Risk
10/25/2010
02:49 PM
50%
50%

Workers Abusing Social Sites On Corporate Networks

Employees' use of Facebook, Gmail, Hotmail and BitTorrent is posing security risks, according to study by Palo Alto Networks.

Slideshow: Cloud Security Pros And Cons
Slideshow: Cloud Security Pros And Cons
(click image for larger view and for full slideshow)
More than 70% of the traffic on corporate networks today comes from the Internet, and a sizable portion of it stems from employees’ use of Gmail, Hotmail, Facebook and BitTorrent for personal reasons.

That finding comes from a study released by next-generation firewall vendor Palo Alto Networks, based on firewall data captured in 723 organizations worldwide: 275 in North America, 207 in the Asia-Pacific region and 241 in Europe.

"This is based on real traffic in enterprise networks at a global level," said Franklyn Jones, director of EMEA marketing for Palo Alto. Compared with results from similar studies, he said, "It seems as though users are taking control of the corporate network," in the types of applications they're using, accompanying security risks introduced and bandwidth consumed.

To provide more precise details, Palo Alto divided the personal applications it found into three categories: socializing, saying (email and IM) and sharing. Altogether, these applications account for about 25% of the traffic seen on corporate networks.

In terms of socializing, the most popular networking platforms (in terms of the percentage of businesses in which their use was seen) were Facebook (95%), Twitter (93%), LinkedIn (85%), MySpace (79%) and Facebook applications (76%).

While all social networking platforms have risks -- as well as potential rewards -- Palo Alto said that the prevalence of Facebook applications was cause for concern. "The more that enterprises download Facebook applications, the more likely they are to be attacked," said Jones. Relatively speaking, Facebook and its applications are bandwidth hogs, consuming 500% more bandwidth than the other 47 social networking applications seen combined, without even factoring in Facebook mail and chat traffic.

For email and IM, 81% of the applications found have the potential to allow inbound threats into the network, while 59% create the potential for data leakage.

The most popular email client was Gmail, found in 93% of enterprises, followed by Hotmail in 90%. In addition, 76% of businesses use the IM consolidation platform Meebo.

For applications aimed at sharing information -- beyond email, IM and social networks -- the Palo Alto study found that 83% of all related bandwidth can be traced to P2P applications. That's consistent for most countries, except Germany, where P2P use in the workplace is relatively low, and Spain, where use of Megaupload, a browser-based file-sharing tool, is high. "I don't know what's going on in Spain, but there is some serious, serious file transferring going on," said Jones.

The bottom line is that when it comes to personal applications on corporate networks, they're not going away. "The challenge then is how IT should respond," he said.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-3308
Published: 2015-09-02
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.

CVE-2015-4330
Published: 2015-09-02
A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges for OS command execution via invalid parameters, aka Bug ID CSCuv10556.

CVE-2015-6274
Published: 2015-09-02
The IPv4 implementation on Cisco ASR 1000 devices with software 15.5(3)S allows remote attackers to cause a denial of service (ESP QFP CPU consumption) by triggering packet fragmentation and reassembly, aka Bug ID CSCuv71273.

CVE-2015-6277
Published: 2015-09-02
The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1, Nexus 9000 devices 7.3(0)ZD(0.61), and MDS 9000 devices 7.0(0)HSK(0.353) and SAN-OS NX-OS on MDS 9000 devices 7.0(0)HSK(0.353) allows remote...

CVE-2015-6587
Published: 2015-09-02
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.

Dark Reading Radio
Archived Dark Reading Radio
Another Black Hat is in the books and Dark Reading was there. Join the editors as they share their top stories, biggest lessons, and best conversations from the premier security conference.