After what seemed to be a continuing decrease in the amount of spam email and malicious spam email, M86 is reporting now a huge spike in the amount of malicious spam email since the beginning of August. The belief is that with the arrest of cyber-criminals and the take down of major botnets, the cyber-criminals are back in force trying to re-establish their bot networks.
This increase in malicious spam is a good reminder to IT administrators to keep vigilant with their security, whether it's email or web based security, as many emails rely on tricking users into filling out linked web pages or downloading malicious software from linked pages. Security should especially be of concern for your web proxy if you're only using URL database filtering today. In addition to that layer of security every web proxy should also do real time scanning of downloaded content using an anti-malware or anti-virus engine.
Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.
Wednesday, August 17, 2011
Monday, August 15, 2011
Thinking DLP? Think Proxy.
If you've got plans to implement DLP (Data Leakage Protection) into your organizations network, either for regulation or corporate compliance around confidential data protection, you're probably also looking at your secure web gateway (aka web proxy).
Why is that? Because most traffic that's likely to leave your organization today is going out over the web. Most DLP vendors prefer to not be directly inline in the network as a single point of failure, nor are their boxes or software designed to be inline as a network traffic device.
That's where the web proxy or secure web gateway comes in. The web gateway can decided when to send traffic to a DLP device over a standard protocol like ICAP and wait for a response from the DLP server before giving a response back to the end-user. Any major DLP vendor today will point you to a web proxy as the integration point for network based DLP.
The key here is to make sure your secure web gateway is capable of ICAP for integration, and generally capable of at least two ICAP server support (one for uploads and one for download scanning). The upload ICAP server is the one used for DLP, and the download one is used for malicious threat scanning (anti-malware).
Why is that? Because most traffic that's likely to leave your organization today is going out over the web. Most DLP vendors prefer to not be directly inline in the network as a single point of failure, nor are their boxes or software designed to be inline as a network traffic device.
That's where the web proxy or secure web gateway comes in. The web gateway can decided when to send traffic to a DLP device over a standard protocol like ICAP and wait for a response from the DLP server before giving a response back to the end-user. Any major DLP vendor today will point you to a web proxy as the integration point for network based DLP.
The key here is to make sure your secure web gateway is capable of ICAP for integration, and generally capable of at least two ICAP server support (one for uploads and one for download scanning). The upload ICAP server is the one used for DLP, and the download one is used for malicious threat scanning (anti-malware).
Thursday, August 11, 2011
Web Application Controls
I wrote an article a few months ago talking about the new feature called "Web 2.0 controls". This feature has been firming up of late, and seems to be coalescing around the term "Web Application Controls". Each vendor does have a slightly different take on it, some focusing more on social networking, others being more broad based and covering a number of applications. Even those without real controls, are claiming "web application control" capability.
That being said, it's important to find out what a vendor means when they say "web application control". For some it just means blocking a web site based on its category. That alone probably isn't sufficient in today's malware laden web world. Really, the secure web gateway or web proxy needs to be able to control actions with web sites (applications). For example, does the web proxy allow the user to view the website, but prevent them from posting information to that update, restrict them from uploading a photo, a video or other documents? Is there any granular control over the types of information or document type that can or cannot be uploaded? Can a user be prevented from using a chat function within a page or an email function within a page?
Those are the important controls and the ones needed to customize a policy to adhere to an organization's compliance rules. It may be easy to say create a read-only Facebook policy, but it won't apply across the board. Marketing folks may need to add the ability to post to the company's Facebook site, but maybe you don't let them chat on Facebook. The CEO may be the only one allowed to do anything of Facebook, etc.
The key takeaway here? Make sure you know what your web proxy can do and make sure it fits your needs around "web application control".
That being said, it's important to find out what a vendor means when they say "web application control". For some it just means blocking a web site based on its category. That alone probably isn't sufficient in today's malware laden web world. Really, the secure web gateway or web proxy needs to be able to control actions with web sites (applications). For example, does the web proxy allow the user to view the website, but prevent them from posting information to that update, restrict them from uploading a photo, a video or other documents? Is there any granular control over the types of information or document type that can or cannot be uploaded? Can a user be prevented from using a chat function within a page or an email function within a page?
Those are the important controls and the ones needed to customize a policy to adhere to an organization's compliance rules. It may be easy to say create a read-only Facebook policy, but it won't apply across the board. Marketing folks may need to add the ability to post to the company's Facebook site, but maybe you don't let them chat on Facebook. The CEO may be the only one allowed to do anything of Facebook, etc.
The key takeaway here? Make sure you know what your web proxy can do and make sure it fits your needs around "web application control".
Tuesday, August 9, 2011
Sophos AV Critically Flawed?
The big news out of Black Hat last week in Las Vegas was a session that described Sophos AV as being critically flawed.
A Google security engineer, Tavis Ormandy, released his findings in a paper following his presentation at Black Hat. Ormandy said his analysis found that Sophos software uses weak or outdated cryptography in the way it builds and matches virus signatures, relies on obfuscation for security too often, and fails to comprehend certain exploitation techniques, among other problems.
From Ormandy:
Sophos has promised fixes in an upcoming release. When asked if these problems existed in other AV vendors, the suggestion was that it's likely as most of these programs are not that fundamentally different.
