<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ERE-Security Blog &#187; Social Media</title>
	<atom:link href="http://ere-security.com/blog/category/social-media/feed" rel="self" type="application/rss+xml" />
	<link>http://ere-security.com/blog</link>
	<description>NERC CIP, NERC CIP compliance, SCADA, SOX, digital certificates, harmonized TRA, privacy compliance audit, CSOX compliance audit,  it security audit, information security auditors, IT security auditors, web security auditors, information security audit, information security auditor, security policy document</description>
	<lastBuildDate>Sat, 21 May 2011 00:10:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Anti-Social Networking Sites:  Part 2</title>
		<link>http://ere-security.com/blog/anti-social-networking-sites-part-2</link>
		<comments>http://ere-security.com/blog/anti-social-networking-sites-part-2#comments</comments>
		<pubDate>Tue, 29 Sep 2009 17:27:40 +0000</pubDate>
		<dc:creator>Ron Lepofsky</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://ere-security.com/blog/?p=59</guid>
		<description><![CDATA[My previous blog article focused on the two points that
1) Social networking sites present security threats.
2) There are many steps corporate security professionals can take to mitigate these threats, including policy, enforcing policy with procedures, security training, administrative procedures, and technology.
What&#8217;s in the News 
Since the last blog there has been a steady stream of [...]]]></description>
			<content:encoded><![CDATA[<p>My previous blog article focused on the two points that</p>
<p>1) Social networking sites present security threats.</p>
<p>2) There are many steps corporate security professionals can take to mitigate these threats, including policy, enforcing policy with procedures, security training, administrative procedures, and technology.</p>
<p><strong>What&#8217;s in the News </strong></p>
<p>Since the last blog there has been a steady stream of news about more security threats originating at web sites, particularly from social networking sites.  Profit motive appears to be the primary intent of the threats.  The methodology is committing identity theft for profit.  Below are a sample of four web based news articles to which I refer:</p>
<p><strong>Mitigating Web-Based Malware Attacks. August 17, 2009</strong></p>
<p><a href="http://www.threatpost.com/blogs/mitigating-web-based-malware-attacks-117">http://www.threatpost.com/blogs/mitigating-web-based-malware-attacks-117</a></p>
<p><strong>The Dirtiest Websites To Avoid, 2009-08-20</strong></p>
<p><a href="http://www.securitypronews.com/insiderreports/insider/spn-49-20090820TheDirtiestWebsitesToAvoid.html">http://www.securitypronews.com/insiderreports/insider/spn-49-20090820TheDirtiestWebsitesToAvoid.html</a></p>
<h3>Researcher details Facebook CSRF Flaw, August 21, 2009</h3>
<p><a href="http://www.scmagazineus.com/Researcher-details-Facebook-CSRF-flaw/article/146986/">http://www.scmagazineus.com/Researcher-details-Facebook-CSRF-flaw/article/146986/</a></p>
<p><strong>Malware designed to steal IDs increased 600 percent, August 20, 2009</strong></p>
<p><a href="http://www.scmagazineus.com/Malware-designed-to-steal-IDs-increased-600-percent/article/146909/">http://www.scmagazineus.com/Malware-designed-to-steal-IDs-increased-600-percent/article/146909/</a></p>
<p>For additional statistical data, the reader can verify the list of infected sites from various manufacturers, including Google and can see growth of malware sites over 100% in last year.</p>
<p><strong>More Financial Motivation </strong></p>
<p>There appears to be a current trend towards targeting smaller and medium sites with identity theft attacks, probably because the larger sites were attached first.  Also, organizations that deploy small and medium sized sites may not have the security precautions and resources available to their larger counterparts.</p>
<p>Of course, bad guys do not get sleep deprivation if their attack is running on a small site rather than on a large site.</p>
<p><strong>The Popular Drive-By Attack</strong></p>
<p>There is increase in &#8220;drive by download&#8221; of malware, where a visitor to a web site unwittingly loads malware from the site.  The malware is placed by the perpetrators by exploiting vulnerabilities in web sites.  They find the vulnerabilities by a simple query to search engines to find vulnerabilities readily published by software tool manufacturers, providing notifications of patches and weakness warnings.</p>
<p><strong>My Next Blog Article</strong></p>
<p>My next article will provide preventative measures that both end users and web site managers can implement to protect all concerned from the dangers of drive-by malware.</p>
<p>Have a secure week.</p>
<p>Regards,</p>
<p>Ron Lepofsky</p>
<p>ERE Information Security Auditors</p>
]]></content:encoded>
			<wfw:commentRss>http://ere-security.com/blog/anti-social-networking-sites-part-2/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anti-Social Networking Sites</title>
		<link>http://ere-security.com/blog/anti-social-networking-sites</link>
		<comments>http://ere-security.com/blog/anti-social-networking-sites#comments</comments>
		<pubDate>Tue, 22 Sep 2009 03:06:55 +0000</pubDate>
		<dc:creator>Ron Lepofsky</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Information Security Consulting]]></category>
		<category><![CDATA[Information Security Monitoring]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://ere-security.com/blog/?p=43</guid>
		<description><![CDATA[Over the last two weeks security news reports identify social networking sites as distribution points for malware of all sorts and flavours and as botnets for distributing more of the same.  In addition, site users seem enthusiastic to reveal personal information to those who would gladly accept the information for purposes of identity theft. [...]]]></description>
			<content:encoded><![CDATA[<p>Over the last two weeks security news reports identify social networking sites as distribution points for malware of all sorts and flavours and as botnets for distributing more of the same.  In addition, site users seem enthusiastic to reveal personal information to those who would gladly accept the information for purposes of identity theft.  The benefits of social networking are being strongly challenged by the disadvantages of predatory, definitely anti-social behavior.</p>
<p>We have posted several such articles on the ERE web site: <a href="http://www.ere-security.ca/">www.ere-security.ca</a>; the most recent one being</p>
<p>August 17, 2009</p>
<p>Hackers put social networks such as Twitter in crosshairs</p>
<p><a href="http://www.infoworld.com/d/security-central/hackers-put-social-networks-such-twitter-in-crosshairs-832?source=IFWNLE_nlt_sec_2009-08-17">http://www.infoworld.com/d/security-central/hackers-put-social-networks-such-twitter-in-crosshairs-832?source=IFWNLE_nlt_sec_2009-08-17</a></p>
<p>My advice to all concerned, especially CIOs CSOs and security managers is to create and enforce end-user policy for social networking sites.  The fundimentals are of course:</p>
<ol>
<li>Do not reveal any personal / financial information that you would not otherwise gladly hand to your neighbours.</li>
<li>Do not answer any personal questions.</li>
<li>Be very leary of links to other web sites, particularly those involving any aspect of personal finance.</li>
</ol>
<p>Policy should also enforce:</p>
<ol>
<li>Timely patch updates on all end-user devices.</li>
<li>Timely updated anti-malware signatures and updates.</li>
<li>Defence in depth with at least two layers of malware protection: at least on the end-user devices and on an internet gateway device, through which all related traffic must pass.</li>
<li>Enforce all related traffic through the gateway; shut down all unnecessary ports and services on the corporate firewall and then test to see if undesired traffic can be tunneled or otherwise circumvent the gateway.</li>
</ol>
<p>The difficulties of enforcing policy regarding end-user activity is of course convincing them to want to act in accordance with policy and then punishing those who contravene policy.  These of course are age old problems.  However there are tried-and-true solutions.</p>
<p>Security awareness training has proven most beneficial in this arena, particularly where training is coupled with rewards for adhering to policy. Handing out rewards to those who pass an on-line test demonstrating their awareness and possibly compliance with policy is a positive reinforcement that further encourages support of the policy.</p>
<p>Rewards may include inexpensive items such as tee-shirts with an appropriate message or sporting and entertainment vouchers. Of course accolades in corporate news services are a must.</p>
<p>Enforcement must be consistent and ubiquitous, including all senior management.  Detection of non-compliance can be accomplished with the use of many automated tools plus by an audit team, perhaps composed of H/R staff, simply visiting the employee accounts on social networking sites.  This of course requires that as part of policy, that employees must disclose all their social networking accounts, which is a major issue of contention with regard to privacy.</p>
<p>Privacy policy is another topic entirely, as the usual measures of privacy really are outdated by the invention of social networking sites.  For instance, it would have been impossible for privacy policy authors to contemplate social networking sites 20 years ago.  But this is a topic for another time.</p>
]]></content:encoded>
			<wfw:commentRss>http://ere-security.com/blog/anti-social-networking-sites/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

