Watch Your Back
So how does spyware get on your systems? Such programs are typically installed through the following means:
- Free utility softwareNumerous free utilities are written specifically as delivery mechanisms for spyware. These programs are one of the most common sources of spyware and include software to block popups, manage calendars, synchronize clocks, find bargains on the Internet, give real-time weather updates, and view online greeting cards.
- Bundled softwareSometimes a software company that wants to generate additional revenue from its software will partner with a spyware company.
- Licensed softwareSnoopware is often installed through standard licensed software.
- Drive-by downloadSpyware that exploits low browser or application security settings can affect a system when the user visits a Web site, views a popup advertisement, or reads an HTML-enabled email message.
- Silent downloadOnce installed, some forms of spyware will install new spyware. Because spyware typically has escalated privileges on the affected system, new spyware installations or upgrading of the existing spyware is common.
Spyware distributed by free, bundled, or licensed software typically comes with an End User License Agreement (EULA) that the user must accept before installation. These EULAs often provide detailed information about what rights the user is granting the spyware publisher and what activities the publisher might monitor. (They also complicate legal actions against spyware companies, as the sidebar "Is Spyware Legal" explains.) A typical EULA, such as the one that comes with DashBar, is 12 pages and grants the publisher the ability to "occasionally install and/or update software components," among other rights. Drive-by and silent downloads almost never present EULAs and therefore represent a greater risk to organizations because their publishers make no commitment about the rights and limitations of the software.
Understand the Risks
Would you let end users randomly establish VPNs to remote organizations without your knowledge and approval? If your answer is "No!" but your organization doesn't have policies or infrastructure in place to prevent spyware, you might be surprised by the real risks to which you're open. Table 1 lists these risks and their relative likelihood (which might vary from business to business). Of these risks, the two most misunderstood are reduced security posture and increased bandwidth usage. If you need a reason to get approval for preventative measures, the following information might come in handy.
Reduced security posture. Each time a system on your network becomes infected with spyware, the overall security of your organization is compromised. Spyware often runs with administrative-level privileges to systems on which it is installed, giving it the ability to communicate on the network and download and install software. The only limitations of these escalated privileges are those imposed by the spyware publisher. In addition, many types of spyware directly alter the security settings of the affected system to better enable the spyware's operation or to prevent its removal. Some spyware adds sites to Microsoft Internet Explorer (IE's) trusted zone, alters Web browser security settings, adds entries to a HOSTS file, or even disables antispyware and antivirus software. Even after you remove spyware, general configuration changes made to the system often remain, leaving the computer vulnerable to other spyware programs.
Increased bandwidth usage. All types of spyware use your bandwidth to communicate with remote systems. In lab tests, I found that each spyware product adds an average of two times the standard network traffic (e.g., for a system infected with 10 spyware products, 30KB of inbound/outbound traffic for a Google search averages 600KB of traffic). In one test, a system running only WeatherBug generated 133KB of traffic just by opening a Web browser to the default Google home page. Only 1.7KB of this traffic resulted from communication with the Google Web server; the rest was the result of communications between the system and two Web servers registered under different organizations (but both in fact representing the same spyware publisher).
Arm Yourself
By now you're asking, "How do you get rid of this stuff?" Unfortunately, no one product or technology can eliminate the risk of spyware within your organization. However, you can control spyware by establishing a defense-in-depth strategy that involves a combination of use policies, user education, and technology.
The typical foundation of such a strategy is often an acceptable use policy that defines what users can and can't do with their systems andmost importantlyestablishes penalties for not adhering to the policies. Typical policies cover Web browsing, downloading, and installing software. User education is often the next layer in your defensive strategy. Spyware can be confusing to IT administrators; it's often incomprehensible to end users. Still, given a proper education, many users can be taught the risks of visiting questionable Web sites, accepting ActiveX controls, or installing software from unknown or questionable organizations. Of course, no defense is complete without the help of the proper technology. Several categories of software can be used to fight spyware (see "Learning Path," page 62, for suggestions about where to find more information about some of these types of products):
- Content filtersContent filters at your network perimeter can prevent users from visiting sites that might represent a spyware risk and can prevent spyware from communicating with its publisher.
- Antivirus softwareNetwork- or desktop-based antivirus software can give you an early warning of certain malware, particularly Trojan horses and dialers.
- Antispyware softwareAntispyware software identifies, cleans, and prevents spyware from being installed on a system. Unfortunately, because of the speed with which new spyware is introduced and the relative immaturity of antispyware programs, no one product provides a comprehensive solution. As a result, many IT departments use two or more products in tandem to increase breadth of coverage.
- Desktop firewallsHost-based firewalls have traditionally been deployed only to mobile users but are becoming more common on desktops. Firewalls that regulate outbound connectionsnot including Windows XP Service Pack 2's (SP2) Windows Firewallcan reduce the risk of spyware by providing notification. Although knowing about spyware doesn't prevent a system from becoming infected, it can help you keep the spyware from performing its intended function.
- Patch-management programsSpyware often exploits security vulnerabilities in browsers to install itself on systems. Keep systems updated with critical system and browser security patches, by using either Windows Update or centralized patch-management solutions.
- Browser securitymanagement toolsTools that help you centralize the definition and management of browser security, such as the Internet Explorer Administration Kit (IEAK), let you lock down the security of your organization's Web browsers and prevent drive-by downloads.
A Real and Present Danger
Spyware in all its formsadware, snoopware, and malwarerepresents a real and present danger to businesses, in the form of increased security and legal risks. Understanding what spyware is, how it gets on your systems, and how it can negatively affect your business is an essential part of developing a strategy to protect your organization.
End of Article