Home > Security News > Wacky Web misuses highlight internal risks
Security News:
EMAIL THIS

Wacky Web misuses highlight internal risks

By Anne Saita, News Director
02 May 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Thanks to Web filtering, one IT manager discovered that an employee was running a side business selling items on eBay while on the clock. Keeping tabs on an online auction during working hours is hardly unique, but this particular employee happened to be selling office items stolen from the company warehouse.

"We thought it was kind of ingenious," Eric Lundbohm, vice president of marketing for Orange, Calif.-based 8e6 Technologies Inc., said sarcastically. His company has released results of a survey conducted during February's RSA Security Conference. The winners for best anecdotes were released this week.

"People running eBay businesses, in general, were among the most widely referenced examples," explained Paul Myer, the company's president and COO. "What made this unique [was] there was inventory taken out of the warehouse that was being sold out of his eBay store."

For more information

Highlights of the 8e6 survey:

  • More than 32% cited the need to control employee productivity as a key reason to use Web filtering.
  • Almost one in four of the 400 surveyed said managing bandwidth was their biggest problem.
  • A third of security professionals said they must provide detailed reports on Internet surfing to management, some on a weekly basis.
  • Second place went to a CTO whose company suffered an internal denial-of-service attack after a Victoria's Secret webcast overloaded the network. Third place went to an infrastructure manager that caught a female employee running an online call-girl service during business hours.

    Another noteworthy instance involved employees who reconfigured a company server for internal office pools and then parlayed that success to create a full-scale gambling site -- all done within the network's firewall.

    "It really stretches the imagination to see what people have come up with," Myer said. He noted one particularly disturbing instance when an employee strategically set up a webcam in the next cubicle to spy on a co-worker while working from home.

    All of these instances point to more than employee gumption. In addition to sucking up productivity and bandwidth, they pose legal and security risks.

    "The days are over when it's sufficient for a security professional to keep bad guys out of your network," Myer said. "These threats are not perimeter-based; they bypass security because they are initiated by users."

    The company, named for the phrase to "86" someone by tossing them out of a place, serves a number of customers in the education field, which Myer said provides a great test beds for risky or malicious insider behavior. "These customers deal with some very creative users with a lot of time and a lot of curiosity," he added.

    During the last nine months, the company's seen an upswing in misuse of anonymization tools to mask Web surfers. In response, 8e6 has built into its URL library the ability to block open source and publicly available proxy software at the packet level.

    "Employees probably feel the internet is an unlimited resource, and it's a victimless crime to misuse it a bit," Lundbohm said. "And the challenge for the security professional is to separate the wheat from the chaff."

    Tags: Web Authentication and Access ControlVulnerability Risk AssessmentEnterprise Risk Management: Metrics and AssessmentsSecurity Awareness Training and Internal ThreatsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Web Authentication and Access Control
    Group to shed light on secure identity management threats
    How to confirm the receipt of an email with security protocols
    Schneier-Ranum Face-Off: Is Perfect Access Control Possible?
    Kaminsky reveals key flaws in X.509 SSL certificates at Black Hat
    Changing times for identity management
    How to use single sign-on for Web access control to prevent malware
    IBM USB banking device stops keyloggers, malware
    Can mutual authentication beat phishing or man-in-the-middle attacks?
    Could someone place a rootkit on an internal network through a router?
    Sun launches open source OpenSSO for identity management

    Vulnerability Risk Assessment
    What patch management metrics does Project Quant use?
    Screencast: How to launch an OpenVAS scan
    Trusteer CEO criticizes Adobe, touts better patch deployments
    Patch management study shows IT taking significant risks
    Vulnerability mitigation study shows need for faster patching
    Microsoft to issue security report card, new tool at Black Hat
    Newest malware threats
    Are Web application penetration tests still important?
    PCI compliance requirement 6: Systems and applications
    Cybercrime and threat management
    Vulnerability Risk Assessment Research

    Enterprise Risk Management: Metrics and Assessments
    How to justify information security spending on cloud computing
    Layoffs prompt insider threat fears, cybersecurity survey finds
    How to avoid Internet liability lawsuits
    Bruce Jones: Report Security and Risk Metrics in a Business-Friendly Way
    Bernie Rominski: Communicate Effectively with Management about Risk
    Best Policy and Risk Management Products
    Monitoring program data and internal controls for risk management
    Risk management strategy for an information technology solution provider
    Align your data protection efforts with GRC
    The basics of enterprise GRC project management
    Enterprise Risk Management: Metrics and Assessments Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    access log  (SearchSecurity.com)
    anonymous Web surfing  (SearchSecurity.com)
    authentication, authorization, and accounting  (SearchSecurity.com)
    identity chaos  (SearchSecurity.com)
    knowledge-based authentication  (SearchSecurity.com)
    multifactor authentication (MFA)  (SearchSecurity.com)
    walled garden  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts