Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.

Showing posts with label anonymous proxy. Show all posts
Showing posts with label anonymous proxy. Show all posts

Thursday, October 1, 2009

Who makes anonymous proxies and why?

We've talked about anonymous proxies on this blog in the past, and recently I came across an article that discussed why someone would want to host an anonymous proxy. I've attached the link above and included some of the relevant information below:

Anonymous proxies require a lot of bandwidth to host. This bandwidth costs money, sometimes quite a lot. So who is hosting these proxies, and who is footing the bill? A few proxies are hosted by technically-adept students, bypassing their school filters, and limiting the use to a select group of their peers. Frequently these types of proxy are hosted on a home broadband connection, but with a handful of users, that’s no problem. These are the only truly ‘free’ forms of proxy and they can also be pretty tricky to block – URL list-based filters will have difficult time trying to catch them!

Public web proxies on the other hand (the most common type) can eat their way through many gigabits of bandwidth. The cost of this is usually offset by placing pay per click adverts on the proxy page. Revenue is miniscule, but with many hits, it all adds up. Of course, the proxy owners have to advertise too – top proxy lists are one way of doing this, but sometimes legitimate ads are placed as well. Some software-based proxies charge a fee but the majority are free and don’t carry any ads. Since it is highly unlikely that the creators are magnanimously footing the hosting bills, these proxy services will undoubtedly be selling on browsing habits, injecting ads or unwanted text, and even pushing malware.

Many students who use anonymous proxies are also unaware of the risks to their own personal security and identity. Malicious proxy servers do exist and are capable of recording everything sent to the proxy, including unencrypted logins and passwords. Although some proxy networks claim to only use ‘safe’ servers, due to the ‘anonymous’ nature of these tools, proxy server safety is impossible to police. Students should be educated to understand that whenever they use a proxy, they risk someone “in the middle” reading their data.

Other tips to prevent proxy abuse:
•Educate teachers to recognise illicit surfing or proxy abuse and report it to the IT department
•Educate students about the danger of using proxies.
•Allow slightly more lenient filtering outside of core hours
•Make sure your AUP covers anonymous proxying and that both students and teachers are familiar with its content. Make it clear that proxy abuse can be tracked to individuals.

Tuesday, April 21, 2009

US Mulls Tougher Penalties For Criminal Use Of Proxy Servers

Many IT administrators already know that our end-users attempt to use anonymous proxy servers to bypass the organizations' proxy web gateway. They do it to either hide their activities or get around the organizations use policies on what's acceptable to visit on the web.

Now, there's even more incentive for IT administrators to make sure their end-users aren't using anonymous proxies to surf the web. Whether knowingly or unknowingly if an end-user uses an anonymous proxy to commit a crime, they could find themselves behind bars for a longer time period.

From redorbit.com:

The U.S. Sentencing Commission is set to hold a crucial vote on Wednesday regarding new federal sentencing guidelines that would classify the use of proxy servers as an indication of “sophistication.” Those facing such charges would face prison sentences about 25 percent longer than those called for under current sentencing guidelines. Depending on the crime, convicted criminals now face years or even decades longer behind bars,


Digital rights advocates are against these longer convictions, claiming "new guidelines might lead to unreasonably harsh sentences for technology neophytes who were unaware they were using proxies, or were merely engaging in a practice often encouraged as a safer way of surfing the Web".

If the commission votes in favor of the amendment, the change would go into effect Nov. 1 unless Congress takes the exceptional step of blocking it before then.

One other important item redorbit.com noted:

Criminals often use legitimate proxies that are misconfigured. Universities, corporations and home users who own such proxies are often unaware their bandwidth is being sucked up by cybercriminals trying to cover up their tracks.


These are two good reminders to make sure our proxy servers block access to anonymous proxies, and to make sure our proxies are configured correctly.

Wednesday, March 11, 2009

Detect and destroy web proxy servers

A new article on why anonymous proxies are bad was just released on the Search Security website. It also covers defense mechanisms against anonymous proxies.

The obvious reason why anonymous proxies are bad, is of course they allow end-users in an organization to bypass any existing web security that may be in place, and gives the end-user an opportunity to bring malware into the organization.

The article specifically points out something many of your users may forget about the web security you've put in place for them:

The products also protect an enterprise from content on legitimate sites that are unknowingly hosting malware via third-party ads by trying to block malware that may be dispersed via the adds.


The article goes on to say that an important part of blocking access to anonymous proxies is having visibility in your network. If you don't understand what's leaving your network, you'll never know when your network is being compromised. Visibility isn't just capturing packets, but understanding data on an application level as well. Somehow this sounded strangely like Blue Coat's recent Application Delivery Network vision we talked about recently in this blog as well. Other vendors seem to be joining this bandwagon as well, and I'm sure we'll see more on this topic in the year to come.

Wednesday, February 4, 2009

Security Players Take Aim at Anonymous Proxies

We've discussed anonymous proxies on this blog in the past so it's no surprise that the security vendors are taking a hard look at them as well.

Anonymous proxies are a threat to many organizations because they allow the end-user to bypass any security controls (such as proxies in the organization), and go directly to sites that may contain drive-by malware, viruses, and other threats (not to mention users that are trying to bypass HR or corporate policies on what sites are allowed). Your enterprise proxy should have some way to protect your users from using anonymous proxies. URL filtering is probably not enough by itself as new anonymous proxies are appearing daily, and it's a hard task to keep a list updated.

Make sure your protection uses some type of real-time detection for anonymous proxies, and you won't be regretting the fact that one of your users got to an anonymous proxy and some malicious website.

Friday, January 16, 2009

Anonymous Proxies Remain a Major Concern for IT Managers

There's little surprise in this new report showing that 64% of IT managers consider anonymous proxies as a security threat. There's also a large increase in the volume of anonymous proxies on the Internet, and traditional web filtering using URL databases seems ineffective at blocking access to these anonymous proxies.

The idea behind an anonymous proxy is that you can point your browser explicitly to an anonymous proxy, and it will let you bypass your corporate or enterprise proxy, which typically would be blocking you from social or recreational websites like youtube or myspace, and preventing you from downloading any malware or viruses. No wonder IT managers find anonymous proxies to be a security threat.

If traditional web filtering using URL databases is ineffective at blocking access, then what's a proxy administrator to do? The only truly effective way to block an anonymous proxy is real time rating of a web address. Without real time rating, anonymous proxies appear and disappear too quickly to make it on to a URL database. The proxy administrator just needs to make sure the real time rating system they use is effective at recognizing anonymous proxies, and that a category exists to create policy to block anonymous proxy access.

Thursday, November 20, 2008

I Need A Proxy, Everybody Wants A Proxy

Unfortunately the article linked above is referring to open proxies that most people use to get around the corporate or school proxy enforcing policy. Open proxies allow anyone pointing to them to get around the corporate policy. Many good security proxies maintain lists of these open proxies and prevent users from going to them. The tough part is of course making sure this list is up to date, as new open proxies get created every day.

The article above, though makes good points for the end-user on why you shouldn't use an open proxy. There are lots of inherent risks to your company or school and especially to your own workstation or laptop if you use an open proxy.

The article I referenced in yesterday's blog post made a good suggestion for system administrators to prevent the use of open proxies on the corporate network, which was making your corporate policy, a default "deny policy", and only allow specific websites through your corporate proxy. Unfortunately this is probably too severe for most organizations, which tend to have a default "allow policy", and then policy to deny specific site categories.

So if you're relying on your corporate proxies to prevent access to open proxies, and you have a default "allow policy", you need to make sure your URL database is not only up to date with their open proxy list, but you need to make sure they've got a method to determine when a new open proxy comes on-line and give a real-time rating to match the open proxy category. Many corporate proxies have this real-time capability today. Make sure yours does too.

Wednesday, March 26, 2008

Privacy and Proxy Avoidance

Today, the most common mention about proxies deals with either proxy avoidance (getting around that proxy at work or school), or using an anonymizing proxy to prevent leaving footprints on the web that could possibly be used for identification theft or other malicious intent.

Proxy avoidance is popular in both workplaces and schools where proxies have limited the web access of end-users. Proxy avoidance is a big headache for IT administrators trying to enforce corporate or school policy. The most common form of proxy avoidance is to use an open proxy on the internet to bypass the proxy in the local environment. Typically, the end-user just changes the setting in the browser to point to the open proxy IP address and port number, and in an insecure deployment, this allows them to surf freely without policy restrictions.

So how does an organization protect themselves from end-users that use proxy avoidance techniques? The first step is to make sure the proxy is capable of recognizing proxy avoidance techniques and can prevent end-users from getting to those sites. With open proxies coming on line daily, the URL list we talked about is really no solution for this problem. On the other hand a dynamic rating system, would be able to solve most of this problem as most of these open proxies, if you go directly to their IP address with a browser have a landing page describing how to use the open proxy. This would allow a dynamic rating system to pick up on new pages and automatically detect and rate new open proxies correctly in the "proxy avoidance" category. According to Blue Coat Systems, this is exactly what their ProxySG product's DRTR (Dynamic Real Time Rating) system does, and with the correct policy prevents end-users from getting to the open proxy.

In addition to open proxies there's less well known techniques for avoiding proxies that are used when there is malicious intent in mind. I'll save that for another post tomorrow.