Despite the hype ‘encrypted’ does not equal ‘safe’
Blue Coat Systems has published research results that show that the growing use of encryption to address privacy concerns is creating perfect conditions for cyber criminals to hide malware inside encrypted transactions, and even reducing the level of sophistication required for malware to avoid detection.
The use of encryption across a wide variety of websites — both business and consumer - is increasing as concerns around personal privacy grow. In fact, eight of the top 10 global websites as ranked by Alexa deploy SSL encryption technology throughout all or portions of their sites. For example, technology goliaths Google, Amazon and Facebook have switched to an ‘always on HTTPS’ model to secure all data in transit using SSL encryption.
Business critical applications, such as file-storage, search, cloud-based business software and social media, have long-used encryption to protect data-in-transit. However, the lack of visibility into SSL traffic represents a potential vulnerability to many enterprises where benign and hostile uses of SSL are indistinguishable to many security devices. As a result, encryption enables threats to bypass network security and allows sensitive employee or corporate data to leak from anywhere inside the enterprise.
Revealing the visibility void
As Blue Coat’s latest security report, ‘2014 Security Report – The Visibility Void’ explains, encrypted traffic is becoming more popular with cyber criminals because:
The growing use of encryption means that many businesses are unable to track the legitimate corporate information entering and leaving their networks, creating a growing blind spot for enterprises.
“The tug of war between personal privacy and corporate security is leaving the door open for novel malware attacks involving SSL over corporate networks that put everyone’s data at risk,” said Dr. Hugh Thompson, chief security strategist for Blue Coat. “For businesses to secure customer data and meet regulatory and compliance requirements they need the visibility to see the threats hiding in encrypted traffic and the granular control to make sure employee privacy is also maintained.”
How to preserve security and privacy
Corporate security demands must be balanced with privacy policies and applicable compliance requirements. Because corporate policies and applicable compliance regulations can vary geographically on a-per organization and per industry basis, businesses need flexible, configurable, customizable and targeted decryption capabilities to meet their unique business needs. To help enterprises comply with their policy and compliance requirements while still combating threats hiding in encrypted traffic, Blue Coat has developed a list of key factors that IT security departments should consider when framing the issue within their organization. The full list of guidance is available in The Visibility Void report.
A new E-Guide is available for download at: https://www.bluecoat.com/etm-guide/. The E-Guide highlights:
•Date: 19th November 2014 • World •Type: Article • Topic: ISM