Minimizing Malicious Content

author-image
DQC News Bureau
New Update

Casual non-business related web surfing has
caused many businesses countless hours of legal litigation. Hostile work
environments have been created by employees who view and download offensive
content. As government regulations and legal requirements begin to hold company
executives accountable for their employee's actions, corporate executives and
IT professionals alike are becoming more concerned about what their employees
are checking and downloading from the Internet.

Advertisment

While
the Internet is a large source of business-related information, unmonitored Net
access is a leading legal liability for organizations, especially when it comes
to employees getting access to objectionable content while at work, and using
corporate resources to download, store and exchange copyrighted material.
Inappropriate use of the Internet at work is becoming a regular occurrence in
today's corporate environment.

Casual non-business
related web surfing has caused many businesses countless hours of legal
litigation, as hostile work environments have been created by employees who view
and download offensive content. Copyright infringement lawsuits filed by the
music and movie picture industries are increasing as employees use file-sharing
programs to download their favorite music and movie files.

As government
regulations and legal requirements begin to hold company executives accountable
for their employee's actions, corporate executives and IT professionals alike
are becoming more concerned about what their employees are viewing and
downloading from the Internet.

Advertisment

The instant
accessibility to information has been a blessing and source of pain for all
types of businesses as well as home users. Traditional firewalls, intrusion
detection systems and anti-virus solutions that are commonly used to secure the
modern enterprise can not help to monitor and secure web surfing activities
conducted by employees. With increased use of Web applications, the need to
monitor and control Web access is becoming clearer to all businesses large and
small.

Getting malicious content

According to a survey that was conducted by SonicWall Inc, more than 75% of
people have accidentally visited a pornographic web site while at work; 15% of
them more than 10 times. The survey also reported that 50% of respondents spent
more than 10% of their time at work surfing the Web for personal reasons, which
is roughly equal to four hours per week, or nearly nine days a year.

As per an IDC report
that 30% to 40% of Internet access is being used for non-business purposes. The
American Management Association reports that 27% of Fortune 500 companies have
been involved in sexual harassment lawsuits over their employee's
inappropriate use of email and Internet use.

Advertisment

The Center of Internet
Studies has reported that more than 60% of companies have disciplined employees
over Internet and email use with more than 30% terminating employees, while the
Recording Industry Association of America (RIAA) and the Motion Picture
Association of America (MPAA) have pursued legal action against corporations
over the illegal downloading of music and movies from the Internet. The RIAA
recently won a case against an Arizona company for $1 million dollars.

Pop up windows (55%),
misrepresented links (52%), misspelled URLs (48%) and auto links within emails
(23%) are the most common ways people have accidentally reached pornographic
content on the Web. While it is common to accidentally come across pornographic
web sites, reports indicate that people have knowingly surfed pornography sites
at work at least once in addition to using the office time to surf gambling
sites, for shopping online and surfing sports-related web sites.

According to Sugata
Sanyal, Senior Director, Content and Managed Security, SonicWALL, “Adult sites
tend to have threats of viruses, trojans and spyware. But the threat is not
limited to only adult sites. Users may not be sufficiently cautious when
entering personal information on web sites. Some sites look authentic, but are
not - for example, fake airline reservation sites. Spyware, virus programs can
detect users' browsing habits (sites visited, links clicked, etc.) for
fraudulent purposes.”

Advertisment

“The most common
methods of becoming infected with spyware are downloading programs, using
peer-to-peer software/screensavers/windows utilities, download managers/file
sharing software/demo software, games, trojans delivered or downloaded in
e-mail, banner ad-based software where the user exchanges the annoyance of
banner or pop-up ads for the benefit of not having to pay for software.
Microsoft's ActiveX module, which everyone has natively with Windows is
perhaps the most notorious enabler of Spyware,” he adds.

Grayware
categories


Adware: Adware is
usually embedded in freeware applications that users can download and
install at no cost. Adware programs are used to load pop-up browser
windows to deliver advertisements when the application is open or run.

Dialers: Dialers are
grayware applications that are used to control the PC's modem. These
applications are generally used to make long distance calls or call
premium 900 numbers to create revenue for the thief.

Gaming: Gaming
grayware applications are usually installed to provide jokes or nuisance
games.

Joke: Joke grayware
are applications that are used to change system settings, but do no damage
to the system. Examples include changing the system cursor or Windows'
background image.

Peer-to-Peer: P2P
grayware are applications that are installed to perform file exchanges.
(P2P) While P2P is a legitimate protocol that can be used for business
purposes, the grayware applications are often used to illegally swap
music, movies, and other files.

Spyware: Spyware
applications are usually included with freeware. Spyware is designed to
track and analyze a user's activity, such a user's web browsing
habits. The tracked information is sent back to the originator's Web
site where it may be recorded and analyzed. Spyware can be responsible for
performance related issues on the user's PC.

