Mobile Code
Home > Ask the Security Experts > Application Security Questions & Answers > Controlling U3 smart drive use in the enterprise
Ask The Security Expert: Questions & Answers
EMAIL THIS

Controlling U3 smart drive use in the enterprise

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 12 December 2006
Users have discovered that they can load Skype on U3 smart drives to get around our security policies. If we want to control p2p applications, what are our options? Can we employ application control on the desktop?

>
EXPERT RESPONSE
Mobile storage devices, or so called thumb drives, pose a real risk to network security. They can be used to download confidential data or introduce malicious code to the network. There has probably been far more corporate data lost to misplaced or stolen thumb drives than to laptops!

U3 devices compound these problems, since software can be downloaded on the host computer without any need for administrative privileges. U3 smart drives are specially formatted USB flash drives developed for Microsoft Windows systems, and they store and execute their own applications directly from the drive. Any data written to files or the host computer's registry is removed when the flash drive is ejected. This is an administrative nightmare, since users can easily run unauthorized programs that may consume bandwidth, impair network performance or undermine productivity. And the problem isn't going to go away. According to U3, forecasts predict USB flash drive sales to grow to 150 million units worldwide by 2008, with 70% of them projected to be smart drives.

You have various options to control the use of these devices. You could disable Universal Plug and Play, a set of protocols that automatically load USB storage devices as a drive, though this is a little draconian. A better solution is to control which USB devices are allowed to connect to your systems. GFI Software Ltd.'s EndPointSecurity, for example, allows administrators to log access and monitor the activity of storage devices such as USB drives and communication devices like BlackBerrys.

I would combine this type of defense with some form of application control at the desktop. Safend's USB Port Protector, for example, allows smart storage devices to be used strictly as simple storage devices (so long as they comply with the rest of your storage policy). The tool blocks their smart functionality so that programs can't be run from the device.

To tackle security issues involving Skype in particular, I would look to review your network border controls, such as firewalls, and stop the traffic on the network. Also, visit the Skype Web site, where you'll find an administrative template file for Windows Active Directory environments, allowing you to control Skype's use. At the end of the day, though, the only way to really reduce the risk of thumb drives is to develop and enforce an acceptable usage policy for thumb drives and U3-based applications. Your staff should also be made aware of the consequences of non-compliance.

More information:

  • Learn more about the threats that USB memory sticks pose to an enterprise.
  • Use this Messaging Security School lesson to protect your Blackberrys and other mobile devices.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    Protecting exposed servers from Google hacks (and Google 'dorks')
    Which automated quality assurance tools can be used to test software?
    Has proof-of-concept mobile device malware translated into any meaningful attacks?
    How to test the security of personal details submitted to a website
    Is security improved when the number of Internet gateways is reduced?
    Are Internet cafe users' email credentials at risk?
    Which operating system can best secure an FTP site?
    Will firewall technology have to adapt to applications that use port 80?
    How secure is a mobile phone platform that has an open source framework?
    What ports should be opened and closed when IPsec filters are implemented?

    Device Security Policy
    Finding lost notebooks with 'LoJack for laptops'
    iPhone security in the enterprise: Mitigating the risks
    VMworld: Desktop virtualization drives security skepticism
    Blogging on corporate laptops is risky business
    Will disabling thumb drives also affect the use of the keyboard and mouse?
    Are USB storage devices a serious enterprise risk?
    Wireless security: IT pros warily watching mobile phone threats
    Pod slurping: The latest data threat
    Report: FBI still losing laptops
    RSA: Accenture executive touts DRM, corporate data lockdown
    Device Security Policy Research

    Mobile Code
    Information security book excerpts and reviews
    When will attackers go mobile?
    Kaminsky on DNS rebinding attacks, hacking techniques
    Discovery of malware cesspool triggers attack fears
    Should the contents of a USB token be copied to a hidden directory called 'IEDW?'
    Are USB storage devices a serious enterprise risk?
    Mobile carriers admit to malware attacks
    Dozens of Web sites spread malicious Trojan
    Do USB memory sticks pose enterprise threats?
    Platform Protection: Security Issues for Mobile Devices

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts