Free Newsletters




   
CIO magazine chief information officer ERP IT strategy  research  analysis business technology e-business CRM customer relationship management e-business   enterprise resource management leadership
CIO.com
About
Search
Awards Programs
Subscribe
Magazine
Current
Previous
Print Links
Newsletters
CIO Store
CIO Conferences
CIO Executive Council
Blogs
News Alerts
CEO Reading
IT Strategy
Tech Linkletter
Tech Policy
Viewpoints
Experts
Alarmed
Analyst Corner
Beneath the Buzz
Consultant Briefing
Higher Learning
In the Know
Leading Questions
Weigh-In
Discussion Forums
Career
CIO Wanted
Counselor
IT Events Calendar
Movers & Shakers
Research & Polls
CIO Research Rpts
Quick Poll
Tech Poll
Reports & Guides
CIO Bookmark
Reading Room
Special Reports
Compliance
RITLAB
State of the CIO
Webcasts
White Papers
About Us
Advertise at CIO
Conference Info
Editorial Calendar
Editorial Staff
List Services
News Bureau
Reprints
Sales
Related Sites
CSO
CMO
Darwin
IDG Network
Feedback to CIO
© CXO Media Inc.
subscribe to CIO Magazine



Home > CIO Metrics
Regulatory Resource   Threat Intelligence      Resilient IT      Boardroom Strategies      
Threat Intelligence / Spam and Viruses

Playing Bond: Catching Spyware in the Act

By Laura Roe Stevens

A comprehensive strategy for security management has never been more critical for the enterprise. Antivirus software alone will not root out the most demanding of security breaches. Today, corporations are challenged by the heightened threat of spyware and its less-evil cousin, adware. Both intruders can creep in and remain undetected by the network while they reside on end users' computers.

Spyware finds its way to individual PCs or enterprise networks through loopholes found primarily in Microsoft's Internet Explorer browser protections (the company offers patches to combat the spyware). Once inside, this sophisticated bot may track keystrokes, steal passwords, "listen in" on instant messaging conversations, and spy on open applications. It can also allow unauthorized users to manipulate PCs remotely, downloading and installing software and accessing data stored on the computers it infects. At the enterprise level, competitive and sensitive information can be disclosed, potentially harming the enterprise's bottom line.

Spyware's advertising equivalent, adware, comes attached to Internet sites and can be downloaded unbeknownst to the end user. Some marketing companies use adware to operate like Internet private detectives -- allowing them to follow people as they surf the Web and gather information such as the Web sites they visit, ads they view, and goods they purchase. With this knowledge, companies can then send targeted pop-up ads, even getting around pop-up blockers. While this is intrusive, it isn't often perceived as quite as dangerous as spyware. However, for the enterprise, it can cause many problems, including reduced available bandwidth, loss of employee productivity, and an over-worked IT help desk department.

Spyware is an insidious, widespread problem. A recent Aberdeen Research report noted, "every PC in the world is now infected with spyware bots." What's more, these intruders can bypass firewalls and antivirus programs, rendering traditional security practices useless against them. A comprehensive strategy is required to fend off these malicious intruders.

Spyware's many ports of entry

Multiple anti-spyware products are now on the market, but until recently, most were designed for desktop users and not scalable to corporations. Enterprise anti-spyware products are now emerging as the spyware threat increases. Analysts strongly recommend that corporations purchase a product that can sweep the network daily for spyware, while also instituting a comprehensive strategy to protect the company from future break-ins. Even if the firewall is protected, there are multiple ways spyware can get into the enterprise -- including via telecommuting employees and disgruntled employees, who may infect their own PCs intentionally before leaving a company.

All ports of entry are vulnerable to spyware -- even loyal employees may unknowingly bring in spyware when downloading applications necessary to do their jobs. Forrester Research points out that employees may also drag in spyware when surfing the Web, particularly when visiting file-sharing sites, which are renowned for having ads with spyware.

Attacking spyware on the network

One way to combat this threat is to have a united front. Companies should create a centralized "security overseer" responsible for setting and managing security policies. This person would report to the CIO or CEO and would set enterprise-wide policies on Internet access and surfing behavior. This will reduce the likelihood of encountering spyware.

With recent federal regulations, the security chief can also file suit or report violators to the government. In October of 2004, the U.S. House of Representatives passed two anti-spyware bills, allowing large fines to be levied on companies found deploying spyware. The "Spy Block Act," now pending in the Senate, would require software companies to notify consumers of the fact that software is about to be downloaded onto their machines. Even without the support of this legislation, the U.S. Federal Trade Commission (FTC) has been able to crack down on spyware purveyors by citing deceptive-business laws. The FTC asked a federal court to shut down two companies owned by one New Hampshire businessman -- a marketing company that reportedly infected computers with spyware and sent out pop-up ads advertising the man's other company, which sold anti-spyware services.  

Once considered strictly a consumer issue, spyware is sneaking into the enterprise, eating up bandwidth, pumping out unwanted pop-ups, crashing employees' computers, and potentially posing a risk to sensitive and critical corporate data. Companies can and must develop strategies to protect valuable data and worker productivity.

Laura Roe Stevens is an Atlanta-based freelance writer who has covered business and technology for The New York Times, Los Angeles Times, and the Atlanta Business Chronicle.

CIO Strategy Center is a daily editorial resource offering innovative insights and strategies for building an integrated, secure and resilient IT infrastructure.

Articles by Topic
Spam and Viruses
Preparedness
Strategies
Related Content
Fast Fact

"Every PC in the world is now infected with spyware bots."

--Aberdeen Research






Advertisers



Free Newsletters
Sponsor Content
 Domains
Compliance CIO Partner Domain for I.T. Productivity
The domain for everything you need to assess, measure and improve
IT Productivity within your organization, Whitepapers, Books, Research, Benchmarking tools and lots more.
 Webcasts
Compliance Failure is not an option: Why online compliance and security can’t wait.
Compliance BI Standardization: Attend our virtual conference for real advice.
Compliance Getting Smart about Offshoring: How Visual Simulation Gets It Right the First Time
Compliance Turning Best Practices to Best Projects
Compliance Securing Enterprise Data In An Unsecured World
Compliance A New Game—The Fast Emerging World of IP Convergence
Compliance All CIO Webcasts
 White Papers
Compliance Organizations Shift Focus to Information Management
Compliance Tera-Scale Data Warehouse Appliances Overcome the Technology Bottleneck
Compliance Knowing the Risk
Compliance Why Asset Management and Discovery are Core Contributors to Effective Business Service Management
Compliance Start your ERP upgrade with a distinctive master data advantage
Compliance Putting your Spend Data Warehouse on steroids
Compliance All CIO White Papers

IDG ENTERPRISE NETWORK

NetApp launches expanded NAS line - Infoworld Staff
IBM, BEA lay out new Java specs - Infoworld Staff
  »More  

Phishing scams rocket
Wi-Fi switches: breakthrough year, future fear
  »More  

Users get going on SP2 rollouts
Shark Tank: Just one more thing to remodel
  »More  

SPONSORED LINKS:
Align IT with business goals. Introducing PlanView Enterprise.
A data warehouse 10-50x faster at ½ the cost. Learn more!
How do you compare with 565 IT organizations?
For real advice on BI Standardization attend the Virtual Conference on Feb 22
Manage IT Change. Manage the Business. Free white paper.
Ten Principles for Knowledge Management Success" - Get the free white paper from ServiceWare
Audit the Data or Else: Un-audited data increases business risk Grid
See Qualcomm, EPL, and Deutsche Post on the Oracle Grid
Preventing Client/Vendor Mismatch: click here to learn more

Free Newsletters

Dated: March 01, 2005
http://www.cio.com/blog_view.html?ID=221


About CIO.com | Welcome | Privacy Policy | Terms of Service | Linking to us

CIO.COM complies with the ASME Guidelines with IDG extensions for new media.

CIO magazine chief information officer ERP strategy IT research analysis business technology management e-business knowledge management intranet CRM cio.com CRM customer relationship management e-business ERP enterprise resource management leadership management measuring IT value outsourcing supply chain

© 1994 - 2005 CXO Media Inc.

An International Data Group (IDG) Company



 HOME  CURRENT ISSUE  ARCHIVE   About CIO :: Advertise :: Subscribe :: Conferences 

Reprints, IDG Network, Privacy Policy

THE IDG NETWORK
CSO :: CMO :: Darwin :: Computerworld :: Network World :: Infoworld :: PC World :: Bio-IT World
IT Careers:: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp



Problems/complaints/compliments about this site can be sent to deiben@cio.com.