It only covers a six-month snapshot, but the conclusions run counter to popular wisdom:
http://www.internetnews.com/security/article.php/3667201