Key logger: Key loggers are perhaps one
of the most dangerous grayware applications. These programs are installed
to capture the keystrokes made on a keyboard. These applications can be
designed to capture user and password information, credit card numbers,
email, chat, instant messages, and more.

Hijacker: Hijackers are grayware
applications that manipulate the Web browser or other settings to change
the user's favorite or bookmarked sites, start pages, or menu options.
Some hijackers have the ability to manipulate DNS settings to reroute DNS
requests to a malicious DNS server.

Plugins: Plugin grayware applications
are designed to add additional programs or features to an existing
application in an attempt to control, record, and send browsing
preferences or other information back to an external destination.

Network management: Network management
tools are grayware applications that are designed to be installed to for
malicious purposes. These applications are used to change Tools network
settings, disrupt network security, or cause other forms of network
disruption.

Remote administration tools: These tools
are grayware applications that allow an external user to remotely gain
access, change, or monitor a computer on a network.

BHO: BHO grayware applications are DLL
files that are often installed as part of a software application to allow
the program to control the behavior of Internet Explorer. Not all BHOs are
malicious, but the potential exists to track surfing habits and gather
other information stored on the host.

Toolbar: Toolbar grayware applications
are installed to modify the computer's existing toolbar features. These
programs can be used to monitor web habits, send information back to the
developer, or change the functionality of the host.

Download: Downloaders are grayware
applications that are installed to allow other software to be downloaded
and installed without the user's knowledge. These applications are
usually run during the startup process and can be used to install
advertising, dial software, or other malicious code.

It's all grayware

'Grayware' is a term that regularly appears on IT and security
professionals' radar screens today. An umbrella term applied to a wide range
of applications that are installed on a user's computer to track and/or report
certain information back to some external source, these applications are usually
installed and run without the permission of the user.

Advertisment

In addition, many of the
most threatening impacts of grayware, such as usage pattern tracking, invasion
of privacy and information theft can remain unseen and all possible without the
user having to consciously download and execute any

applications.

“With grayware, users
don't even have to open an attachment or execute a program to become infected.
Just visiting a Web site that harbors this technology is enough to become a
victim. While some types of grayware such as pop-ups may be viewed as an
annoyance not a true security threat - there is a fine line between
“harmless” grayware and those types that can compromise valuable information
such as credit card numbers, passwords, and user identity,” says Vishak Raman,
Country Manager, Fortinet Inc.

“All grayware sources
are not necessarily malevolent, as Web site developers are using newer
techniques to customize their web sites and obtain better results. Tracking the
usage patterns of visitors to offer more customized search results and cause
higher sale is the ultimate goal of many of grayware applications,” he adds.

Advertisment

When systems go gray

When loaded with grayware, the performance of the computer is slower because
the grayware application takes more CPU and memory. Often, the grayware
applications running on the computer are “unknown” applica­­­­­­­­­­­tions
to the user.

In the presence of
grayware, the send and receive lights on the cable/DSL modem or the
network/modem icons on the task bar flash to indicate traffic transmitted to and
from the computer, even though the user is not performing any online processes
at that time to cause such traffic to occur. The computer displays pop-up
messages and advertisements when not connected to the Internet or when the
browser is not running. Also the home page on the web browser gets changed from
the selected default and changing it back may not fix the problem.

When grayware is
installed, Internet Explorer's search engine gets changed from the default
setting and an unexpected search site delivers search results. The user web
browser's “favorite” list gets modified and changing it back or removing
the new additions does not work. The search or web browser toolbars are modified
and new options are installed. Attempts to remove the toolbar items fail.

Advertisment

Many users get increased
phone bills due to numbers or premium services that they did not use. Most
anti-virus, anti-spyware programs, or other security related programs stop
working and users get warnings of missing application files and replacing them
does not solve the problem. Sophisticated grayware applications may even disable
popular security programs before installing themselves.

Grayware: Who is responsible?

Most of the problems related to grayware have been attributed to user
behavior. This means that if malicious content is detected on a network all the
stakeholders responsible for such act would be liable.

These stakeholders
could include the Infrastructure and IT Head of an organization, the concerned
machine owner, the surfer and of course the establishment owner and the owner of
the site.

In the event of being
found guilty, an employee necessarily gets punished and the degree of punishment
would depend on each organization and the culture they operate in. What is
objectionable is very subjective and will differ on employee sensibilities. It
is quite likely to differ from one to country to another. However as common
practice employees found guilty would be subject to serious disciplinary action,
including suspension or termination.

