Newsletter:

Skip Navigation LinksHome > News > Security > Protect your site from malware, warns Forrester

Protect your site from malware, warns Forrester

By Phil Muncaster
27 March 2008 03:03PM
Tags: protect | site | malware | warns | forrester

A new report by analyst firm Forrester Research has again highlighted the growing threat to firms of their web sites being infected by malware and their brands being abused in sophisticated phishing attacks.

The Threat Report: 2007 and Beyond, set for launch at this week’s Forrester Security Forum Emea event in Amsterdam, notes that where malware was once prevalent only on questionable web sites, it is to be found frequently on trusted domains today.

“There are countless examples where trusted sites have been compromised to host malware, or code that will redirect the user to a malware site,” said report author Chenxi Wang. “It’s important for operators of trusted sites to be extremely vigilant about the security of their sites so that there is no possibility they could be compromised.”

For sites with large quantities of user-generated content, Wang recommended automated scanning tools to check if any content being uploaded contains malware.

Another conclusion of the report is that firms’ brands are more at risk than ever before from phishing attacks. The new anti-phshing toolbar in IE7 will help users to a certain extent, but to “eradicate phishing completely will require a shift in user behaviour to greater vigilance” said Wang.

But Wang warned that internet service providers are unlikely to take a more proactive stance in scanning traffic for phishing sites and malware because of the risk of false positives, and the degradation of service that may result.

The report also highlights the sophistication of the criminal networks which write and disseminate malware for profit; describing various players in the chain from malware producers, through bot net operators to attack launchers.

“A question I raised in the report is ‘what can the good guys do to disrupt this underground economy and break the economic chain to turn things to our advantage?’,” said Wang.

itweek.co.uk @ 2008 Incisive Media

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Unified Communications Podcast Centre

TopTopics
(7040) -  microsoft
(6493) -  iinet
(6484) -  copyright
(6484) -  afact
(6423) -  internet
(5934) -  servers
(5934) -  mipi
(4294) -  telstra
(4106) -  phone
(3744) -  broadband
(3672) -  nvidia
(3586) -  nbn
(2439) -  avg
(1972) -  onecare
(1924) -  google