Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 2005

Put a Stop to Spyware

Learn how to recognize and get rid of this modern-day scourge
RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Is Spyware Legal?

Watch Your Back
So how does spyware get on your systems? Such programs are typically installed through the following means:

  • Free utility software—Numerous free utilities are written specifically as delivery mechanisms for spyware. These programs are one of the most common sources of spyware and include software to block popups, manage calendars, synchronize clocks, find bargains on the Internet, give real-time weather updates, and view online greeting cards.
  • Bundled software—Sometimes a software company that wants to generate additional revenue from its software will partner with a spyware company.
  • Licensed software—Snoopware is often installed through standard licensed software.
  • Drive-by download—Spyware that exploits low browser or application security settings can affect a system when the user visits a Web site, views a popup advertisement, or reads an HTML-enabled email message.
  • Silent download—Once installed, some forms of spyware will install new spyware. Because spyware typically has escalated privileges on the affected system, new spyware installations or upgrading of the existing spyware is common.

Spyware distributed by free, bundled, or licensed software typically comes with an End User License Agreement (EULA) that the user must accept before installation. These EULAs often provide detailed information about what rights the user is granting the spyware publisher and what activities the publisher might monitor. (They also complicate legal actions against spyware companies, as the sidebar "Is Spyware Legal" explains.) A typical EULA, such as the one that comes with DashBar, is 12 pages and grants the publisher the ability to "occasionally install and/or update software components," among other rights. Drive-by and silent downloads almost never present EULAs and therefore represent a greater risk to organizations because their publishers make no commitment about the rights and limitations of the software.

Understand the Risks
Would you let end users randomly establish VPNs to remote organizations without your knowledge and approval? If your answer is "No!" but your organization doesn't have policies or infrastructure in place to prevent spyware, you might be surprised by the real risks to which you're open. Table 1 lists these risks and their relative likelihood (which might vary from business to business). Of these risks, the two most misunderstood are reduced security posture and increased bandwidth usage. If you need a reason to get approval for preventative measures, the following information might come in handy.

Reduced security posture. Each time a system on your network becomes infected with spyware, the overall security of your organization is compromised. Spyware often runs with administrative-level privileges to systems on which it is installed, giving it the ability to communicate on the network and download and install software. The only limitations of these escalated privileges are those imposed by the spyware publisher. In addition, many types of spyware directly alter the security settings of the affected system to better enable the spyware's operation or to prevent its removal. Some spyware adds sites to Microsoft Internet Explorer (IE's) trusted zone, alters Web browser security settings, adds entries to a HOSTS file, or even disables antispyware and antivirus software. Even after you remove spyware, general configuration changes made to the system often remain, leaving the computer vulnerable to other spyware programs.

Increased bandwidth usage. All types of spyware use your bandwidth to communicate with remote systems. In lab tests, I found that each spyware product adds an average of two times the standard network traffic (e.g., for a system infected with 10 spyware products, 30KB of inbound/outbound traffic for a Google search averages 600KB of traffic). In one test, a system running only WeatherBug generated 133KB of traffic just by opening a Web browser to the default Google home page. Only 1.7KB of this traffic resulted from communication with the Google Web server; the rest was the result of communications between the system and two Web servers registered under different organizations (but both in fact representing the same spyware publisher).

Arm Yourself
By now you're asking, "How do you get rid of this stuff?" Unfortunately, no one product or technology can eliminate the risk of spyware within your organization. However, you can control spyware by establishing a defense-in-depth strategy that involves a combination of use policies, user education, and technology.

The typical foundation of such a strategy is often an acceptable use policy that defines what users can and can't do with their systems and—most importantly—establishes penalties for not adhering to the policies. Typical policies cover Web browsing, downloading, and installing software. User education is often the next layer in your defensive strategy. Spyware can be confusing to IT administrators; it's often incomprehensible to end users. Still, given a proper education, many users can be taught the risks of visiting questionable Web sites, accepting ActiveX controls, or installing software from unknown or questionable organizations. Of course, no defense is complete without the help of the proper technology. Several categories of software can be used to fight spyware (see "Learning Path," page 62, for suggestions about where to find more information about some of these types of products):

  • Content filters—Content filters at your network perimeter can prevent users from visiting sites that might represent a spyware risk and can prevent spyware from communicating with its publisher.
  • Antivirus software—Network- or desktop-based antivirus software can give you an early warning of certain malware, particularly Trojan horses and dialers.
  • Antispyware software—Antispyware software identifies, cleans, and prevents spyware from being installed on a system. Unfortunately, because of the speed with which new spyware is introduced and the relative immaturity of antispyware programs, no one product provides a comprehensive solution. As a result, many IT departments use two or more products in tandem to increase breadth of coverage.
  • Desktop firewalls—Host-based firewalls have traditionally been deployed only to mobile users but are becoming more common on desktops. Firewalls that regulate outbound connections—not including Windows XP Service Pack 2's (SP2) Windows Firewall—can reduce the risk of spyware by providing notification. Although knowing about spyware doesn't prevent a system from becoming infected, it can help you keep the spyware from performing its intended function.
  • Patch-management programs—Spyware often exploits security vulnerabilities in browsers to install itself on systems. Keep systems updated with critical system and browser security patches, by using either Windows Update or centralized patch-management solutions.
  • Browser security–management tools—Tools that help you centralize the definition and management of browser security, such as the Internet Explorer Administration Kit (IEAK), let you lock down the security of your organization's Web browsers and prevent drive-by downloads.

A Real and Present Danger
Spyware in all its forms—adware, snoopware, and malware—represents a real and present danger to businesses, in the form of increased security and legal risks. Understanding what spyware is, how it gets on your systems, and how it can negatively affect your business is an essential part of developing a strategy to protect your organization.

End of Article

   Previous  1  [2]  Next  


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Interact! Take our spyware Instant Poll

Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

IE 8.0 and Chrome Could Enable Next-Gen Web Apps—Unless Your ISP's Bandwidth Cap Gets in the Way

Both browsers are being positioned as the core system application that will enable the next generation of web apps--however, ISP usage caps could throw a major monkey wrench at web-based application delivery. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...


Security Whitepapers Protecting (You and) Your Data with Exchange Server 2007

Extended Validation SSL Certificates

Unauthorized applications: Taking back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

IT Connections
Dive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities.

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Get SQL Server 2008 at WinConnections
Don’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.



Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing