Cisco, Commtouch and other security companies are reporting a drop in the amount of spam email worldwide. Most expected a spam increase around the holidays, which did not happen. Commtouch reported a 30% decrease in SPAM from the September 2010 high. Some experts believe that spammers may be changing their attention from e-mail to attacks in the social networking realm. This alone should bring up concern to those running a secure web gateway and proxy for web services.
There's no doubt that social networking is a prime target for malware, and if the assumption by experts is true, there's more need than ever to be making sure that IT administrators are running the latest URL filtering software and malware scanning software on their secure web gateways.
Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.
Tuesday, January 4, 2011
Wednesday, December 15, 2010
Is the Cloud the Future of Web Proxy?
A quick visit to Ironport's website could make you wonder if they sell web gateway appliances anymore. The website focuses on DLP, their mid-year security report, and the cloud. In addition a lot of Secure Web Gateway manufacturers have acquired or announced intentions to start their own cloud services. Which could easily lead one to wonder if secure web gateways and proxies have a limited shelf life, and will soon be replaced by the cloud. The cloud has some obvious benefits. The first is of course, no hardware cost, so no capital expenditures. Everything is an operating expenditure, and you pay for the services on a monthly basis. This is great in a down economy when you're trying to cut capital expenditures.
But the question here is, whether the total costs over the life of the service exceed those of a hardware based solution, and what's the break-even point, at which point hardware would be cheaper? In addition what happens, when the economy picks up and the company wants to make capital expenditures? It may make it look like a cloud is preferable today, but it may not be tomorrow.
In addition, there's the usual complaints about a service offering, including the inability to schedule maintenance windows. With a service you're bound by the provider's operating windows, and you need to ensure uptime with a good SLA in place with the provider.
Finally a service offering has to appeal to all levels of organizations, from the smallest to the largest, as any size company could be their customer. That means the interfaces and the mechanisms for establishing policy for the secure web gateway is going to one that's easy to use, and has the widest appeal. While this probably works for small organizations, it's likely the policy engine will not be sophisticated enough to handle most large organization's needs around not only acceptable use policy across the organization, but the differences that may be necessary from department to department within the organization.
For these various reasons, it's probably not likely the cloud will take the place of the secure web gateway. Instead both will probably be offered for the foreseeable future, and each has its place, depending on the size and complexity of the organization.
But the question here is, whether the total costs over the life of the service exceed those of a hardware based solution, and what's the break-even point, at which point hardware would be cheaper? In addition what happens, when the economy picks up and the company wants to make capital expenditures? It may make it look like a cloud is preferable today, but it may not be tomorrow.
In addition, there's the usual complaints about a service offering, including the inability to schedule maintenance windows. With a service you're bound by the provider's operating windows, and you need to ensure uptime with a good SLA in place with the provider.
Finally a service offering has to appeal to all levels of organizations, from the smallest to the largest, as any size company could be their customer. That means the interfaces and the mechanisms for establishing policy for the secure web gateway is going to one that's easy to use, and has the widest appeal. While this probably works for small organizations, it's likely the policy engine will not be sophisticated enough to handle most large organization's needs around not only acceptable use policy across the organization, but the differences that may be necessary from department to department within the organization.
For these various reasons, it's probably not likely the cloud will take the place of the secure web gateway. Instead both will probably be offered for the foreseeable future, and each has its place, depending on the size and complexity of the organization.
Tuesday, December 7, 2010
The Move from Acceptable Use Policy to Protecting the Innocent
Web filtering really got its start as way to implement Acceptable Use Policy (AUP) in organizations that wanted to make sure their employees were spending their time on the Internet at websites that met corporate acceptable use guidelines. With the growth of the web and the spread of malware from email to websites, the focus for web filtering has really moved from implementing AUP to protecting the casual web user from malware and drive-by downloads they might get from good or bad sites.
The malware isn't exactly new, as much of what's prevalent today depends on techniques that have been in effect for years, but rather the subtlety with which they are released has changed. Rather than an anonymous email asking you to watch their video, it's a close friend's hijacked Facebook account that sends you a message asking you to watch their kid's latest accomplishment video. Click on the video and of course you'll be prompted to update your video codec, which actually downloads malware onto your computer.
An unsuspecting user will naturally trust the person they know rather than the one they don't, making the hijacked Facebook account much more malicious than a spam email asking you to watch some sexy video.
So with this evolution to targeted attacks, protecting the everyday user from malware and drive-by downloads is increasingly important for organizations, and the role the secure web gateway plays in the organization. That's why it's more important than ever to make sure your web filtering software and subscriptions are up to date, and using an accompanying anti-malware program that scans everything. Reputation based exceptions don't really work anymore, since even reputable sites can get hacked and host malware links.
The malware isn't exactly new, as much of what's prevalent today depends on techniques that have been in effect for years, but rather the subtlety with which they are released has changed. Rather than an anonymous email asking you to watch their video, it's a close friend's hijacked Facebook account that sends you a message asking you to watch their kid's latest accomplishment video. Click on the video and of course you'll be prompted to update your video codec, which actually downloads malware onto your computer.
An unsuspecting user will naturally trust the person they know rather than the one they don't, making the hijacked Facebook account much more malicious than a spam email asking you to watch some sexy video.
So with this evolution to targeted attacks, protecting the everyday user from malware and drive-by downloads is increasingly important for organizations, and the role the secure web gateway plays in the organization. That's why it's more important than ever to make sure your web filtering software and subscriptions are up to date, and using an accompanying anti-malware program that scans everything. Reputation based exceptions don't really work anymore, since even reputable sites can get hacked and host malware links.
Tuesday, November 16, 2010
Facebook adds Email
If you've been watching the news this week, it was unavoidable. You inevitably saw the announcement from Facebook that they are rolling out email services to their user base, making them the largest email provider in the world. Facebook has long been a thorn in the side of security administrators who manage secure web gateways and proxies. Most companies didn't want their employees visiting social networking sites and spending all their times on them. Times have changed, and even the US military has changed its stance on Facebook, realizing it's an important tool in keeping the troops happy. So like companies that realize Facebook is an important marketing tool, the U.S. military has to find the right balance between allowing access and making sure employees don't get carried away playing games or using other Facebook applications all day.
Having email in Facebook, just adds one more distraction, and provides one additional page to block if your organization's policy already prohibits external access to e-mail. The good news for most security and IT administrators is that modern URL filters and web protection already offer mechanisms to allow basic Facebook access, but prevent access to specific pages and applications through the use of multiple categories. Allowing the category of "social networking", but blocking "games", "alcohol", "pornography", and even "webmail" will block things like Farmville, drinking games, Playboy's Facebook page, and eventually Facebook's email application, since these are generally categorized as both social networking and the appropriate other category they fall into.
Having email in Facebook, just adds one more distraction, and provides one additional page to block if your organization's policy already prohibits external access to e-mail. The good news for most security and IT administrators is that modern URL filters and web protection already offer mechanisms to allow basic Facebook access, but prevent access to specific pages and applications through the use of multiple categories. Allowing the category of "social networking", but blocking "games", "alcohol", "pornography", and even "webmail" will block things like Farmville, drinking games, Playboy's Facebook page, and eventually Facebook's email application, since these are generally categorized as both social networking and the appropriate other category they fall into.
Thursday, November 11, 2010
The Super Long URL
Blue Coat's Security Lab's latest post is about what for most people should be an obviously bad URL:
If you actually saw a URL that looked like the one above you should be immediately suspicious that it's part of an attempt at phishing.
But in actuality of course most people don't see the URL above, they see the HTML facade that's created for the email or webpage, and the above is just what's linked to the HTML display. But wait, you're thinking most browsers will show you where the HTML actually links to, and I'm smart enough to check that out (either in the bubble that shows up in the browser or the full link in the status bar at the bottom of the page).
But what's interesting about a URL like the one above is that it's so long that the entire URL won't display in most cases, so you only see the front part of the URL in your bubble or status bar. And that's the most likely explanation behind why the hacker created the URL. If you're not careful to check out the entire URL, you'll only see the front, and it may be enough to convince some people it's a legitimate link.
So be careful, and check the full URL of where you're going on the web, or at the very least make sure you're browsing through a Secure Web Gateway or proxy device that's configured to block phishing sites.
online.citibank.com.us.jps.portal.index.do.signin.logon.citibank.online.secure.sessionid.udp pincyyadcjfwjkgporvazebpnejlinbnunptl.qtpycihnqzaepbbwdrgjysgkvvegkvrztfytnffb.cg gshinmxvtsmxeesikaeciwhyqscvtfbcxjklti.sid.afterthehunttaxidermy.com/
If you actually saw a URL that looked like the one above you should be immediately suspicious that it's part of an attempt at phishing.
But in actuality of course most people don't see the URL above, they see the HTML facade that's created for the email or webpage, and the above is just what's linked to the HTML display. But wait, you're thinking most browsers will show you where the HTML actually links to, and I'm smart enough to check that out (either in the bubble that shows up in the browser or the full link in the status bar at the bottom of the page).
