web threats

You are currently browsing articles tagged web threats.

The browser is an integral element in the corporate Cloud strategy. The broad take-up of web technology with standardized languages and protocols has resulted in the browser taking on the role of a universal client for end-user access to web-based and cloud-based resources. Browsers are free, and everyone knows how to use one. Pretty compelling arguments when budgets are tight!

But is using an industry standard browser really a zero-cost proposition for the enterprise? Let’s take a look at some of the issues.

Consumer-driven technology. The browsers we’re all familiar all obey one fundamental design principal: they must be as easy to use as possible for the greatest number of users. They must not hinder the user’s interaction with the web and the sites they want to visit – no matter what content those sites are hosting. In response to the Web 2.0 drive to increased user interactivity with rich internet applications, the browser transparently downloads and executes “helper” applications (Ajax, Flash, Java, ActiveX for example). In other words, the configuration of the browser is unstable and unmanageable. Is this really what you want from a key element of the corporate information infrastructure, the user interface to business critical applications?

Insecure design. Security professionals are increasingly aware that browsers are inherently insecure. The problems are threefold: (i) the browser, like any complex software environment, will always be exposed to bugs and vulnerabilities; (ii) the browser, connected to the internet, is inherently more exposed to external threats than software operating primarily locally on the machine, with local data; (iii) the browser’s self-modifying architecture (via plugins, for example – see above) multiplies the two preceding security risks.

No protection for confidential data. The end user connecting to enterprise Cloud services from home or from a cybercafé using the locally-installed browser is a threat to the enterprise. Business-critical processes and data may be exposed, via the browser, to a PC over which the enterprise has no control. Even if the user is sufficiently security-aware (and technically competent) to clear the browser cache and history at the end of each session – and how many of your users are? – sensitive data may still be stored locally (Flash cookies, to give just one example, without going into spyware and other threats).

If corporate IT management is to take full control of the cloud computing environment, we need to rethink the client-side connection. A new browser architecture is needed, secure by design, protecting corporate IT resources against web-based threats.

For more about the security issues of the browser and the Cloud, take a look at our White Papers.

The SANS Institute, internationally recognized for its leadership in information security training and certification, has just published a threat report under the title “The Top Cyber Security Risks“. It comes as no surprise to us at commonIT that the report clearly identifies web usage as the key vector for attacks, whether at the client side or on the server.

The report leads by identifying two priorities that need addressing: unpatched client-side software, and vulnerabilities in Internet-facing web sites. Based on data collected between March and August of this year, the authors show that application vulnerabilities now far exceed those being discovered in the operating system, commenting that “browsers and client-side applications that can be invoked by browsers seem to be consistently targeted”.

A well-developed tutorial included in the report describes one specific way in which the enterprise can expose itself to web-based penetration. But the report is full of interesting data, and merits the time to read it for any information security professional.

And so to Virtual Browser. If we find the report particularly interesting and relevant, it’s not just for the quality of the data. It’s also because our Virtual Browser technology successfully addresses and mitigates the situations described, something no other technology on the market today is capable of. By putting the browser in a datacenter-hosted virtual machine and isolating browsing sessions from each other, the enterprise is fully protected whether the client side or server side is compromised. Virtual Browser — the enterprise browser solution, Secure by Design.