How safe is your incoming e-mail? With phishing, viruses, worms, Trojan Horses, spam, data storage challenges, disruption and downtime risks, data loss and leakage concerns and a host of other potential e-mail obstacles (is your head spinning yet?), it could be time to rethink your e-mail protection strategy.
The bottom line: you must safeguard your network in order to adhere to compliance mandates.
Amateur hour is over. Just when malware design seemed to have reached a plateau, new attack techniques have burst forth. Some are so complex they could have only been designed by means of sophisticated research and development.
We spoke about the challenges this type of malware presents with experts at a number of software security and threat-management companies, including Sophos, AppRiver, and IronPort Systems, now part of Cisco Systems.
For a time, one expert pointed out, security controls designed to manage malware were working. But, as a result of this success, the threats they protected against were forced to change. In 2007, many of these threats underwent significant adaptation. Malware went stealth, and its sophistication increased. E-mail is a primary vector.
“E-mail is a challenge from a security perspective because everybody’s doors are open,” said Pat Peterson, vice president of Technology at IronPort Systems. “Anybody who wants to deliver mail to your server and ultimately to the desktop can do so as long as the get through your anti-spam and anti-virus scans. That’s one of the fundamental and unique problems with e-mail compared to the Web or the telephone.”
The Network Administrator’s Responsibility
End users still fall for social engineering gimmicks that compel them to click on a link promising something interesting. That links ushers them to a Web site that downloads malicious payloads. It’s the network administrator’s responsibility to make sure that payload can’t make its way to the desktop and subsequently…