Home > Security Tips > Web Security Advisor > Tools for combating spyware in the enterprise
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

Tools for combating spyware in the enterprise


Mike Chapple, CISSP
07.07.2004
Rating: -3.26- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


You've probably seen the buzz in both the trade and consumer press about the threat spyware applications pose to user privacy. Have you considered how these threats might impact your enterprise and what you're going to do about it?

Quite simply, spyware consists of applications that contain chunks of code that (in addition to legitimate functions) monitor user activity. These applications, remarkably similar to Trojan horses, can perform many types of monitoring and reporting, ranging from merely monitoring use of the target application to full-scale invasions of privacy such as Web logging and keystroke monitoring. Some of these applications openly advise users that they're performing this monitoring, while others do so in a surreptitious fashion.

The implications to individual user privacy are clear – you certainly wouldn't want your credit card number or other sensitive information logged by a spyware application and reported back to spyware central. Enterprise users face similar risks – confidential corporate information can easily be detected by these systems. Enterprise users also face the detrimental impact that a large number of clients sending spyware reports over the Internet could have on bandwidth utilization.


MORE INFORMATION ON SPYWARE:

So what's an enterprise security administrator to do? Chances are that you already have (or are entitled to have) some level of spyware protection based upon your current antivirus license agreement. If you're using Symantec's AntiVirus Corporate Edition, the new Expanded Threat Detection and Threat Categorization feature allows you to detect (but not eliminate) spyware on your network. McAfee's VirusScan Enterprise edition has similar functionality.

You also may have come across more versatile applications like LavaSoft's Ad-Aware, Webroot's Spy Sweeper and McAfee's AntiSpyware that can both detect and eliminate spyware applications. However, until recently, the major drawback to these applications was their inability to scale to the enterprise. Most are $30 desktop systems that are capable of monitoring and protecting individual workstations but don't allow for integration into an enterprise-wide solution.

Two newer applications take a more comprehensive approach to spyware. ZoneLabs' Integrity Enterprise Endpoint Security is capable of not only detecting spyware but also blocking spyware traffic from leaving the client system. PestPatrol, the makers of a popular desktop anti-spyware solution, recently released PestPatrol Corporate Edition, a scalable enterprise solution that can detect and eradicate spyware across a large enterprise.

Now that the major players in the security software field are starting to catch up with the spyware threat, it's time to look at your enterprise's vulnerability and research appropriate solutions to protect your data and bandwidth.

About the author
Mike Chapple, CISSP, currently serves as Chief Information Officer of the Brand Institute, a Miami-based marketing consultancy. He previously worked as an information security researcher for the U.S. National Security Agency. His publishing credits include the TICSA Training Guide from Que Publishing, the CISSP Study Guide from Sybex and the upcoming SANS GSEC Prep Guide from John Wiley. He's also the About.com Guide to Databases.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Malware, Viruses, Trojans and Spyware,   Web Security Advisor,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Malware, Viruses, Trojans and Spyware
Hackers to sharpen malware, malicious software in 2010
iPhone worm Rickrolls jailbroken phones
Israeli Mossad add Trojan Horse to Syrian laptop
Schneier-Ranum Face-Off: Is antivirus dead?
Modern malware, stealthy botnets, adapt quickly, expert says
Computer worm infections up, scareware antivirus down, Microsoft says
Web-based attacks skyrocket, pirating sites surge, security firms say
Mini guide: How to remove and prevent Trojans, malware and spyware
Kaspersky system analyzes malicious URLs on Twitter for malware
Silon malware intercepts Internet Explorer sessions, steals credentials

Web Security Advisor
DNS rebinding defenses still necessary, thanks to Web 2.0
New defenses for automated SQL injection attacks
PCI compliance and Web applications: Code review or firewalls?
Worst practices: Bad security incidents to avoid
Web scanning and reporting best practices
Social networking Web site threats manageable with good enterprise policy
Enterprise security in 2008: Building trust into the application development process
PCI DSS Section 6: A plan for tackling application security
Making the case for Web application vulnerability scanners
Preparing for uniform resource identifier (URI) exploits

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
directory traversal  (SearchSecurity.com)
government Trojan  (SearchSecurity.com)
Kraken  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
RAT (remote access Trojan)  (SearchSecurity.com)
RavMonE virus  (SearchSecurity.com)
RFID virus  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts