during 2011 to mobile versions. The trend is for this to continue, and once the first cases for a specific type of malicious code appear, the next step would be the creation of variants that can begin to massify slowly," the report said.
And it concludes by stating that "users must be aware of the value of the information they transport day by day on their mobile devices and must understand that they can not only compromise the confidentiality of it while using web services but with the loss and / or theft of equipment."
Despite the above, the ESET report emphasizes that there will not be a total migration of malware to this type of equipment, but it does imply certain changes that must be taken into account to protect the information effectively.


