Related Links

Related Stories

  • Researchers build browser-based darknet
    Researchers have developed technology that enables users to participate in an anonymous, private communication session using nothing but an HTML 5-compliant web browser.
  • ‘Brad Pitt’ more dangerous than ‘Hugh Jackman’ – McAfee rates risky search terms online
    Searching for ‘Brad Pitt’ is riskier than searching for ‘Hugh Jackman’ according to a McAfee study on the most dangerous search terms online.
  • McAfee Calls for More Legal Measures on Cybercrime
    ISPs, banks and software vendors must be legally persuaded to take a more prominent role in fighting cybercrime, warns a report from McAfee released Tuesday 9 December. The firm's Virtual Criminology Report calls for more law enforcement training and more liability for software vendors, along with legal incentives for ISPs as the 'front line' for anti-cybercrime measures.
  • Nine Lives - Self-modifying Malware
    As the Conficker worm proved when it first appeared in October 2008, there’s more to a piece of malware code than meets the eye, especially when it is self-updating. But can self-updating also mean self-modifying? Steve Gold investigates whether an IT security manager’s nightmare has become a programming reality
  • Information security goes green
    Green IT has gone mainstream. The last year has seen corporations such as Citigroup establishing their environmental credentials by opening green data centers. But how do the separate disciplines of green IT and information security come together? Robin Arnfield reports

News

McAfee: Hybrid apps will be hacker target

04 January 2010

Applications that blur the boundaries between online and offline software will be a primary hacker target this year, according to McAfee.

In its 2010 Threat Predictions Report, McAfee said that the advent of HTML 5 - a yet-to-be-ratified, enhanced version of the HTML language used to create web pages - is blurring the line between the internet and the desktop. New functionality in the language makes web apps act more like desktop computer software than ever before. The hacker community will be drawn to this phenomenon, McAfee predicted.

An example of a HTML 5-based application is Google Wave, which reinvents email, combining it with instant messaging-like functionality to create online conversations that can be embedded in other web pages. The anti-virus vendor singled out Google's Chrome OS as a technology that will complement the new language to draw interest from hacker groups.

Chrome OS, an open-source operating system that was released to developers in November, is designed for use on netbooks and other small footprint devices that rely almost exclusively on internet-based applications for their operation. The system is scheduled for end-user release later this year.

"Google Chrome OS is intended for use with netbooks, and HTML5 enables not only a rich internet experience, but also offline applications. Another motivation for attackers is HTML 5’s anticipated cross-platform support, which will allow attackers to eventually reach users of many mainstream browsers", McAfee continued.

The document also suggested that the hacker community may switch its emphasis from Microsoft to Adobe. "In 2010, we anticipate Adobe software, especially Acrobat Reader and Flash, will take the top spot", it said. Adobe has already seen several zero-day attacks from hacker groups targeting these two.

Other, perhaps more obvious, predictions from the report include more sophisticated hacker threats targeting social networking applications, as their user numbers increase, and cleverer banking trojans (it's generally a safe bet to assume that the hacker underground won't become dumber, and simpler, and neither will its products).
 

 

This article is featured in:
Internet and Network Security Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.