Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.
Thursday, April 10, 2008
Bandwidth Management?
You may be wondering what Bandwidth Management has to do with Proxies. At this week's RSA Conference, Blue Coat Systems was showing off a demonstration in their booth where their ProxySG allowed all text to be displayed immediately from sites categorized as Sporting, but bandwidth limited all the graphics on the page to only 1kbps. The obvious benefit here of course is that you get all the textual content, and prevent the graphics on the page from using up all the internet bandwidth available, so that actual job-related use of the internet can continue.
Tuesday, April 8, 2008
RSA Conference, San Francisco
This week brings the RSA Security Conference to San Francisco. It's one of the largest security shows for networking in the industry, and the exhibit hall opened up last night. As is common with all conferences lately, many of the talks are available on podcast, which means that if your organization didn't send anyone to RSA, you may have lots of listeners on your local area network, eating up the bandwidth to the internet.
The exhibit hall of course is filled with vendors that can help you solve that problem from blocking that content to allowing it, and only allowing one download to happen from the internet, caching that content, and delivering locally when requested by each additional requester. This year, RSA is touting 400 exhibitors, 240 sessions and a keynote by Michael Chertoff.
If you get the chance stop by and visit, even if you can't afford the conference pass, the exhibits are sure to provide lots of learning opportunities.
The exhibit hall of course is filled with vendors that can help you solve that problem from blocking that content to allowing it, and only allowing one download to happen from the internet, caching that content, and delivering locally when requested by each additional requester. This year, RSA is touting 400 exhibitors, 240 sessions and a keynote by Michael Chertoff.
If you get the chance stop by and visit, even if you can't afford the conference pass, the exhibits are sure to provide lots of learning opportunities.
Thursday, April 3, 2008
In the News: Risks of Anonymous Proxies
A recent article (linked above) on the risks of anonymous proxies (which have become a popular way of avoiding the corporate or school proxy), indicated that at least 5% or more of anonymous proxies contained some kind of malware. Users accessing these anonymous proxies, put their organizations at risk for drive-by spyware, viruses and trojans. They can also possibly expose your users to identity theft and your organization to information theft.
Your end-user may find access to barred sites by using an anonymous proxy, violating corporate or policy or even regulatory requirements. The article describes methods to combat anonymous proxies and recommends such features as SSL interception in a proxy, and advanced proxies that recognize anonymous proxy sites. In case you don't think you're vulnerable, set up a test PC in your corporate network and point the browser at a few anonymous proxies, you may be surprised at the result.
Your end-user may find access to barred sites by using an anonymous proxy, violating corporate or policy or even regulatory requirements. The article describes methods to combat anonymous proxies and recommends such features as SSL interception in a proxy, and advanced proxies that recognize anonymous proxy sites. In case you don't think you're vulnerable, set up a test PC in your corporate network and point the browser at a few anonymous proxies, you may be surprised at the result.
Wednesday, April 2, 2008
In the News: Web Attacks Won't Stop
According to this blog article from InfoWorld, the Web will continue to be a dangerous place to visit with even the best of sites compromised, and the threat being as simple as a "drive-by" meaning that just visiting a site could cause some malicious code to be implanted on your computer.
With well known sites with good reputations being victims themselves of bots, hackers and other malware being deposited on their sites, URL filtering alone won't solve the security problem.
While we focus on proxies in this blog, it's also important to remember that threats are beginning to enter the organization in other more unconventional means as this article reminds us. While the web may be the source of a lot of malware, physical devices are also a source of infection in computer networks. In 2007 there was a rash of digital picture frames that were shipped with the Trojan virus, and USB sticks (thumb drives) are vulnerable to this type of distribution of malware.
A good proxy remains important in keeping out the malware, but remember to be checking on the desktop as well.
With well known sites with good reputations being victims themselves of bots, hackers and other malware being deposited on their sites, URL filtering alone won't solve the security problem.
While we focus on proxies in this blog, it's also important to remember that threats are beginning to enter the organization in other more unconventional means as this article reminds us. While the web may be the source of a lot of malware, physical devices are also a source of infection in computer networks. In 2007 there was a rash of digital picture frames that were shipped with the Trojan virus, and USB sticks (thumb drives) are vulnerable to this type of distribution of malware.
A good proxy remains important in keeping out the malware, but remember to be checking on the desktop as well.
Tuesday, April 1, 2008
In the News: What Firewalls do and What Firewalls don't do
The linked article above has an interesting view point. Where we agree is that firewalls aren't sufficient to address all the security threats on the network. Where we disagree is how to address that shortcoming. The author discusses the use of UTM (Unified Threat Management) devices to address all the other threats out on the Internet. While in theory I like the idea, the problem I have with it is that it only works for the smaller organization. Any organization that has any volume of email and web usage will probably find any UTM device inadequate as the scanning necessary to address the myriad of threats tends to drive up CPU usage, and most UTM devices don't scale to the necessary levels for larger organizations.
Another and perhaps bigger problem with UTM devices is that attacks on organizations tend to focus on one protocol, a denial of service attack will be on HTTP, SMTP, or DNS, but not usually all of them at once. With a UTM device an attack on any of these will render all of them unusable. By separating the security devices associated with each protocol, when one is under attack, there's a good chance the other protocols remain available for use.
The final problem with UTM devices is having to rely on the technology that the UTM vendor has selected for the given protocol. This leaves the organization vulnerable if the best of breed technology wasn't selected by the UTM vendor. In this blog we focus on proxies, and I believe any organization should evaluate the proxy solutions available and decide which one is best for their needs. At the same time, find the best email solution for spam and viruses, and any other protection they think need (including ILP/DLP, etc.).
Find the proxy solution with all the security features you need and don't rely on the UTM vendor to do it for you.
Another and perhaps bigger problem with UTM devices is that attacks on organizations tend to focus on one protocol, a denial of service attack will be on HTTP, SMTP, or DNS, but not usually all of them at once. With a UTM device an attack on any of these will render all of them unusable. By separating the security devices associated with each protocol, when one is under attack, there's a good chance the other protocols remain available for use.
The final problem with UTM devices is having to rely on the technology that the UTM vendor has selected for the given protocol. This leaves the organization vulnerable if the best of breed technology wasn't selected by the UTM vendor. In this blog we focus on proxies, and I believe any organization should evaluate the proxy solutions available and decide which one is best for their needs. At the same time, find the best email solution for spam and viruses, and any other protection they think need (including ILP/DLP, etc.).
Find the proxy solution with all the security features you need and don't rely on the UTM vendor to do it for you.
Monday, March 31, 2008
In the News: Think you're protected? Think again!
There's a new study out regarding a government agency that had strict rules around network access. The study was done in conjunction with Panda Security. At least 13% of computers were infected with viruses, even though all had desktop anti-virus and anti-malware software installed and all access to the internet was through a secure proxy. An even higher percentage of computer (16%) were infected with some type of malware.
It just goes to show neither a proxy, nor desktop software alone are a complete defensive solution. The proxy is a necessary component of an overall security plan, and choosing a proxy with the most security defenses is key. As we've outlined in previous blog articles, look for a proxy that can detect obfuscated URLs, intercept SSL and analyze SSL content, and has a dynamic real-time method for categorizing websites.
It just goes to show neither a proxy, nor desktop software alone are a complete defensive solution. The proxy is a necessary component of an overall security plan, and choosing a proxy with the most security defenses is key. As we've outlined in previous blog articles, look for a proxy that can detect obfuscated URLs, intercept SSL and analyze SSL content, and has a dynamic real-time method for categorizing websites.
Thursday, March 27, 2008
Obfuscating the URL
Common techniques used by spammers seems to also cause grief for many proxies that scan URLs against URL database lists. Spammers would try to hide the actual URL in an email by using some standard features of URLs. In addition to domain names, URLs can contain usernames and passwords, IP addresses, and encoded IP addresses. All of these provide ways to create URL's that look like they are going to a site, but really are going somewhere else.
Simple proxies don't recognize anything other than a standard domain name. So many of the techniques in the linked article above will get past a URL filter. So if someone wanted to bypass a typical proxy they could obfuscate the URL they type in the browser and still get to sites that are deemed inappropriate based on policy or contain malicious content.
Many of the better proxies are aware of these techniques and will "translate" the URL before passing it through the URL filter to ensure the real URL gets filtered, and blocked or scanned if appropriate.
Be sure to include obfuscation techniques in your evaluation of any proxy solution for your organization.
Simple proxies don't recognize anything other than a standard domain name. So many of the techniques in the linked article above will get past a URL filter. So if someone wanted to bypass a typical proxy they could obfuscate the URL they type in the browser and still get to sites that are deemed inappropriate based on policy or contain malicious content.
Many of the better proxies are aware of these techniques and will "translate" the URL before passing it through the URL filter to ensure the real URL gets filtered, and blocked or scanned if appropriate.
Be sure to include obfuscation techniques in your evaluation of any proxy solution for your organization.
Subscribe to:
Posts (Atom)