Risk
10/25/2010
02:49 PM
Connect Directly
RSS
E-Mail
50%
50%

Workers Abusing Social Sites On Corporate Networks

Employees' use of Facebook, Gmail, Hotmail and BitTorrent is posing security risks, according to study by Palo Alto Networks.

Slideshow: Cloud Security Pros And Cons
Slideshow: Cloud Security Pros And Cons
(click image for larger view and for full slideshow)
More than 70% of the traffic on corporate networks today comes from the Internet, and a sizable portion of it stems from employees’ use of Gmail, Hotmail, Facebook and BitTorrent for personal reasons.

That finding comes from a study released by next-generation firewall vendor Palo Alto Networks, based on firewall data captured in 723 organizations worldwide: 275 in North America, 207 in the Asia-Pacific region and 241 in Europe.

"This is based on real traffic in enterprise networks at a global level," said Franklyn Jones, director of EMEA marketing for Palo Alto. Compared with results from similar studies, he said, "It seems as though users are taking control of the corporate network," in the types of applications they're using, accompanying security risks introduced and bandwidth consumed.

To provide more precise details, Palo Alto divided the personal applications it found into three categories: socializing, saying (email and IM) and sharing. Altogether, these applications account for about 25% of the traffic seen on corporate networks.

In terms of socializing, the most popular networking platforms (in terms of the percentage of businesses in which their use was seen) were Facebook (95%), Twitter (93%), LinkedIn (85%), MySpace (79%) and Facebook applications (76%).

While all social networking platforms have risks -- as well as potential rewards -- Palo Alto said that the prevalence of Facebook applications was cause for concern. "The more that enterprises download Facebook applications, the more likely they are to be attacked," said Jones. Relatively speaking, Facebook and its applications are bandwidth hogs, consuming 500% more bandwidth than the other 47 social networking applications seen combined, without even factoring in Facebook mail and chat traffic.

For email and IM, 81% of the applications found have the potential to allow inbound threats into the network, while 59% create the potential for data leakage.

The most popular email client was Gmail, found in 93% of enterprises, followed by Hotmail in 90%. In addition, 76% of businesses use the IM consolidation platform Meebo.

For applications aimed at sharing information -- beyond email, IM and social networks -- the Palo Alto study found that 83% of all related bandwidth can be traced to P2P applications. That's consistent for most countries, except Germany, where P2P use in the workplace is relatively low, and Spain, where use of Megaupload, a browser-based file-sharing tool, is high. "I don't know what's going on in Spain, but there is some serious, serious file transferring going on," said Jones.

The bottom line is that when it comes to personal applications on corporate networks, they're not going away. "The challenge then is how IT should respond," he said.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5700
Published: 2014-09-22
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in blocks/loginbox/loginbox.template.php to index.php. NOTE: some o...

CVE-2014-0484
Published: 2014-09-22
The Debian acpi-support package before 0.140-5+deb7u3 allows local users to gain privileges via vectors related to the "user's environment."

CVE-2014-2942
Published: 2014-09-22
Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a privileged terminal session by calculating the superuser code, and then leveraging physical access or terminal access to enter this code.

CVE-2014-3595
Published: 2014-09-22
Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.

CVE-2014-3635
Published: 2014-09-22
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows remote attackers to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one m...

Best of the Web
Dark Reading Radio