SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Are you overconfident in dealing with Web 2.0 threats?

Are you overconfident in dealing with Web 2.0 threats?

By:  Rafael Ruffolo  On: 21 May 2009 For: ComputerWorld Canada Creator

As C-level executives finally come around on Web 2.0 usage, many security admins continue to lag behind the threats it will bring, according to Websense. Plus, why Info-Tech says security vendors are missing a key issue in the debate

New research from San Diego, Calif.-based security firm Websense Inc. suggests that while 80 per cent of IT managers are confident in their organization’s Web 2.0 security policies, a large majority are ill-equipped to protect against emerging threats. But according to at least one industry analyst, security vendors have to look above and beyond content filtering and work more closely with popular social networking platforms.

The survey, which polled 1,300 enterprise IT managers around the global, found that 93 per cent of Canadian respondents allowed access to at least one type of Web 2.0 site, with those numbers reaching 95 per cent globally.

Additionally, 30 per cent of respondents around the world reported pressure from C-level executives and directors to allow more access to Web 2.0 sites within the enterprise, a statistic causing serious headaches for the 51 per cent of Canadian respondents who felt users in their organization were trying to bypass existing Web security policies.

Despite the numbers, Websense is pointing to the 68 per cent of respondents that do not have real-time analysis of Web content, 59 per cent that cannot prevent URL redirects, and the 53 per cent that are unable to detect and stop spyware and malicious embedded code as a very dangerous security trend.

“We even saw malicious content on Barack Obama’s Web site, so even high-profile sites can be hit,” said Carl Mercier, director of software development for Websense’s Defensio.com service, a spam filtering Web service that protects against malicious attacks in blog comment boxes. He added that many IT managers are too overconfident in their immunity to these threats and don’t take the proper precautions, such as basic backups, to protect themselves.

For Websense, the strongest tool in Web 2.0 protection is content filtering, with the company offering real-time threat protection and Web filtering software specifically designed for growing social networking threats.

But according to Tim Hickernell, associate lead research analyst with Info-Tech Research Group Ltd., while content filtering is an important first step, it’s not the only step to successfully dealing with Web 2.0 security challenges.

“It’s understandable that they focus on this, because that’s what these guys know,” he said. “But what’s unfortunate is there are specific and very unique challenges in some Web 2.0 technologies — especially social networking ones — that are not about content and cannot be trapped at the network level.”

Hickernell said that currently there are no enterprise-class administrative controls on any social networking services. A common problem occurs when employees use their Facebook Inc. account for both personal and business contacts, he added.


Sign up for our Newsletters
Tags: networking












Print |  Views: 2726   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Rafael Ruffolo Rafael Ruffolo was a senior writer for ComputerWorld Canada from 2006 to 2011. He was the winner of a Kenneth R. Wilson award for business journalism in 2009.

Related Content

Xbox Live exec leans on his security background
Xbox Live exec leans on his security backgroundA Microsoft executive tells the SecTor 2008 crowd how to get every business unit thinking about protecting data without shelling out big bucks on new training and services
Security group releases business-relevant metrics
Security group releases business-relevant metricsThe Center for Internet Security will make its metrics available as a community resource and will include ways of measuring vulnerability assessments and time to recover from security incidents. How you can use these metrics to improve your company’s security
So you think you know security
So you think you know securitySecurity is one of the biggest issues on the CIO’s agenda. But how good is your basic knowledge around this vital subject? Well, here’s your chance to find out. Prominent security vendors and consultants from across the country sent us the following questions for our National CIO Security Test. So sharpen your pencil and prepare to be challenged.
The Conficker conflaguration
three months is a pathetic response time for pretty much every business issue, but it’s particularly pathetic when you’re talking about an issue that could cripple your employee’s ability to work at all. and yet, as the conficker/downadup worm continues to wreak havoc across enterprise it networks, security researchers are saying that many firms still haven’t deployed the patch microsof

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.