Skip to main content

How to lock down instant messaging in the enterprise.

Instant messaging (IM) is one of the most widely deployed Internet-enabled applications today. This huge user base is one of several reasons why IM applications are an obvious target for hackers. Another is IM's capability to transfer files, which makes it an effective medium for spreading malware. IM traffic also bypasses many firewall checks, as it can use any port to connect to IM services and is often embedded inside HTTP packets.

Like many Web-based applications, IM security is not keeping up with its rate of adoption. Enterprises must appreciate that the nature of IM-borne threats is substantially different to those that enter a network via email. The critical defenses that protect against email threats won't provide adequate protection against the growing array of threats that can enter networks through IM clients.

Here are a few defensive strategies that make sense when locking down instant messaging in the enterprise.

Monitor IM traffic
To control and monitor IM usage, it's necessary to monitor inbound and outbound traffic across all ports and protocols. Top-end Web security gateway devices can provide this type of multi-layered traffic inspection. Web security gateways offer the advantage of consolidating many security functions in a single device, protecting clients from the internal network threats they encounter while using the Internet. A Web security gateway also allows an administrator to set policy rules on one device, a far easier task than trying to enforce each policy across several different devices. This greatly reduces workloads particularly as there is only one interface to grapple with.

For those that go the Web security gateway route, ensure that it can integrate with the organization's identity and authentication management system, often Active Directory. This will allow the blocking of specific users or groups of users from accessing IM services.

Deploy an enterprise IM system
To really tackle the threats posed by IM, I feel there is a strong case for using an enterprise IM system. Real control is impossible if an organization allows employees to use IM software of their own choice. Bringing the instant messaging infrastructure in-house enables enforcement of policy rules, as well as monitoring, filtering, blocking and archiving traffic. None of the major instant messaging protocols encrypt network traffic, but an enterprise IM system can enforce the use of encrypted messages as well as authenticate users to the server. This will help ensure compliance with regulatory and corporate governance policies.

Create an IM acceptable-usage policy
Whether your organization deploys an enterprise IM server or a Web security gateway, it is vital to create and enforce an IM acceptable-usage policy. You can certainly base this policy on an existing email usage policy, as the framework will be similar. The IM policy though must address, additional areas, such as how file transfers are initiated.

Finally, as new services like VoIP are added to instant message software, it is as important as ever to keep your system and software programs patched and up to date. IM usage has become a must-have communications method in countless enterprises, and with a moderate investment of time and effort, there's no reason it can't be adequately secured.

About the author:
Michael Cobb, CISSP-ISSAP is the founder and managing director of Cobweb Applications Ltd., a consultancy that offers IT training and support in data security and analysis. He co-authored the book IIS Security and has written numerous technical articles for leading IT publications. Mike is the guest instructor for several SearchSecurity.com Security Schools and, as a SearchSecurity.com site expert, answers user questions on application security and platform security.

Comments

Popular posts from this blog

Want To Get Answering Machine For Your IM?

Computer's personal often face problems when they have to take a break from their PC for some time and can’t answer to emails and instant messages. Actually, for email you can set up an autoresponder if you use Outlook software, and there’s a way out for gmail, too. But what can you do with your instant messenger? I have a lot of IM accounts for any purposes with different people in each account. So what utility can tell these people that I am out on a vacation or down with fever? Answer.im comes to the rescue by setting up an automated web based answering machine for your instant messenger. It works with MSN, ICQ, AIM, Yahoo and Google Talk as of now. How it Works Setting it up is very simple. First, hop over to http://answer.im/. Then, select your IM network (like GTalk, Yahoo, etc). Fill in your username and password and hit Login. Features Now, you can customize your automated reply and select the status you would like your account to remain at. Since the service is web based, ...

Durov: The phone of the richest man in the world was hacked through WhatsApp.

The founder of "VKontakte" and Telegram Pavel Durov said that back in November 2019 he warned about the vulnerability of the WhatsApp application, through which hackers hacked the smartphone of the richest man on the planet Jeff Bezos. Durov wrote about it in his Telegram-channel. Earlier, the company Facebook, which owns WhatsApp, noted that the businessman's mobile phone was hacked because of vulnerabilities in the operating system from Apple. At the same time, Durov is convinced that the problem is not iOS. " WhatsApp in its marketing campaign uses the words 'end-to-end encryption' as a magic spell, which itself should ensure the security of all communications. But this technology alone cannot guarantee absolute confidentiality," says the founder of Telegram. One of the drawbacks of end-to-end encryption, he says, is that backups of transmitted data are often not encrypted. In addition, says Durov, each application has "ways around...

Primus to Provide VoIP for MSN Messenger

Primus Telecommunications Group, Inc. has entered into an agreement with Microsoft Corp. to provide Voice-over-Internet Protocol (VoIP) services for MSN Messenger Service customers. Marketed as "PrimusTalk," once a user has logged into MSN Messenger Service, calls can be made by clicking on the "Make a Phone Call" link. A phone dialer will appear where a call can be made to any number -- national, international or mobile. The McLean, Va.-based Primus will provide PrimusTalk service as an Internet telephony application that can be accessed by any user accessing MSN Messenger Service. Specifically, the PC-to-phone service will be integrated with the MSN Messenger Service as an option that may be accessed by users of Microsoft client software programs. "Primus is leading the way to a carrier class era of converged communications solutions," said John Melick, co-president of Primus and one of the principal developers and implementers of the company's VoIP ...