Websense: Beware user comments online

By Vivian Yeo, ZDNet Asia
Wednesday, September 16, 2009 05:56 PM

Web 2.0 sites that allow users to create content, are increasingly used to carry out a wide range of attacks, according to a new security study.

Released Tuesday, Websense's State of Internet Security, Q1 - Q2, 2009 report noted that attackers are focusing their attention on interactive Web 2.0 elements. Some 95 percent of user-generated comments on blogs, message boards and in chatrooms are either spam or malicious, the security vendor warned.

"The very aspects of Web 2.0 sites that have made them so revolutionary--the dynamic nature of content on the sites, the ability for anyone to easily create and post content, and the trust that users have for others in their online networks--are the same characteristics that radically raise the potential for abuse," Websense said in its report.

Web 2.0 sites, the company added, comprise "many" of the most visited sites on the Internet. The top 100 most visited Web properties, tended to be classified as social networking or search sites. Nearly half, or over 47 percent, of the top 100 Web sites support user-generated content.

At the same time, sites that allow user-generated content make up the majority of the top 50 most active distributors of malware. Over 60 percent of the top 100 Web properties either hosted malicious content or redirected users to malicious sites without their knowledge.

"With their large user base, good reputations and support of Web 2.0 applications, these sites provide authors of malicious code with abundant opportunity to easily reach a wide number of victims with their attacks," the report continued.

Efforts to self-police Web 2.0 properties have, on the other hand, been "largely ineffective", Websense revealed. The security company said its research during the first six months of 2009 indicated that community-driven security tools, which enable users to report inappropriate content, on sites including YouTube and BlogSpot are 65 percent to 75 percent "ineffective in protecting Web users from objectionable content and security risks".

According to Websense statistics, the number of malicious sites between January and June grew 233 percent over the second half of 2008, and 671 percent compared to the same period last year.

The security firm also found that during the period, 78 percent of new Web pages with objectionable content such as pornography or gambling, contained at least one malicious link. Some 77 percent of Web sites with malicious code were compromised legitimate sites.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

3 Lessons a CIO can learn from Windows 7

Tech Management

Microsoft's missteps with Vista, and attempts at redemption with Windows 7, offers firms valuable lessons in IT, be it in rolling out a new corporate application or delivering millions of copies of a new OS.


Read more »



Amendments to empower Copyright Tribunal

Blog thumbnail

As a lawyer, I often inform my clients about the need to clear licenses with the various licensing societies whenever they use works belonging to other parties. This is especially..... by Bryan Tan

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web