Network World recently published an article on web usage patterns in the U.S. and in Europe. Not surprisingly the peak traffic on the Internet in each of these areas is not during working hours. What was surprising is that traffic peaks around 11 PM in the U.S. and much earlier at 7 PM in Europe.
The two driving factors in all this Internet usage? Games and video. For games, it's specifically World of Warcraft and Steam, and video traffic is primarily from youtube and adult sites. As Network World says "So, in a sense you could say that what’s keeping Internet users up at night is sex and violence."
Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.
Tuesday, October 20, 2009
Monday, October 19, 2009
Kaspersky CEO Calls for End to Internet Anonymity
In an interview with ZDNet this week, Eugene Kaspersky, the CEO of Kaspersky, Russia's No. 1 anti-virus package has said that the internet's biggest security vulnerability is anonymity, calling for mandatory internet passports that would work much like driver licenses do in the offline world. Kaspersky also proposed the formation of an internet police body that would require users everywhere to be uniquely identified.
From an article in the The Register on Kaspersky's controversial comments:
This of course leaves the question, how much control are we willing to live with in order to stop cyber crime. It's not an easy answer, and the solution probably lies somewhere in the middle of the spectrum.
From an article in the The Register on Kaspersky's controversial comments:
"Everyone should and must have an identification, or internet passport," he was quoted as saying. "The internet was designed not for public use, but for American scientists and the US military. Then it was introduced to the public and it was wrong...to introduce it in the same way."
Kaspersky, whose comments are raising the eyebrows of some civil liberties advocates, went on to say such a system shouldn't be voluntary.
"I'd like to change the design of the internet by introducing regulation - internet passports, internet police and international agreement - about following internet standards," he continued. "And if some countries don't agree with or don't pay attention to the agreement, just cut them off."
He rejected the notion that internet protocol numbers were sufficient for tracking a user, arguing they are too easy to come by.
"You're not sure who exactly has the connection," he explained. "Even if the IP address is traced to an internet cafe, they will not know who the customer or person is behind the attacks. Think about cars - you have plates on cars, but you also have driver licenses."
Kaspersky admitted such a system would be hard to put in place because of the cost and difficulty of reaching international agreements. But remarkably, his interview transcript spends no time contemplating the inevitable downsides that would come in a world where internet anonymity is a thing of the past.
"You could make the same argument about the offline world," said Matt Zimmerman, a senior staff attorney at the Electronic Frontier Foundation. "You know, every purchase you make should be tracked, we should ban the use of cash, we should put cameras up everywhere because in that massive data collection something might be collected to help someone. But we think privacy is an important enough countervailing value that we should prevent that."
In Kaspersky's world, services such as Psiphon and The Onion Router (Tor) - which are legitimately used by Chinese dissidents and Google users alike to shield personally identifiable information - would no longer be legal. Or at least they'd have to be redesigned from the ground up to give police the ability to surveil them. That's not the kind of world many law-abiding citizens would feel comfortable inhabiting.
And aside from the disturbing big-brother scenario, there are the problematic logistics of requiring every internet user anywhere in the world to connect using an internationally approved device that authenticates his unique identity. There's no telling how many innovations might be squashed under a system like that.
No doubt, the cybercriminals that Kaspersky has valiantly fought for more than a decade are only getting better at finding ways to exploit weaknesses in internet technologies increasingly at the heart of the way we shop, socialize and work. But to paraphrase Benjamin Franklin, those who sacrifice net liberty for incremental increases in security no doubt will get neither.
This of course leaves the question, how much control are we willing to live with in order to stop cyber crime. It's not an easy answer, and the solution probably lies somewhere in the middle of the spectrum.
Thursday, October 15, 2009
Researchers advise cyber self defense in the cloud
Network World reported this week that Security researchers are warning that Web-based applications are increasing the risk of identity theft or losing personal data more than ever before. The best defense against data theft, malware and viruses in the cloud is self defense, researchers at the Hack In The Box (HITB) security conference said. The difficulty of course is in getting people to change how they use the Internet, such as what personal data they make public.
From Network World:
Articles like these from Network World remind us why we have proxies in place in our networks. While they won't prevent all problems and threats, they are the first step in protecting web users from the new threats in the "Wild Wild Web"
From Network World:
People put a lot of personal information on the Web, and that can be used for an attacker's financial gain. From social-networking sites such as MySpace and Facebook to the mini-blogging service Twitter and other blog sites like Wordpress, people are putting photos, resumes, personal diaries and other information in the cloud. Some people don't even bother to read the fine print in agreements that allow them onto a site, even though some agreements clearly state that anything posted becomes the property of the site itself.
The loss of personal data by Sidekick smartphone users over the weekend, including contacts, calendar entries, photographs and other personal information, serves as another example of the potential pitfalls of trusting the Cloud. Danger, the Microsoft subsidiary that stores Sidekick data, said a service disruption almost certainly means user data has been lost for good.
Access to personal data on the cloud from just about anywhere on a variety of devices, from smartphones and laptops to home PCs, shows another major vulnerability because other people may be able to find that data, too.
"As an attacker, you should be licking your lips," said Haroon Meer, a researcher at Sensepost, a South African security company that has focused on Web applications for the past six years. "If all data is accessible from anywhere, then the perimeter disappears. It makes hacking like hacking in the movies."
A person who wants to steal personal information is usually looking for financial gain, Meer said, and every bit of data they can find leads them one step closer to your online bank, credit card or brokerage accounts.
First, they might find your name. Next, they discover your job and a small profile of you online that offers further background information such as what school you graduated from and where you were born. They keep digging until they have a detailed account of you, complete with your date of birth and mother's maiden name for those pesky security questions, and perhaps some family photos for good measure. With enough data they could make false identification cards and take out loans under your name.
Identity theft could also be an inside job. Employees at big companies that host e-mail services have physical access to e-mail accounts. "How do you know nobody's reading it? Do you keep confirmation e-mails and passwords there? You shouldn't," said Meer. "In the cloud, people are trusting their information to systems they have no control over."
Browser makers can play a role in making the cloud safer for people, but their effectiveness is limited by user habits. A browser, for example, may scan a download for viruses, but it still gives the user the choice of whether or not to download. Most security functions on a browser are a choice.
Lucas Adamski, security underlord (that's really what his business card says) at Mozilla, maker of the popular Firefox browser, offered several bits of cyber self defense advice for users, starting with the admonition that people rely on firewalls and anti-virus programs too much.
"You can't buy security in a box," he said. "The way to be as secure as possible is about user behavior."
There is a lot of good built-in security already installed in browsers, he said. If you get a warning not to go to a site, don't go to it. When you do visit a site, make sure it's the right one. Are the images and logos right? Is the URL correct? Check before you proceed with filling in your username and password, he counseled.
Software updates are vital. "Make sure you have the most up-to-date version of whatever software you use," he said. Updates almost always patch security holes. Key software programs such as Adobe Systems' Flash Player and Reader are particularly important to keep updated because they're used on so many computers and are prime targets for hackers.
He also suggested creating a virtual machine on your computer using VMWare as a security measure.
"It's really hard to get people to change their browsing habits," he said. People want to surf the Web fast, visit their favorite sites and download whatever they want without thinking too much about security. "Educate them, move them along, but don't expect them to become security experts."
Internet browser makers take great care in building as much security as possible into their products and putting them through rigorous testing.
The security team for Google's Chrome browser, for example, will take the first crack at any major update to the software, hacking away to find vulnerabilities or ways to improve security, said Chris Evans, an information security engineer at Google.
After the Chrome security team takes a whack at the software and it is reworked to fix the holes they found, other security teams at Google will have a go at the product to see what trouble they can cause. Finally, the software is released in beta form, and private security researchers and others can hack away. Any problems are fixed before the final release goes out and then the Chrome team stands ready to make new patches for any other security issues that crop up.
Despite all the testing, browser makers are only one part of the security solution because they have no control over Web software or user browsing behavior.
The cloud is the Wild West: hackers and malware makers abound, phishers seek passwords and users do whatever they want to, recklessly surfing and downloading potentially dangerous content as judged by security researchers.
Companies developing Cloud applications and services will need to do more for Web security. Amazon.com with its Web Services and Google as it moves forward with initiatives, such as Google Docs, that attempt to draw people to Web applications and away from computer applications will need to work more closely with security researchers, Meer said.
And Google's work on the security in the Chrome browser highlights the reason why: Computer applications such as Chrome face intense scrutiny by security researchers throughout the Web, while Web applications do not.
"Reverse engineering keeps [big software companies] honest," said Meer. "If they hide something in the software code, sooner or later someone finds it. With Cloud services, you just don't know because we simply cannot verify it."
Cloud applications are built by one company, and nobody is looking at the code or how safe it is, said Meer. Applications for computers are different. They can be ripped apart by security experts then put back together stronger so there are no security holes, he said.
"Trust but verify," said Meer. "Just because a guy does no evil today, we cannot trust that they will do no evil tomorrow because we simply cannot verify it."
Articles like these from Network World remind us why we have proxies in place in our networks. While they won't prevent all problems and threats, they are the first step in protecting web users from the new threats in the "Wild Wild Web"
Wednesday, October 14, 2009
From Sidekick to Gmail: A short history of cloud computing outages
Network World covered the recent Microsoft-T-Mobile-Sidekick data loss mess recently, and reminded us that it wasn't the first time data was lost in the cloud. While cloud computing remains the latest buzz word, this latest event is definitely enough to give pause to any IT administrator considering a move to the cloud.
Here's Network World's short history of cloud computing SNAFUs:
So the question remains as to whether cloud computing is mature enough for the enterprise market.
Here's Network World's short history of cloud computing SNAFUs:
Microsoft Danger outage: Contacts, calendar entries, photographs and other personal information of T-Mobile Sidekick users looks to be lost for good following a service disruption at Sidekick provider Danger, a Microsoft subsidiary. The amount of data and number of users affected wasn't disclosed by Microsoft or T-Mobile, but Sidekick support forums were buzzing with pleas from users looking for tips on how to restore their devices or get their data back.
Google Gmail fails…again: When Google's Gmail faltered on Sept. 24, it wasn't down for more than a couple of hours, but it was the second outage during the month and the latest in a disturbing string of outages for Google's cloud-based offerings, including Google search, Google News and Google Apps over the past 18 months. Various explanations have been served up by the vendor, from routing errors to server maintenance issues. Some have come to Google's defense, saying that even though the company has had its share of outages, we are talking about mainly free services (you get what you pay for, in other words).
Twitter goes down…and yes, that's news: While Twitter had been keeping its Fail Whale in hiding more often than not, a big Twitter outage that lasted throughout the morning and into early afternoon in early August had social networking types fuming. A denial-of-service attack was blamed for the problem.
eBay's PayPal crashes: The PayPal online payments system failed a couple of times in August, leaving millions of customers unable to complete transactions. A network hardware issue was fingered as the culprit for the outage, which lasted for between 1 and 4.5 hours, depending on how you look at it. It cost PayPal millions of dollars in lost business; it's unclear how much it cost merchants.
Rackspace pays up: Rackspace was forced to pay out between $2.5 million and $3.5 million in service credits to customers in the wake of a power outage that hit its Dallas data center in late June. Rackspace, which offers a variety of hosting and cloud services for enterprise customers, suffered power generator failures on June 29 that caused customer servers to go down for part of the day. More disruptions followed and Rackspace kept customers up to date via its blog.
Windows Azure test release goes down: Early adopters of Microsoft's cloud-computing network Windows Azure suffered an overnight outage over a weekend in mid-March during which their applications being hosted on the network weren't available. This was only a test release of Azure, so observers noted that this obviously wasn't as big a deal as a production service outage. Separately, Microsoft also suffered a Hotmail messaging system outage in March.
Salesforce.com kicks off the Year of the Cloud Outage: As CIO.com's Thomas Wailgum reported in January, Salesforce.com suffered a service disruption for about an hour on Jan. 6 due to a core network device failing because of memory allocation errors.
Amazon S3 storage service knocked out: We actually have to go back to summer of 2008 to find coverage of the last major Amazon S3 cloud network outage, which lasted for 7 to 8 hours and followed another outage earlier last year caused by too many authentication requests.
So the question remains as to whether cloud computing is mature enough for the enterprise market.
Tuesday, October 13, 2009
Barracuda snags Purewire in Web security play
It was announced today that security appliance maker Barracuda Networks has acquired Purewire, a Web security-as-a-service provider. The acquisition gives Barracuda the SaaS offering. Barracuda also reported that the deal provides some additions to its security researcher and threat detection capabilities.
Barracuda offers lower end e-mail, Internet, Web, and instant messaging protection in appliance form factors, much of it based on open-source software. Purewire launched its Trust Web reputation service earlier this year.
Barracuda offers lower end e-mail, Internet, Web, and instant messaging protection in appliance form factors, much of it based on open-source software. Purewire launched its Trust Web reputation service earlier this year.
Monday, October 12, 2009
Cisco shines light on dark corners of the Web
Cisco announced last week the launch of software that shines light on potentially troublesome websites hidden in what the US computer security firm dubbed the "Dark Web." The idea behind Cisco IronPort Web Usage Controls is to identify content that has escaped detection by business IT managers and security applications because of its stealthy nature on the Internet. Cisco claims it can identify as much as 90% of this traffic.
The Dark Web (as Cisco calls it) has been formed largely as a result of tidal wave of Web pages triggered by Web 2.0 trends in user-generated content such as blogging and social networking.
According to the AFP:
Cisco's announcement is a good reminder that URL lists, while important should never be the only source of protection in the web proxy. In today's Web 2.0 world, you absolutely need some type of real time rating system to find "dark web" pages and protect your users from this content. The good news here, is there are proxy vendors who already provide this type of service, including now, Cisco.
The Dark Web (as Cisco calls it) has been formed largely as a result of tidal wave of Web pages triggered by Web 2.0 trends in user-generated content such as blogging and social networking.
According to the AFP:
Only 20 percent of the more than 45 billion websites in the world are reportedly categorized effectively enough to be used by filtering programs, leaving 80 percent of the Web in the dark.
Tests of Ironport Web Usage Controls reportedly identified 50 percent more off-limits websites than did previous-generation filtering software relying on website address lists.
"We are doing pretty well; there is room for improvement," Kennedy said. "You have to balance between catch rate and false-positive rate."
False positives are times when filtering software blocks access to websites that don't deserve to be off-limits by company standards.
Cisco's announcement is a good reminder that URL lists, while important should never be the only source of protection in the web proxy. In today's Web 2.0 world, you absolutely need some type of real time rating system to find "dark web" pages and protect your users from this content. The good news here, is there are proxy vendors who already provide this type of service, including now, Cisco.
Thursday, October 8, 2009
Hotmail passwords heisted by hackers
Sophos blogger Chester Wisniewski noted on his blog this week that over 10,000 usernames and passwords were publicly disclosed from users of hotmail.com, msn.com, and live.com email services. All of the accounts initially posted begin with the letter a or b, suggesting that this may be the tip of the iceberg.
From Sophos:
And of course there's the bit of security the IT admin can make sure is up to date, and that's the proxy and it's URL database, real-time rating system and malware scanning software.
From Sophos:
BBC News contacted Microsoft and was able to confirm the validity of the accounts that were released.
Microsoft has released a public statement saying their investigation determined the IDs were stolen through a phishing attack. Part of their statement said "As part of that investigation, we determined that this was not a breach of internal Microsoft data and initiated our standard process of working to help customers regain control of their accounts."
This raises the question of how many people fell victim to this attack, and is it still underway? I may not be able to answer these questions, but with over 10,000 accounts exposed from the first 2 letters of the alphabet the scope of this fraud could be very large. Users who have followed Graham Cluley's (from Sophos) advice about using separate passwords for each site they use will minimize their exposure to just Microsoft's online services.
Another question is what Microsoft means by "due to a phishing scheme". Was this another view your blocked MSN friends website, or was it a direct phish of an impostor Hotmail login page? SophosLabs blogged about these attacks early in September, and it seems likely this may be related.
Computer World reported that this may be a similar attack to the one that disclosed private emails of vice presidential candidate Sarah Palin during last years U.S. election. I find this to be highly improbable. To compromise 10,000 or more accounts in an apparently serial manner would not be practical by guessing security questions. It is far more likely an that users were duped into providing their passwords to a fraudulent website posing as Microsoft or an affiliate.
My recommendation for users of Microsoft's online services is to change your passwords immediately. You are better to be safe than sorry, and password rotation is something we are often too lazy to do. This is a great time to log into those Facebook, Twitter, Gmail, and Yahoo! accounts and do likewise as a simple best practice to prevent yourself from becoming a victim of habit.
Password rotation is not fun, but it is a great preventative to these types of disclosures.
If you are an IT administrator this would be a great time to remind your users to change their Microsoft Live!, MSN, and Hotmail passwords. Additionally, as always, be sure your anti-spam protection is current and educate your users about phishing and clicking links in email. Sophos Web Appliance customers have been protected against the MSN friends scam for some time now, however technology and education are always the best solution.
And of course there's the bit of security the IT admin can make sure is up to date, and that's the proxy and it's URL database, real-time rating system and malware scanning software.
Subscribe to:
Posts (Atom)