Home > Security Tips > Web Security Advisor > Social networking Web site threats manageable with good enterprise policy
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

Social networking Web site threats manageable with good enterprise policy


Michael Cobb
02.14.2008
Rating: -2.62- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


A majority of attacks on the Internet depend upon the exploitation of human nature through the abuse of trust. It is human nature, for example, to feel comfortable with Web-based social networks that include our friends and family. We don't expect these people to be hosting anything on their pages that would "attack" us.

Likewise, most wikis are created by well-meaning people, typically subject matter experts, and we tend to trust experts. We don't expect a page full of useful information to contain anything that would be harmful. However, there is plenty of evidence that such Web pages are being used to distribute malware, almost always without the knowledge of the page owner or creator.

In November 2007, the MySpace profiles of Alicia Keys and a number of other recording artists were found to be serving up malicious code. McAfee Inc. also recently reported a malicious MySpace friend request which, when clicked, popped up an apparently legitimate "Automatic Update" window that, in fact, tries to download what McAfee described as a "malware cocktail" containing additional downloaders, several Trojans and a remote administration tool.

So, in addition to enterprise concerns over productivity losses to social networks and privacy issues arising from their use, particularly at work, there are now some direct security threats in play, including network compromise via infected pages. (To get a measure of just how much "drive-by" malware is being distributed by Web pages --including but not limited to social networks -- take a look at "The Ghost in the Browser" published last year by researchers at Google.)

For more information

Social networking sites may not be popular in corporate settings, according to a recent survey.

Learn about a do-it-yourself program designed to help would-be phishers target those using social networking sites.
 
Have an application security question? Ask Michael Cobb.
Creating a sensible social network policy
The challenge for the enterprise is to protect against attacks that come through social networks without losing the potential benefits derived from accessing them. These benefits are quite real, and a blanket ban on employees going to social network sites or wikis, either through policy, filtering or both, could put the organization at a competitive disadvantage, particularly in sectors such as entertainment and hi-tech, or in fields like marketing and human resources. Just as the maliciously inclined seek to leverage the popularity of social networks to their ends, all manner of legitimate entities are looking to do the same: promoting products, recruiting people, and so on.

Enterprises should manage social network dangers with sensible policy implemented through technology and training. The policy will depend upon an organization's risk posture and other specifics. A talent agency or other entertainment-related business, for example, may find a ban on social networks to be impractical. A bank, however, may allow only certain employees or group to access such sites. All organizations will want to remind employees that their Web browsing is monitored, and excessive trips to non-work related sites will be flagged and perhaps be used as grounds for some sort of penalty.

Getting employees to follow the policy
Training employees means educating them as to the policy, its enforcement and the risks that the policy is intended to mitigate. Employers are likely to get better cooperation if they lay the information out to workers rather than simply issue blanket bans from on high.

As for the risks mentioned in the policy, computers can be infected and used to attack other machines, including the corporate network, potentially causing significant damage and possibly the compromise of personal data and loss of personal files. Following such directives as "No clicking on banner ads on social networks" can help avoid those consequences since such ads have often been used to spread malware. Management professionals may want to add further directives amid the emergence of other attack vectors, like bogus update notices.

It may also be useful to do some general awareness training about social networks and wikis. Assumptions of anonymity on social networking sites should be challenged. Remind employees that what they post on numerous social networks is accessible to anyone on the planet with an Internet connection, and that information is often traceable. And just as employees should be advised to never put anything in email that they wouldn't want their mothers to read, they should ask themselves the same question when posting to social network sites: "Do you really want total strangers, and everyone you know, to know this about you?"

Of course, not all social Web sites are created equal. Some require meaningful identification of members and restrict access to vetted members, sometimes through paid subscription. These sites are arguably less open to abuse. For example, CompuServe forums, which required a paid subscription, never suffered much damage.

Regarding "social" malware, the defensive technology available includes traditional antimalware scanning across the network and all connecting clients, which may detect, and hopefully prevent, infections. Link checking or site filtering that weeds out known malware pages should also be considered; programs like LinkScanner and SiteAdvisor may help. Also, it may be worthwhile to consider OpenDNS, a free DNS resolution service, as a way to steer employees away from a whole range of bad sites. For employees whose machines spend time out of the office, consider specific bot defenses and the use of network access control technology, which vet systems before they are allowed back onto the corporate network.

Clearly social networking isn't going away anytime soon; it's arguably one of the most compelling and enjoyable ways to use the Internet. However, it's increasingly clear that malware and other threats will continue to plague social networking sites for the foreseeable future. With good policy and employee awareness, however, social networking threats can be greatly reduced.

About the author
Michael Cobb, CISSP-ISSAP is the founder and managing director of Cobweb Applications Ltd., a consultancy that offers IT training and support in data security and analysis. He co-authored the book IIS Security and has written numerous technical articles for leading IT publications. Mike is the guest instructor for several SearchSecurity.com Security Schools and, as a SearchSecurity.com site expert, answers user questions on application security and platform security.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Web Security Advisor
DNS rebinding defenses still necessary, thanks to Web 2.0
New defenses for automated SQL injection attacks
PCI compliance and Web applications: Code review or firewalls?
Worst practices: Bad security incidents to avoid
Web scanning and reporting best practices
Enterprise security in 2008: Building trust into the application development process
PCI DSS Section 6: A plan for tackling application security
Making the case for Web application vulnerability scanners
Preparing for uniform resource identifier (URI) exploits
How to avoid dangling pointers: Tiny programming errors leave serious security vulnerabilities

Creating and Managing Information Security Policies
IT security not valued at many firms, study finds
Sound compliance policies, practices reduce legal costs
Exploring Microsoft's Network Access Protection policy options
IAM best practices for employees with varying degrees of access to the same computer
How to avoid DLP implementation pitfalls
What's your advice for getting other business units to contribute to crafting an effective information security policy?
Security Awareness Training Essential Part of Infosec Program
Is it necessary to grant a full administrative privileges to a security administrator?
How to lock down instant messaging in the enterprise
Worst practices: Bad security incidents to avoid
Creating and Managing Information Security Policies Research

Emerging Information Security Threats
Weaponizing Kaminsky's DNS discovery
Linux systems actively targeted using SSH key attacks
What warning signs will indicate the presence of a P2P botnet?
Adobe investigates clipboard hijackings
How to patch Kaminsky's DNS vulnerability
Researchers use browser to elude Vista memory protections
Hacking techniques compromise Windows Vista heap
Kaminsky: DNS flaw capable of attacks on many fronts
Hoffman to demonstrate new hacking techniques
Black Hat Las Vegas 2008: News, podcasts and videos

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
defense in depth  (SearchSecurity.com)
non-disclosure agreement  (SearchSecurity.com)
security policy  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts