SAN JOSE - The bad guys on the internet are narrowing the time frame they need to unleash computer attacks that take advantage of publicly disclosed security holes, new research shows.
More and more of these attacks are coming within 24 hours after vulnerability is disclosed. That means security flaws are being exploited in web browsers, computer operating systems and other programs before many people even have had time to learn there's a problem, according to IBM's latest internet Security Systems X-Force report.
The report, scheduled to be released today, looked at the first six months of 2008 and reflects two growing trends in internet-based threats.
The first is that online criminals have latched on in a big way to programs that help them automatically generate attacks based on publicly available information about vulnerabilities. In the past they apparently spent more time finding such holes themselves, but no longer find that as necessary.
"The bad guys are not the ones actively finding vulnerabilities - they've shifted their business to standing on the shoulders of the security research community," Kris Lamb, operations manager for X-Force, said in an interview. "They don't have to do the hard work anymore. Their job is packaging what's been provided to them."
The second trend is that the debate among security researchers is intensifying over how much information should be released to the public when a new software flaw is discovered.
Most times the researcher will wait until the affected company has released a software patch before revealing details. But sometimes researchers will release not only details of the vulnerability but also so-called "proof-of-concept" exploit code to show the flaw is legitimate.
That runs the risk of providing criminals a framework for building their attacks, and saves them valuable time in doing so. Lamb said this finding "begs the question" of what the security industry's standard practice should be.
Some researchers defend the practice of supplying exploit code. They say it's a powerful tool to pressure companies into creating patches and users into applying them, and also helps technicians study how the attacks work and prevent against them in the future.
The IBM report found that the tools criminals use to generate their attacks - known as exploit code - are appearing online faster than before.
The time from vulnerability disclosure to the availability of exploit code or a working attack has typically been measured in days or even weeks as criminals try to get their arms around a newly discovered weakness.
But that gap has been shrinking quickly.
In web browsers - an area heavily targeted by hackers - hacking exploits were available within a day after flaws were discovered 94 per cent of the time, up from 79 per cent in 2007, IBM's report said.
For all PC vulnerabilities, over 80 per cent of the exploit code was released the same day - or even before - the holes were publicly disclosed. That's up from 70 per cent last year, according to the IBM study.
Exploit code can surface even before a vulnerability is made public if researchers have discussed the flaw without providing specifics.
The tactic allows them to attach their names to high-profile vulnerabilities they've discovered, while giving companies time to create patches. The downside is other researchers can often work backward from the public comments and create their own exploit code.