SSL security leaves loophole for hackers

Companies need additional defences to tackle the problem, say experts

Written by Phil Muncaster

Many firms are unknowingly allowing hackers to send malicious code into their networks via Secure Sockets Layer (SSL) encrypted links because it cannot be detected by most intrusion-detection systems (IDSs), according to a leading web application security vendor.

Marc Shinbrood, chief executive of Breach Security, told IT Week that because IDSs can only read clear text HTTP traffic, there is a blind spot that firms need to eliminate by installing tools to decrypt SSL traffic as it arrives and then pass it on to be inspected.

“Hackers have been using SSL for years,” said Shinbrood. “But the amount of encrypted traffic over the last few years has increased to around 50 percent [of all network traffic], so it has become more of an issue.”

Nearly 200,000 public sites are protected by SSL, including online banking and e-commerce web sites, according to Breach.

Greg Day, security analyst at McAfee, said that if firms are aware of the problem they can place more detection sensors behind the SSL termination point or on the client, using hosted intrusion-prevention systems (IPSs).

"If it is your pipe we can actually decrypt and do real-time analysis," Day said. "But it's very easy for firms to overlook [this blind spot] – the problem is having false confidence; firms have to realise their IT security limitations and have layers of defence."

Breach's Shinbrood added that the main reason for enterprises to invest in tools for web application security is to reduce the risk of bad PR from data being exposed, and the resulting damage to brands and customer trust.

“Compliance with regulations is a necessary evil but it isn’t the driving force [for buying security tools],” Shinbrood said. “If you talk to IT security chiefs, their job is to keep the company off the front page of the Wall Street Journal, or from appearing in front of a government regulatory committee, or ha ving their customers doubting whether they should do business with them.”

But Shinbrood added that many firms are ignoring the risks of attack through the web application layer, which he said now accounts for around 80 percent of successful attacks.

Ofer Shezaf, chief technology officer for Breach, said awareness of web application security is steadily growing, prompting many firms to appoint an application security manager.

Tags:

reader comments

related articles

System to protect remote access at mid-sized firms

Network security vendor WatchGuard and access software vendor Citrix last week released a Secure Sockets Layer (SSL) virtual private network (VPN) system to protect remote access in mid-sized enterprises. 22 Aug 2005

 

Microsoft to purchase VPN security firm

Whale's Windows-based SSL software easier to integrate onto desktop and mobile platforms. 29 May 2006

Safer document sharing

Collaboration web service, Bee-me.com lets workgroups remotely share documents 22 Jun 2006

Vendors line up tools to boost WAN performance

Blue Coat and McData launch WAN accelerator appliances 21 Mar 2006

PineApp tackles zombie threat

Israeli security company adds ZombiCop to existing email and web security range 14 Mar 2008

Debian flaw exposes communications breakdown

A wake up call for open source developers, Gartner warns 28 May 2008

McAfee predicts 2008's worst security threats

Social sites likely to be big targets for cyber criminals 16 Nov 2007

related whitepapers

today's top stories

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

City in pressing need of skilled IT matchmakers

With the financial services sector plunging ever deeper into an M&A maelstrom, IT leaders are having their systems integration skills and due diligence expertise tested as never before 09 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Podcast imageAudio

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation