Enter your email address below and subscribe to our newsletter

Web Security 101 – familiarise yourself today

Share your love

Tich1.gifThe proliferation of the Internet is one of those developments that will undoubtedly be remembered for generations to come. Unfortunately, it has also become inherently complex and vulnerable; a single page can today contain a myriad of security vulnerabilities.

A recent white paper by Symantec: Web Based Attacks, February 2009 cites there has been a dramatic increase in the number and sophistication of Web based threats affecting users across all demographics and geographies.

The report states that throughout 2008 and into the early part of 2009 many new techniques and trends based around Web activity have been observed.

Comments Tich Mugwara, Symantec Enterprise Security Product Specialist at Drive Control Corporation (DCC): “Users are today faced with attacks that are sophisticated and therefore harmful to their laptops, desktops or even networks. It is important to remember that when surfing the Web to also bear in mind that you might stumble onto a site that has a number of viruses that could harm your machine.”

Here are some of the main threats that have been plaguing the worldwide web:

Drive-down downloads are increasing;
Attacks are dynamically changing and traditional anti-virus solutions are ill-equipped to handle it. Misleading applications are finding their way to our PCs via Internet pages; SQL (Windows environment) attacks are used to infect popular and mainstream web sites; Fake advertisements/malvertisements are redirecting people to malicious sites. Massive growth in targeted
malware samples.

In the case of targeting mainstream Websites, it is often those pages which contain material of an adult nature or pirated software that come under fire. Explains Mugwara: “These Websites have thousands of users that visit these sites on a minute-by-minute basis, making them – the users –
vulnerable.”

“With so many users, malware authors can reach the widest audience possible as often, these users are more concerned about the content than actually thinking about the potential harm of some of the applications or advertisement that they click through to.”

The Web Based Attacks, February 2009 report comments that unfortunately the notion that visiting mainstream sites, whether news, tourism, adult and many others, means you are safe no longer holds true.

So, how are these Websites targeted? Attack techniques include: SQL attacks; malicious advertisements; search engine result redirection; vulnerabilities in the Web server or forum hosting software; cross-site scripting (XSS) attacks; and attacks on the backend of virtual hosting
companies.

Furthermore, a single vulnerability in your Web browser, ActiveX controls, browser-plug-ins, multimedia and other third-party applications can render your PC defenseless and therefore open to attack.

“Unfortunately, we are also finding that people simply don’t download the latest virus patches, updates and so forth. While vendors work very hard to ensure that their users are protected the onus still remains with the individual to accept updates and ensure their security features the latest armour in its body of defence,” says Mugwara.

And while finding exploitable holes in a user’s environment is not easy; off-the-shelf web based toolkits enable attackers to probe a user computer and security holes. In fact, once vulnerabilities have been successfully exploited, the attacker can insert any particular malware they want on the
end-user’s system.

So what is your best line of defence against these web-based attacks? The solution is to deploy and comprehensive end point security products which layers of protection such as:

. Heuristic file protection. This technique enables a security product to spot new virus variants, even without a traditional virus finger-print signature, based on characteristics of the file itself;

. Intrusion Prevention System (IPS). Instead of just focusing on the virus files as they sit on disk, Intrusion Prevention Systems monitor network traffic looking for suspicious behaviour with the goal of stopping an attack before it takes up residency on your system.

. Behavioural Monitoring. If a malicious piece of software makes it onto your system by bypassing the defences of the Intrusion Prevention System and the file protection capabilities (both signature and heuristic), then a behavioural monitoring system may still be able to catch it.

Tich Mugwara
Symantec Security Product Specialist