Symantec: 2015 was a year that proved that there are 300 million reasons why you should improve your computer security in 2016 by using IPS.
Without adequate and multi-layered security, the internet was an incredibly threatening landscape in 2015, and this is a trend that will undoubtedly continue in 2016, according to experts at Symantec Corp.(NASDAQ: SYMC), the world's largest cybersecurity company.
Symantec , in order to protect its customers, provides comprehensive security solutions that include a range of products and services. However, when it comes to protection against web - based threats, Symantec 's Intrusion Prevention System ( IPS ) is an essential addition to a multi-layered security solution. IPS can protect computers and everything related to them in a way that an antivirus alone cannot. By scanning all network traffic, IPS detects threats that use known exploits and attack vectors. Instead of detecting specific files, IPS detects the specific methods used to place malicious files on networks, thus protecting users from known and unknown threats, even before antivirus signatures are created for these threats.
IPS of security issues, including vulnerabilities, zero-day exploits, exploit kits (EK), social networking threats, command and control (C & C) operations, back doors and botnets, online fraud, malicious attacks, phishing and more. How effective this technology is is shown by the results of the customers who trusted Symantec IPS during 2015.
Exploit kits (EK)
It is certainly difficult to protect against vulnerabilities that one does not know about, which is why advanced attacks continue to favor zero-day to penetrate their victims’ computers. Attackers move quickly to exploit zero-day so that software vendors have as little time as possible to create appropriate patches, resulting in shorter and shorter response times. Last year, a similar attack on Italian software vendor Hacking Team.
In 2015, Angler EK was the leader in this area and one of the most active EKs during the year. Symantec IPS managed to block hundreds of thousands of attacks from this kit. The total number of attacks based on Angler exceeded 19.5 million. Its favorite mechanism was malvertisements , mostly exploiting Adobe Flash.
The number of EK attacks overall that Symantec blocked in 2015 was around 300 million, an average of 25 million per month! This statistic alone shows how pervasive EKs are on the internet. Angler was significantly ahead of other EKs , with almost 20 million attempts successfully blocked by IPS .
Windows 7 was Angler 's favorite target in 2015, accounting for 64 % of all blocked attacks targeting this operating system, followed by Windows 8.1 ( 24%) and Windows Vista ( 5%). Mac OS X users were not targeted by Angler EK , but that doesn't mean it will remain that way as cybercriminals are increasingly paying attention to the Apple ecosystem .
At the top of the list of countries targeted by IPS in 2015 was the US (45%), followed by Russia (14%) and Brazil (8%). An important thing to keep in mind when looking at these figures is that they represent actual attacks that were blocked . This means that IPS protected many millions of users from cyberattacks who would likely not have been as lucky without IPS systems .
Technical support scams
In 2015, there was a 200% increase (compared to 2014) in technical support scams. Symantec IPS managed to block hundreds of thousands of such scams throughout 2015. The second half of the year saw a significant increase in this trend, which it should be noted will continue this year. In total, Symantec with its solutions blocked more than 100 million technical support scams in 2015. The countries most targeted in these scams were the US, the UK, France, Australia and Germany.
Exploitation of vulnerabilities In addition to the exploitation of vulnerabilities by EKS , Symantec IPS managed to block a significant number of attacks aimed at exploiting vulnerabilities in operating systems and applications in 2015. In total, over 240 million such exploitation attempts were blocked by Symantec IPS .
Windows XP stood out in the ranking of operating systems targeted by their malicious attacks with 71% of attacks blocked by IPS. Even though Microsoft has now stopped supporting XP , it seems that there are many users who are hesitant to upgrade their operating system and attackers are fully aware of this and are exploiting this situation.
Malware ( post-infection)
Symantec IPS also blocked some malware threats that had already infiltrated users' systems and then attempted to perform malicious activities. Specifically, it managed to block over 700 million malware attempts to perform C & C actions , act as a downloader , or perform other malicious activities on users' computers .
Windows, in its various versions, was the operating system that accounted for the majority of attacks in 2015, with Windows 7 (66%) taking the lead. This trend shows that most of the users infected by malware were home users.
Implementing an Intrusion Prevention should be the first line of defense against threats that attempt to take control of users' computers. IPS should be part of a multi-layered security solution. It is recommended to implement multiple security measures, including antivirus, firewall, antispam, and IPS, in order to protect the user from the multitude of threats that exist today. Norton Security, Symantec Endpoint Protection, and many other Symantec security products provide network protection (firewall and IPS).