It's a troubling concern and hopefully one that's addressed by all AV vendors now that there's some light on the issue.
A Google security engineer, Tavis Ormandy, released his findings in a paper following his presentation at Black Hat. Ormandy said his analysis found that Sophos software uses weak or outdated cryptography in the way it builds and matches virus signatures, relies on obfuscation for security too often, and fails to comprehend certain exploitation techniques, among other problems.
From Ormandy:
“My intent for this project was to provide the missing technical speficiations for Sophos Antivirus in order to help those evaluating antivirus do so thoroughly,” Ormandy said. “They’ll be able to make informed decisions about whether this product makes sense in the context in which they want to deploy it.”
Sophos has promised fixes in an upcoming release. When asked if these problems existed in other AV vendors, the suggestion was that it's likely as most of these programs are not that fundamentally different.
It's a troubling concern and hopefully one that's addressed by all AV vendors now that there's some light on the issue.
Monday, August 8, 2011
Malware affects 6 Million Websites
eWeek is reporting a new malware outbreak that affects 6 million web pages. Should we be scared? As an IT admin, should there be concern this is more pages than my web proxy or secure web gateway can rate?
The simple answer is no, and there's a good reason to it as well. While there might be 6 million web pages that have been compromised with an iFrame injection containing javascript, this javascript actually leads to only 8 different Ukraine based websites that actually contain the malware. So if you've got a web proxy or secure web gateway that can block embedded URLs (this is key so you can still get to the content on those 6 million web pages), and can rate those 8 pages as malware, you can be pretty confident that you're protected. In fact most malware attacks on the web are pretty similar to this one. While there may be 8 bad sites, there's many more (in this case 6 million) websites that lead you to those 8 bad sites. So while you can't possibly block all 6 million web sites, you can block the 8 bad ones, and prevent users from loading bad embedded URLs on a page.
Just make sure your web proxy or secure web gateway can do this to, and you won't have to worry about the hype, just the reality.
The simple answer is no, and there's a good reason to it as well. While there might be 6 million web pages that have been compromised with an iFrame injection containing javascript, this javascript actually leads to only 8 different Ukraine based websites that actually contain the malware. So if you've got a web proxy or secure web gateway that can block embedded URLs (this is key so you can still get to the content on those 6 million web pages), and can rate those 8 pages as malware, you can be pretty confident that you're protected. In fact most malware attacks on the web are pretty similar to this one. While there may be 8 bad sites, there's many more (in this case 6 million) websites that lead you to those 8 bad sites. So while you can't possibly block all 6 million web sites, you can block the 8 bad ones, and prevent users from loading bad embedded URLs on a page.
Just make sure your web proxy or secure web gateway can do this to, and you won't have to worry about the hype, just the reality.
Friday, August 5, 2011
Cybercrime costs up 56% in 2011
According to a study by Ponemon and sponsored by Arcsight, the cost of battling cybercrime went up by 56% in 2011 for the organizations they interviewed. For the 50 organizations they looked at, the cost averaged 8.4 million dollars.
This new study is a good reminder why security, especially web security should be at the top of your list for IT dollars, if it isn't already. The web remains the primary vehicle for cybercrime, and protecting your end-users regardless of whether they are behind the company firewall or remote and on a hotel wifi should be one of the largest IT concerns today.
When selecting your web security solution make sure they can answer the tough questions about how they protect you from malware and how they protect your remote users as well as your local ones.
This new study is a good reminder why security, especially web security should be at the top of your list for IT dollars, if it isn't already. The web remains the primary vehicle for cybercrime, and protecting your end-users regardless of whether they are behind the company firewall or remote and on a hotel wifi should be one of the largest IT concerns today.
When selecting your web security solution make sure they can answer the tough questions about how they protect you from malware and how they protect your remote users as well as your local ones.
Monday, August 1, 2011
Video Usage
It's old news, but Cisco has estimated that 90% of all internet traffic will be consumer based video by 2013. That of course instantly translates to businesses as well, whether or not the IT administrator realizes it or not. In fact what most network assessment companies find, is that most IT admins really have little idea of the types of traffic that's running on their network. For example, do you know what percentage of your traffic is peer-to-peer, video usage, or social networking?
PacketShaper users do know, but that's because it's one product that's commonly used in network assessments. But if you're not a PacketShaper owner, what can you do? One thing you can do is to make sure your web proxy or secure web gateway is reporting on video usage and social networking usage. Make sure you know who the top video watcher is on your network, and what percentage of your web traffic goes to video sites.
For social networking, you want to know the same things, but you probably also want controls to either create a "read-only" social networking policy, or at least examine the content that's going to social networking sites. These are features your web proxy or secure web gateway should be able to provide you today.
PacketShaper users do know, but that's because it's one product that's commonly used in network assessments. But if you're not a PacketShaper owner, what can you do? One thing you can do is to make sure your web proxy or secure web gateway is reporting on video usage and social networking usage. Make sure you know who the top video watcher is on your network, and what percentage of your web traffic goes to video sites.
For social networking, you want to know the same things, but you probably also want controls to either create a "read-only" social networking policy, or at least examine the content that's going to social networking sites. These are features your web proxy or secure web gateway should be able to provide you today.
Subscribe to:
Posts (Atom)