Reputation Is Key In Securing A Company

author-image
DQC News Bureau
New Update

As the use of social networking sites become mainstay, even among
employees, IT security is expected to remain as the key focal point among
companies. For the complete solution to threats, coupling a 'reputation service'
to an enterprise gateway solution is critical

Advertisment

Cyber criminals today are always devising new ways to breach the security
systems of enterprises. They have graduated to creating new spam techniques by
using popular Web 2.0 websites such as Wikipedia and YouTube as a front for
malicious websites to lure users to download malware.

Enterprises need to be vigilant when it comes to safeguarding their sensitive
information. Therefore, no matter what position an employee may hold within your
client's company, he should always be aware of the risks of poor IT security and
be on his guard. Better still, as a solution provider you ought to take the
initiative to make your clients and their employees understand the dangers
lurking in cyber world.

Be alert

Anyone's identity can easily be stolen without his or her knowledge. Social
networking sites like Facebook and MySpace have an enormous impact on security
because of people's willingness to share personal information.

Advertisment

Over the past couple of months, IT security vendors have reported an
insurgence in malware across the globe including the recent 'StormWorm'
epidemic, an increase in attachment-based stock spam in PDF, Excel and ZIP
format and web-hosted malware in the form of fake e-greeting cards. The goal of
these perpetrators is to steal online identities and make a fortune selling in
the open market.

Recently, it was reported that there was an increase in spam volume by 25
percent in Asia, as compared to the daily average in July. There was also a
significant increase in spam activities in Asia and across the globe, from the
beginning of August, peaking at 53 percent above July's daily average and 70
percent above June's average.

The spam volume in August reached a record high, whereby 88 percent of all
e-mail was spam. Up to 11 percent of the spam was the latest PDF spam while new
zombie infections had also hit a threshold of 3,80,000 cases per day.

Advertisment

Face the risks

Loss of sensitive data through a lost or stolen device

Thousands of mobile phones and networked handheld devices are lost or stolen
each year leading to the exposure of confidential company information. If a
competitor obtained the data such as an executive's e-mail inbox or calendar,
full of meetings and briefings, the damage can be overwhelming.

Malicious software

Although viruses, Trojan horses, and worms are familiar threats to
traditional desktops and laptops, mobile devices are becoming targets and this
will only increase in time.

Unauthorized Wi-Fi access

While more employees are working remotely at Wi-Fi hotspots such as cafes,
this ad hoc wireless network connection can also lead to unauthorized device
access and critical company data. Wi-Fi hotspots typically do not have any
security solutions in operation at all, making them an easy target for cyber
criminals.

Advertisment

Illicit network penetration

Mobile devices can be targeted as a strategic way of infiltrating protected
corporate systems. Once an attacker gains access to the mobile device, it can
impersonate the legitimate user, making access to the corporate network a
breeze.

Unauthorized device connectivity

An employee connecting a personal device to the Exchange Active Sync may
bypass security settings and applications required on a corporate device.

Holistic security approach

Enterprise network security is the approach to keep the bad guys out.
Internet and e-mail use are pervasive in all enterprises and need specialized,
application-specific security approaches to ensure that they are not compromised
by malware from the outside or by costly data leakage or policy breaches from
the inside. These capabilities represent application-level defense-in-depth and
need to be fully integrated on purpose-built appliances, with application
awareness locally and a real-time awareness of the global Internet for the
purpose of making security-relevant decisions.

Advertisment

What is needed

Here are some important characteristics that an enterprise gateway solution
should include:

- Proactive anticipation of threats to catch them before they cause damage

- Integration across devices and protocols in order to provide the broad
protection necessary in today's ever-changing environment

Advertisment

- Bi-directional inspection of incoming and outgoing traffic

- Multi-layered defense that incorporates multiple security techniques to
ensure a complete blanket of security coverage

- Real-time global intelligence providing a system that is an active
participant in the mutual sharing of real-time security intelligence

For the complete solution to both today's and tomorrow's threats, coupling a
'reputation service' to an enterprise gateway solution is critical. A reputation
service acts as the first layer of protection. It accumulates data from
thousands of sources across the globe to create highly accurate and
up-to-the-second profiles of all messaging and web activity on the Internet.

Advertisment

This real-time activity is then analyzed for deviations from expected 'good'
Internet behavior to create a reputation score for each sender or host. If a
host is determined to be highly unreliable and most likely a spammer or cyber
criminal, then that host's traffic can be scored, tagged, and blocked, no matter
how clever or devious the attack may be.

Organizations now under­stand that attacks spread

very quickly, and for proper protection they must employ effective solutions
that combine intelligence data from thousands of sensors around the world

in real time, and use that information to identify and stop the broader
spectrum of threats.

How reputation helps

A global reputation system coupled with messaging appliances can identify
'bad' senders and content, and automatically blocks huge volumes of unwanted and
infected mail at the outer edge of customers' networks, eliminating well over 80
percent of mail traffic before it reaches the mail servers. Other benefits
include increased available network bandwidth, decreased load on messaging
servers' processors, and a significant improvement in the overall security
posture.

Another way to authenticate a user is to look at the likelihood that this
person is who he or she claims to be. For example, a user could log on to a bank
account located in Singapore, but the user name, password and token information
is identified as originating from an IP address in China that has been
associated as engaging in criminal activities.

Through a reputation service, the authentication request from that login
attempt can be blocked based on such critical infor­mation. A reputation-based
security system will provide the much-needed peace of mind for companies today,
as threats are stopped even before they enter the network. This, coupled with a
strong security policy imple­mented across the organization, will provide
enterprises the needed protection against the constantly evolving security
landscape today.

With increased mobility in the workforce, it is vital for enterprises to take
a proactive approach when it comes to securing their intellectual property. As
an employee, you too have a part to play as your online identity may be at risk
as well. By protecting your company, you are in turn protecting your identity
from being stolen.

Benjamin Low

MD-Southeast Asia and India, Secure Computing