If there is one certainty in the security business, it is that security professionals and hackers are in a constant battle to protect and exploit vulnerabilities.Hackers trying to gain entrance into enterprise networks, for example, have seen a host of robust solutions developed and deployed to stop them. While this wasn't always the case, the majority of enterprise networks deploy perimeter defenses, such as network firewalls or intrusion prevention systems, which are just a couple of the well-established solutions with a rich history of research and development behind them.
Opportunity 2.0 for enterprise hackers
Unfortunately, with the rise of social media, corporations are now quite vulnerable once again. Exploits in peer-to-peer software, social networking and instant messaging applications have companies suddenly getting slammed with an entirely new set of security problems.
What solutions are available to prevent these attacks?
Clearly, one of first things that enterprises should do is better educate employees about the dangers associated with client-side vulnerabilities and other areas of attacks, such as remote access.While there is currently no silver bullet that will stop all of these attacks, there is some very promising research going into host-based solutions. Solutions that can proactively solve problems like this before they become a threat are key to addressing these issues. One example is locking down a user's computer system with application-based access controls that can control what the application can and cannot do, so that even if an application were to be exploited, no harm is done. Additionally, verifying applications and device drivers before the system allows them to execute on the computer is a very sensible approach.It's likely that 2007 will be the year that many enterprises will have to come to grips with the new security problems resulting from social media and address them with the same energy, foresight and aggressiveness as they have other problems in the past.-Mark Zielinksi is security engineer and member of Arbor Networks' Security Engineering and Response Team.