Top 5 social networking business threats

 

Summary

Security experts highlight risks enterprises face on social networks and explain why such sites make ideal targets for online criminal activities.

Events

IT Priorities 2010

Sydney, Australia - 27 Jul 2010
Melbourne, Australia - 28 Jul 2010
Mumbai, India - 4 Aug 2010
Delhi, India - 6 Aug 2010

IDC's Asia/Pacific Cloud Computing Conference 2010
31 Aug 2010

Marriott Hotel, Singapore

Social networking sites are ideal havens for online criminal activities as they provide a combination of two key factors: a huge number of users and a high-level of trust among these users, cautioned a security specialist.

Ronnie Ng, senior manager of systems engineering at Symantec Singapore, told ZDNet Asia in an e-mail that increased use of social networking sites for business purposes brings new security challenges to enterprises, which now need to strike a balance between managing assets and keeping up with the latest communication tools.

Attacks on social networking sites were "standard practice" for criminals in 2009, where the frequency and sophistication in attacks increased in the second half of last year, Ng said.

A recent survey by RSA showed that among users worldwide, Asians were most anxious of their security risk on social networking sites. Symantec also identified the proliferation of social networking sites as one of five security threats to watch for in 2010.

ZDNet Asia spoke to industry experts who highlight the top five security threats enterprises should be mindful about when using social networking sites.

1. Malware
"Social networking sites are vehicles for malicious attacks to spread malware," said Symantec's Ng, and cautioned against Tweets that point unsuspecting users to download malware.

He gave the example of fake Twitter invitations that have been used to spread a mass-mailing and malicious worm. Instead of pointing to an invitation link, the Tweet directs users to a malicious attachment that gathers e-mail addresses from compromised computers and spreads by copying itself into removable drives and shared folders.

In June 2009, the automated Twitter feed of author and venture capitalist, Guy Kawasaki, redistributed a malicious link to its followers.

In an e-mail interview with ZDNet Asia, Vincent Goh, managing director for RSA Southeast Asia added that wildfire infections will increase exponentially with social networking sites.

According to Goh, the leading infection methods are drive-by-download, which hijack legitimate Web sites or route visitors to infected servers, as well as social network infections, where spam is sent to a victim's "friends list" carrying links to infected servers.

He added that applications on social networking sites increase a hacker's surface attacks because most people would run applications on such sites without thinking twice. Malicious code could also be added to advertisements and banners, he noted.

Stefan Tanase, senior regional researcher for Eastern Europe, Middle East and Africa at Kaspersky Lab's global research and analysis team, said in an e-mail interview that enterprises with already compromised computers may post links distributing malware on their corporate accounts, putting customers at risk of being infected.

2. Spam
Ng said that previously spammers registered their own accounts and send unsolicited messages through the social networking site. The site would then send an e-mail notification to users about the new message. However, as the messages are sent to users from an unknown person so spammers are now using a newer technique.

According to Ng, Symantec has observed a rise in newer technique of social networking site abuse. A sender's account is hijacked and sends messages to everyone who is "connected" to the sender. When the receiver navigates to the message in the message, malware will try to load. "This example serves as a good reminder to all social networking site users that the message may not be from a friend, even if it is from a friend," said Ng.

3. Targeted attack through employees
Kaspersky Lab's Tanase said employees today are sharing too much information on social networking sites and hence, allowing themselves to become the point of breach for targeted attacks against the enterprise.

"All the personal information they share can be easily collected by someone with bad intentions and be used in sophisticated social engineering attacks," he said. "Usually, targeted attacks come with serious consequences, like intellectual property theft or corporate espionage."

RSA's Goh added that attackers use the trust factor typically associated with social networking sites to carry out social engineering attacks. "They could use these trusted networks to trick victims into sharing sensitive information or downloading malware like Trojans and worms," he said.

A recent report revealed that attackers had contacted key Google employees via social networks and imposed as their friends in a bid to urge them to on links that contained malware.

4. Phishing
According to Symantec's Ng, cyber attackers are using social networking sites to launch attacks that aim to lure victims to a malicious and fake login page to obtain the user's personal login details.

"Phishing attackers send a message to a victim's Facebook inbox, as well as an e-mail notification with the subject 'Hello' or 'Hi'," he explained. "The e-mail appears to have come from the victim’s friend and includes text asking the user to visit a malicious and fake Facebook login page, where the attacker will then steal the user's login credentials to launch future attacks."

Goh added that once an attacker breaks into a victim's account, it becomes easy to leverage the victim's social network and harvest information from other users. This information could be used for various cyber criminal activities, such as breaking into the users' online banking accounts or enterprise accounts.

5. Human error, leading to leaked corporate data
Tanase cautioned that some employees are also unwittingly posting confidential information about their job and company on social networks, believing this information to be safe.

"Such information about current projects, financial situation or future plans can prove to be invaluable for competitors," he added.

He also pointed out that a corporate social networking site account is usually managed by people with good communication skills, not IT skills.

"The lack of IT security education and strong [user] policies can lead to such an account being compromised, which will badly damage the image of the entire company," he said.

Prevention better than cure
Despite the security risks social networks can bring into a corporate environment, RSA's Goh noted that disabling access to such sites is not the best option as more and more businesses rely on these tools to support their daily operations.

Enterprises then need to make sure its employees are educated about security threats related to social networking sites, and implement a comprehensive access and data control strategy to prevent data loss, he said.

"If the enterprise can govern the access of information to only the right employees, loss of data by the attackers getting into the network could be minimized," he said. "That way, organizations can reap the benefits of social and business networking online, while keeping the fraudsters at bay."

Talkback

Top 5 social networking business threats

One of the frustrations i note with regards to FUD articles like these is that we're kept aware of dangers, but from a solution side, not more is being done.

Most security solutions hog up memory and diskspace, that slows down your machine to a halt. There was talk recently of coming up with solutions that are less CPU-hogging, and more on the network edge, but none have come forward with a good solution as yet.

Shouldnt all the talk about Cloud drive security solutions companies to come up with "thinner" solutions for us?

geewee February 3rd, 2010 Reply
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Access data anywhere in the private cloud & enable entirely new efficiencies with EMC VPLEX.
Tech Vendor: EMC

ZDNet Asia Live

Non-green IT products 'marketing suicide': At the same time, it seems vendors see green technology as a very high ... http://bit.ly/aCqko4

8 minutes ago by greentreats on topsy

Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

(zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

@mrcolinlim but of course for more tech updates you can always visit zdnetasia.com

RT @zdnetasia: Searchable Facebook user data posted to Pirate Bay http://bit.ly/ciJQxY

1 hour 5 minutes ago by phyllis777loves on topsy

RT @HazelHassan: Facebook led police to Philippine serial killer -- http://ow.ly/2iGnh

RT @zdnetasia: 10 questions to ask when http://www.zdnetasia.c...

RT @zdnetasia: S'pore marketeers not chirping to Twitter's tune http://bit.ly/bF2aoa

Facebook led police to Philippine serial killer -- http://ow.ly/2iGnh

1 hour 21 minutes ago by hazelhassan on topsy

Isn't IT ironic?: It's the analogy security firms like to narrate, about a cautious homeowner who pays thousands o... http://bit.ly/9DZIGw

What the iPhone-jailbreaking ruling means http://bit.ly/aXyEf9

S'pore marketeers not chirping to Twitter's tune http://bit.ly/dqTRZC

S'pore marketeers not chirping to Twitter's tune: Microblog site takes "backseat" in marketing campaigns, say Sing... http://bit.ly/axFgVh

S'pore marketeers not chirping to Twitter's tune http://bit.ly/dgUuGq

S'pore marketeers not chirping to Twitter's tune - Internet - News http://tinyurl.com/2bs...

S'pore marketeers not chirping to Twitter's tune: Marketing via Twitter has not picked up in Singapore, where it s... http://bit.ly/9GEDJS

great! S'pore marketeers not chirping to Twitter's tune http://bit.ly/dotZES Good day!

http://bit.ly/8v7Ov3 S'pore marketeers not chirping to Twitter's tune - ZDNet Asia http://is.gd/dSngs

3 hours 14 minutes ago by easytweeting on topsy

in the mean time, if you need to find PDF eBooks, you may use http://www.findpdf.us/

3 hours 45 minutes ago by findpdf on Researchers find workaround for Adobe PDF fix

Just want to say what a great blog you got here! My appreciation of your work, cause i am an IT student also. Try this one too, http://w...

3 hours 52 minutes ago by winsource on Making the case for Filipino IT entrepreneurship

Hi, We have ton of HP empty cartridges. Could you collect them in our office??
Thanks

1 day 45 minutes ago by Pacific Time Pte Ltd on Recycle your HP print cartridges and get rewards

Thanks Kenneth, for your insights. Good to know people out there can see the issue for what it is, and to do so impassively, that is. ...

2 days 50 minutes ago by yedwin on iPhone 4 shows prudence in procrastination

While I agree that the issues with the device have raised many an eyebrow, I think it's unwise to forget that many phone reviews have...

2 days 2 minutes ago by kennethkoh on iPhone 4 shows prudence in procrastination

The online apple store http://store.apple.com/ is not available now. Maybe it's updating the pricing ;)

2 days 252057 seconds ago by mingnow on iPhone 4 to ring in Singapore on Friday

After an awful silence, finally the prices are out..

2 days 56 minutes ago by melvinchia on iPhone 4 to ring in Singapore on Friday

Glad you discovered the Xfce 4.6 magic. Its other endearing feature is its phenomenal configurability. You can make the desktop look and ...

3 days 2 minutes ago by gnome_refugee on Smitten with Xfce 4

yep, tried them all and xfce with compiz/emerald instead of fvwm is by far the best experience I've had. If you didn't know ther...

3 days 1 minute ago by ggolemg on Smitten with Xfce 4

@mingnow: why do you think so? How do you think the FOSS community could tackle this issue? I'm involved in a lot of efforts to get t...

3 days 7 minutes ago by fredericmuller on Taobao initiates Chinese open source revolution

Geez. I would think giving free books and getting kids to school would be a better place to start.

3 days 14 minutes ago by mingnow on India's US$35 tablet--how low can it go?

I think it's great the that country with the biggest internet population is finally contributing back to the open-source world. I thi...

4 days 1 minute ago by mingnow on Taobao initiates Chinese open source revolution

hey.there Im Wendy from a PR Agency.I find your blog interesting and well written.In days to come,we would hold an event. Therefore We ...

4 days 31 minutes ago by wendy on iPhone 4 shows prudence in procrastination

It could be done without all these. Just use the opacity addon of Compiz.

4 days 55 minutes ago by hariks0 on How to get RGBA support in Ubuntu