Risk

10/25/2010
02:49 PM
50%
50%

Workers Abusing Social Sites On Corporate Networks

Employees' use of Facebook, Gmail, Hotmail and BitTorrent is posing security risks, according to study by Palo Alto Networks.

Slideshow: Cloud Security Pros And Cons
Slideshow: Cloud Security Pros And Cons
(click image for larger view and for full slideshow)
More than 70% of the traffic on corporate networks today comes from the Internet, and a sizable portion of it stems from employees’ use of Gmail, Hotmail, Facebook and BitTorrent for personal reasons.

That finding comes from a study released by next-generation firewall vendor Palo Alto Networks, based on firewall data captured in 723 organizations worldwide: 275 in North America, 207 in the Asia-Pacific region and 241 in Europe.

"This is based on real traffic in enterprise networks at a global level," said Franklyn Jones, director of EMEA marketing for Palo Alto. Compared with results from similar studies, he said, "It seems as though users are taking control of the corporate network," in the types of applications they're using, accompanying security risks introduced and bandwidth consumed.

To provide more precise details, Palo Alto divided the personal applications it found into three categories: socializing, saying (email and IM) and sharing. Altogether, these applications account for about 25% of the traffic seen on corporate networks.

In terms of socializing, the most popular networking platforms (in terms of the percentage of businesses in which their use was seen) were Facebook (95%), Twitter (93%), LinkedIn (85%), MySpace (79%) and Facebook applications (76%).

While all social networking platforms have risks -- as well as potential rewards -- Palo Alto said that the prevalence of Facebook applications was cause for concern. "The more that enterprises download Facebook applications, the more likely they are to be attacked," said Jones. Relatively speaking, Facebook and its applications are bandwidth hogs, consuming 500% more bandwidth than the other 47 social networking applications seen combined, without even factoring in Facebook mail and chat traffic.

For email and IM, 81% of the applications found have the potential to allow inbound threats into the network, while 59% create the potential for data leakage.

The most popular email client was Gmail, found in 93% of enterprises, followed by Hotmail in 90%. In addition, 76% of businesses use the IM consolidation platform Meebo.

For applications aimed at sharing information -- beyond email, IM and social networks -- the Palo Alto study found that 83% of all related bandwidth can be traced to P2P applications. That's consistent for most countries, except Germany, where P2P use in the workplace is relatively low, and Spain, where use of Megaupload, a browser-based file-sharing tool, is high. "I don't know what's going on in Spain, but there is some serious, serious file transferring going on," said Jones.

The bottom line is that when it comes to personal applications on corporate networks, they're not going away. "The challenge then is how IT should respond," he said.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12697
PUBLISHED: 2018-06-23
A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.
CVE-2018-12698
PUBLISHED: 2018-06-23
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
CVE-2018-12699
PUBLISHED: 2018-06-23
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
CVE-2018-12700
PUBLISHED: 2018-06-23
A Stack Exhaustion issue was discovered in debug_write_type in debug.c in GNU Binutils 2.30 because of DEBUG_KIND_INDIRECT infinite recursion.
CVE-2018-11560
PUBLISHED: 2018-06-23
The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.