Tackling the problem

Though not a sure-all method, every grayware mitigation program should
start with development, communication, and enforcement of policies to guide end
user behavior. This can be as simple as educating employees regarding the nature
and dangers of grayware and establishing policies that prohibit downloading and
installing applications that are not approved by the company. In the case where
download and installation are allowed, users should be instructed to carefully
research the provider's web site and read the fine print in the “End User
License Agreement”. By doing this, they learn what is being installed and what
the applications are designed to do when they click on the software license's
“I Agree...” button.

Organizations need to
inform their employees about correct security practices like 'good cookie
etiquette' of keeping passwords separately from their computer, or in an
encrypted program on the computer; being aware of entering information into
non-secure sites (including account names, passwords, text of Web forms and
Web-based email, etc.); making sure they do not accidentally enter information
onto sites that look authentic, but are not; and being wary of opening spam or
email from unknown sources, as they may contain spyware programs. Sophisticated
security technology can allow the administrator to give specific privileges as
regards content to specific users. This helps both security and employee
productivity a great deal.

“There are
possibilities that employees browse the internet for objectionable content but
browsing restrictions have been configured and internet access is monitored
regularly. Educating and training employees is very important and Netsol has a
training department that conducts induction/awareness programs and periodic
trainings on different security/technology aspects,” says Sudhir Sharma, MD of
Bangalore-based Network Solutions.

Agreeing with him is
Ravi Verdes, Director, Frontier Business Systems, Bangalore, who says,
“Surfing the net for objectionable purposes cannot be tolerated and will not
be encouraged. To ensure that it is adhered to, we have put checks through
specific tools and surfing has been strictly and regularly monitored. We also
have in place a corporate etiquette that incorporates regular corporate
communication about web access and monitoring so as to maintain and administer
corporate code of conduct. Information about the same is provided in the
employee handbook.”

Stringent measures,
coupled with ethical conduct guidelines for employees, governing the use of
Internet and other IT resources have become the order of the day for most
organizations. Instead of moral policing, most head honchos prefer to act as
facilitators and make people sensitive to such issues.

“We believe people are
responsible enough to manage their conduct ethically and professionally. If we
can provide appropriate culture and work-environment, it makes sense for the
management to educate employees on IT policies and Internet usage, feels
Prashanth L J, Assistant V-P & Head, Global Marketing, Infinite Computer
Solutions, Bangalore. “As an organizational policy we allow restricted
internet use limited to information sites only; access to mail sites, jobsites
and porn sites are controlled by having filters/firewalls. We have a
well-documented IT policy, which serves as a ready reckoner to educate people.
Posters are displayed around our facilities informing people about the policies
besides internal email campaigns,” he adds.

While employee education
and stringent policies may help reduce the amount of malicious content on the
network, it could raise a concern of 'curbing an employee's “right to
surf”. According to Surinder Singh, Head South East Asia and India, Websense,
“Any employee who uses the Internet for legitimate business purpose would not
raise an objection. But even if one does, there are ways to tackle that. Access
to certain websites can be denied during work hours, while it may be provided
after work hours or better still some part of the day can be allotted for
employees to indulge in gaming or downloading video and music. That way the dual
purposes of network protection and employee freedom are served.”

Security packages

In addition to a well-defined Internet usage policy, most organizations use
secured tools and have implemented procedures bound with security packages to
enable employees use the net only for legitimate business purpose. Employee
monitoring and surveillance tools are in place, for web browsing activities,
e-mail, and potentially instant messaging.

Users and IT
professionals have become 'grayware educated' and understand the threats
that these applications bring. They have started turning to client-based
software applications that spot, remove, and block spyware. The new breed of
anti-spyware applications function similar to the anti-virus programs installed
on all computer systems today.

Host-based anti-spyware
applications have the ability to detect, remove, and block grayware
applications, based on their signature database. Their success will depend on
the number of grayware signatures and accuracy of their signature databases.

A third way of detecting
grayware applications is through a network gateway approach. Installing grayware
detection on a perimeter security appliance where the private corporate network
connects to the public Internet can help identify and eradicate grayware
applications before they reach the end user's computer.

The network-based
approach centralizes the intelligence at the ingress point into the corporate
network where grayware enters the company and significantly lowers the
maintenance overhead of installing, maintaining, and keeping signature databases
up-to-date. By performing an update on the gateway appliance performing the
grayware protection, all computers behind the gateway are automatically
protected.

The most effective way
to combat grayware as of today is web content filtering. This includes creating
of a 'black list' dictionary that contains words or phrases. URLs and web
content is compared against the black list to block unauthorized web sites. Also
making a list of containing known bad or unauthorized web site URLs can be made
to allow sensible web surfing.

Category blocking is the
latest web content filtering technology that greatly simplifies the management
process of

web inspection and content filtering. It utilizes external services that help
keep suspect web sites up-to-date as regards content security given its ease of
deployment, management, and updation.

SUBBALAKSHMI BM

(subbalakshmibm@cybermedia.co.in)