Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


March 2005

Put a Stop to Spyware

Learn how to recognize and get rid of this modern-day scourge
RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Is Spyware Legal?

Watch Your Back
So how does spyware get on your systems? Such programs are typically installed through the following means:

  • Free utility software—Numerous free utilities are written specifically as delivery mechanisms for spyware. These programs are one of the most common sources of spyware and include software to block popups, manage calendars, synchronize clocks, find bargains on the Internet, give real-time weather updates, and view online greeting cards.
  • Bundled software—Sometimes a software company that wants to generate additional revenue from its software will partner with a spyware company.
  • Licensed software—Snoopware is often installed through standard licensed software.
  • Drive-by download—Spyware that exploits low browser or application security settings can affect a system when the user visits a Web site, views a popup advertisement, or reads an HTML-enabled email message.
  • Silent download—Once installed, some forms of spyware will install new spyware. Because spyware typically has escalated privileges on the affected system, new spyware installations or upgrading of the existing spyware is common.

Spyware distributed by free, bundled, or licensed software typically comes with an End User License Agreement (EULA) that the user must accept before installation. These EULAs often provide detailed information about what rights the user is granting the spyware publisher and what activities the publisher might monitor. (They also complicate legal actions against spyware companies, as the sidebar "Is Spyware Legal" explains.) A typical EULA, such as the one that comes with DashBar, is 12 pages and grants the publisher the ability to "occasionally install and/or update software components," among other rights. Drive-by and silent downloads almost never present EULAs and therefore represent a greater risk to organizations because their publishers make no commitment about the rights and limitations of the software.

Understand the Risks
Would you let end users randomly establish VPNs to remote organizations without your knowledge and approval? If your answer is "No!" but your organization doesn't have policies or infrastructure in place to prevent spyware, you might be surprised by the real risks to which you're open. Table 1 lists these risks and their relative likelihood (which might vary from business to business). Of these risks, the two most misunderstood are reduced security posture and increased bandwidth usage. If you need a reason to get approval for preventative measures, the following information might come in handy.

Reduced security posture. Each time a system on your network becomes infected with spyware, the overall security of your organization is compromised. Spyware often runs with administrative-level privileges to systems on which it is installed, giving it the ability to communicate on the network and download and install software. The only limitations of these escalated privileges are those imposed by the spyware publisher. In addition, many types of spyware directly alter the security settings of the affected system to better enable the spyware's operation or to prevent its removal. Some spyware adds sites to Microsoft Internet Explorer (IE's) trusted zone, alters Web browser security settings, adds entries to a HOSTS file, or even disables antispyware and antivirus software. Even after you remove spyware, general configuration changes made to the system often remain, leaving the computer vulnerable to other spyware programs.

Increased bandwidth usage. All types of spyware use your bandwidth to communicate with remote systems. In lab tests, I found that each spyware product adds an average of two times the standard network traffic (e.g., for a system infected with 10 spyware products, 30KB of inbound/outbound traffic for a Google search averages 600KB of traffic). In one test, a system running only WeatherBug generated 133KB of traffic just by opening a Web browser to the default Google home page. Only 1.7KB of this traffic resulted from communication with the Google Web server; the rest was the result of communications between the system and two Web servers registered under different organizations (but both in fact representing the same spyware publisher).

Arm Yourself
By now you're asking, "How do you get rid of this stuff?" Unfortunately, no one product or technology can eliminate the risk of spyware within your organization. However, you can control spyware by establishing a defense-in-depth strategy that involves a combination of use policies, user education, and technology.

The typical foundation of such a strategy is often an acceptable use policy that defines what users can and can't do with their systems and—most importantly—establishes penalties for not adhering to the policies. Typical policies cover Web browsing, downloading, and installing software. User education is often the next layer in your defensive strategy. Spyware can be confusing to IT administrators; it's often incomprehensible to end users. Still, given a proper education, many users can be taught the risks of visiting questionable Web sites, accepting ActiveX controls, or installing software from unknown or questionable organizations. Of course, no defense is complete without the help of the proper technology. Several categories of software can be used to fight spyware (see "Learning Path," page 62, for suggestions about where to find more information about some of these types of products):

  • Content filters—Content filters at your network perimeter can prevent users from visiting sites that might represent a spyware risk and can prevent spyware from communicating with its publisher.
  • Antivirus software—Network- or desktop-based antivirus software can give you an early warning of certain malware, particularly Trojan horses and dialers.
  • Antispyware software—Antispyware software identifies, cleans, and prevents spyware from being installed on a system. Unfortunately, because of the speed with which new spyware is introduced and the relative immaturity of antispyware programs, no one product provides a comprehensive solution. As a result, many IT departments use two or more products in tandem to increase breadth of coverage.
  • Desktop firewalls—Host-based firewalls have traditionally been deployed only to mobile users but are becoming more common on desktops. Firewalls that regulate outbound connections—not including Windows XP Service Pack 2's (SP2) Windows Firewall—can reduce the risk of spyware by providing notification. Although knowing about spyware doesn't prevent a system from becoming infected, it can help you keep the spyware from performing its intended function.
  • Patch-management programs—Spyware often exploits security vulnerabilities in browsers to install itself on systems. Keep systems updated with critical system and browser security patches, by using either Windows Update or centralized patch-management solutions.
  • Browser security–management tools—Tools that help you centralize the definition and management of browser security, such as the Internet Explorer Administration Kit (IEAK), let you lock down the security of your organization's Web browsers and prevent drive-by downloads.

A Real and Present Danger
Spyware in all its forms—adware, snoopware, and malware—represents a real and present danger to businesses, in the form of increased security and legal risks. Understanding what spyware is, how it gets on your systems, and how it can negatively affect your business is an essential part of developing a strategy to protect your organization.

End of Article

   Previous  1  [2]  Next  


Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Interact! Take our spyware Instant Poll

Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Windows 7 Sets Sales Record

Microsoft CEO Steve Ballmer described Windows 7's first ten days of sales as "fantastic" while in Japan yesterday. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events WinConnections and Microsoft® Exchange Connections

Deep Dive into Windows Server 2008 R2 presented by John Savill

Cutting Costs with Client Management

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement