Network Security & Hardware - eWeek

Network Security & Hardware: Google Offers Six Tips to Stop Malicious Online Ads


Malicious online ads have plagued the Web for some time, but a series of recent eventsfrom an attack targeting NYTimes.com in September to a number of civil lawsuits filed by Microsofthave turned the spotlight on the problem once again.

Among the groups fighting all this is Google. Earlier this year, the company redesigned the site Anti-malvertising.com to add more educational content to supplement a custom search engine designed to help ad network customers conduct quick background checks. As part of Cyber Security Awareness Month, Google has issued a number of tips to help users and Web publishers alike.
 
  • Know Who You're Working With

    Publishers should research the domain names of ads' click-through URLs, as well as the domains for advertisers' and agencies' companies. If a domain was registered recently, the domain registrant's name and contact information is hidden or false it should send up red flags.
  • Secure Partners

    Publishers should be aware that different ad networks and exchanges may have significantly different standards for malware detection, Google said, adding the company strongly advises against using networks or exchanges without strong anti-malware security measures in place.
  • Perform Comprehensive Q&A on Ad Content

    Sites such as Wepawet and Adopstools should be used to scan Adobe Flash Player, JavaScript and PDF files before they are allowed to run. Test each core creative and all files the creative's code invokes, and use SWF-to-XML converter to detect references made from each SWF file. If the converter fails with an error, treat the creative with suspicion, Google advised.
  • Proper Planning

    Having a strong response plan in place is important to ensure a quick reaction to a threat, Google said.
  • Fake Anti-Virus

    Rogue anti-virus scams are a common threat on the Web. Such operations often pull in significant profits by tricking users into paying for software that does nothing, and malvertising often figures into such schemes. An example of this is the recent attack targeting visitors to NYTimes.com. To avoid this, Google suggests users research a company's reputation before downloading its software or visiting its site.
  • Follow Standard End-User Best Practices

    This includes making sure your browser, operating system and anti-virus are fully patched. Google also urged users to exhibit caution when they are prompted to download an e-mail attachment, follow an instant message link or install a plug-in or unfamiliar piece of software.
xڽZ[s۸~~d_nw7ŗXbwIHB ,JVeSjy|8oi&4oAuB>K9lHbc.!KvfzC7o``ƛVYQ|v$UK*7-;RLDL1OwҨxLO^>.B࿎F:|=F#mX021q #yF.#An{R7Yh[((6j{A،LQLDruzH&$fvȿ+|>o~QLg\M<4#9 "L7'f*Ή{'_tt6g4Wln(3сױ1,?ۈnS3aܰ)M)vtZ4ܪwP臑WhNdm\)I;-<><:1)+Vʢ M&x9tKS:f:bLÃnF1>PC ';!{0#p\V5Ra5G\攪1O|؈{G{(a(;}eq+)P0nC-U̥zU\Ɋn'p` Ձ ^2R`-*T հq셜Þݙo&)?>d R_E!*aR= ׼>Iqv* .[1aCuTD,O4͌3Ky W&?׀c:sBrZ)ĺQĴdv-[9Ϛ 7s.9n ٝօrI/ ah~I%_zlgŎvjf]ffSO0[h>\ !I$STؖN ik'?aWyQq& XR?Ó,)uN~t@|@>c/1)rd|>s\MbSH;{$+}7icqD8 +9 (< ^0ZV {7VeLt"dY> "6#h9p\+ɻtqO@"f.[㑙CB0e_.Ն^ovﶍ#+𫄐Х$^Xr:= vA͘wsN%!JfI+knsqeQapS#Z7>g67c 3O#$vjڧDw% vӂֽWˆלWestOuO~)\9c.4ga-q a cp+)=jѤ:>*7p}SUA^8/VK@V ncFјfTT>g_Y#xO3+(XP.u1sgֽ]0? V|țjUxמo4g{l qEig`oiXI%k#׉x`+,B!S]OLmSgNVӪ2讞]BU:m-.U3g`GG*ar;LmTkqء9j[Xo2cQ JvV_ܔ&˼C]`I`z#p7PD'RMApuPy#y&յy8$Pc.kEb oDz j*cnW~#Z3H䈘 M؞(.D-bt7")th8ɗn &5 ;όF)xp98R.'2]([yw~ޑZuU )RX^c݆̪f;OY*@Λ5`(3<>яv&NXyB)@ SPpxdMADfTaz8ak`9 &*nZS4,PB qٓu"fˆI^KerDdT!Ǫl or AmkB Cs.)(iͩu ?YdbPds[6d$ͺ4X9X؅$ wwv3]»C.0x` acmA4sǑg,Rm.!?^>qL玩&G \01cX{}=+rx>qekZFEbp\|rvP~|x{/: L"s}{zap'xtOO{Wp QXa,m7:~y3Ne`)7}x/\t| Zh3Ow?7mXΊF+c+Ѩ~=ŴYI2UeTF,7vZFSƼ ܟ.^: w%16:tq@N㭲P ƫzD>,