But what's interesting about a URL like the one above is that it's so long that the entire URL won't display in most cases, so you only see the front part of the URL in your bubble or status bar. And that's the most likely explanation behind why the hacker created the URL. If you're not careful to check out the entire URL, you'll only see the front, and it may be enough to convince some people it's a legitimate link.
So be careful, and check the full URL of where you're going on the web, or at the very least make sure you're browsing through a Secure Web Gateway or proxy device that's configured to block phishing sites.
Tuesday, November 2, 2010
Malware hiding in plain sight
It used to be that malware was hosted on the domains that were typically hidden from the average user, hosted in other countries. For example, for a long time malware was most prevalent on ".cm" and ".cn" domains (Cameroon and China respectively). A new report from McAfee shows that malware is now fully entrenched in the ".com" domain. In their latest study ".com" took over ".cm" to be the top domain hosting malware. 31.3% of all sites hosted on a ".com" domain are considered risky. The ".info" domain came in second with 30.7% sites rated risky. ".vn" (Vietnam) came in third at 29.4% and ".cm" fell to fourth to 22.2%.
This new study just confirms what we already know. Hackers and providers of malware are just getting bolder, and that there's more threats out there. It's more important than ever now to make sure your organization is protected when browsing the web using an up to date proxy or secure web gateway.
This new study just confirms what we already know. Hackers and providers of malware are just getting bolder, and that there's more threats out there. It's more important than ever now to make sure your organization is protected when browsing the web using an up to date proxy or secure web gateway.
Monday, November 1, 2010
Appliance, Cloud, or Software
The age old question of whether to buy an appliance or build out hardware yourself and buy software to run on your own general purpose operating system, has been getting serious competition from the cloud, or SaaS (Software as a Service). IT admins now have 3 choices when selecting how to implement web security for their organization. The question is how do you choose which is right for your organization. The key here is that the right answer isn't the same for everyone.
There's an obvious difference between the previous choices of appliance or build your own versus a cloud solution, and that's based in the accounting, which may not be a key criteria for an IT admin, but is certainly a consideration for your finance group. An appliance or build your own has capex ramifications, and of course a cloud solution is limited to opex costs. If your finance arm rules your expenditures you may not get a choice when it's time to upgrade your proxy or secure web gateway.
But for those of you that do have a choice, it may have to do with how much security expertise you have on hand, how much control you need over your maintenance windows, and how many of your users are remote and travel extensively. Each of these will affect which solution you choose, and may even cause you to consider a hybrid of two solutions. If you happen to have extensive expertise, build your own may be the way to go, especially if you need an extremely custom solution.
For those that need ease of use, and quick deployments, an appliance or cloud makes more sense. Those that need control of their maintenance windows should of course avoid a cloud where they will be bound by the service providers maintenance windows. And those with lots of remote users or users who travel extensively, may want the cloud solution to cover those users when they aren't behind the proxy in the data center. And when you have a mix of these requirements you may want to have more than one solution in place. For example, you may want an appliance in your data center and a cloud solution for your remote and traveling users. In the end, it may turn out for most organizations a hybrid solution makes the most sense.
There's an obvious difference between the previous choices of appliance or build your own versus a cloud solution, and that's based in the accounting, which may not be a key criteria for an IT admin, but is certainly a consideration for your finance group. An appliance or build your own has capex ramifications, and of course a cloud solution is limited to opex costs. If your finance arm rules your expenditures you may not get a choice when it's time to upgrade your proxy or secure web gateway.
But for those of you that do have a choice, it may have to do with how much security expertise you have on hand, how much control you need over your maintenance windows, and how many of your users are remote and travel extensively. Each of these will affect which solution you choose, and may even cause you to consider a hybrid of two solutions. If you happen to have extensive expertise, build your own may be the way to go, especially if you need an extremely custom solution.
For those that need ease of use, and quick deployments, an appliance or cloud makes more sense. Those that need control of their maintenance windows should of course avoid a cloud where they will be bound by the service providers maintenance windows. And those with lots of remote users or users who travel extensively, may want the cloud solution to cover those users when they aren't behind the proxy in the data center. And when you have a mix of these requirements you may want to have more than one solution in place. For example, you may want an appliance in your data center and a cloud solution for your remote and traveling users. In the end, it may turn out for most organizations a hybrid solution makes the most sense.
Subscribe to:
Posts (Atom)