|
|
Malicious online ads have plagued the Web for some time, but a series of recent eventsfrom an attack targeting NYTimes.com in September to a number of civil lawsuits filed by Microsofthave turned the spotlight on the problem once again.
Among the groups fighting all this is Google. Earlier this year, the company redesigned the site Anti-malvertising.com to add more educational content to supplement a custom search engine designed to help ad network customers conduct quick background checks. As part of Cyber Security Awareness Month, Google has issued a number of tips to help users and Web publishers alike.
|
|
|
|
- Know Who You're Working With
Publishers should research the domain names of ads' click-through URLs, as well as the domains for advertisers' and agencies' companies. If a domain was registered recently, the domain registrant's name and contact information is hidden or false it should send up red flags. - Secure Partners
Publishers should be aware that different ad networks and exchanges may have significantly different standards for malware detection, Google said, adding the company strongly advises against using networks or exchanges without strong anti-malware security measures in place. - Perform Comprehensive Q&A on Ad Content
Sites such as Wepawet and Adopstools should be used to scan Adobe Flash Player, JavaScript and PDF files before they are allowed to run. Test each core creative and all files the creative's code invokes, and use SWF-to-XML converter to detect references made from each SWF file. If the converter fails with an error, treat the creative with suspicion, Google advised. - Proper Planning
Having a strong response plan in place is important to ensure a quick reaction to a threat, Google said. - Fake Anti-Virus
Rogue anti-virus scams are a common threat on the Web. Such operations often pull in significant profits by tricking users into paying for software that does nothing, and malvertising often figures into such schemes. An example of this is the recent attack targeting visitors to NYTimes.com. To avoid this, Google suggests users research a company's reputation before downloading its software or visiting its site. - Follow Standard End-User Best Practices
This includes making sure your browser, operating system and anti-virus are fully patched. Google also urged users to exhibit caution when they are prompted to download an e-mail attachment, follow an instant message link or install a plug-in or unfamiliar piece of software.
|
xڽ;ks8_e'RĪk"%Օ$!cee&$2sU"F kt>$=R#ɶɘqnq[] mj5^qW~]/d4[xQ3%]iaL}?_NAydy9LhԄ?`B`uE4 zh!ΈR!;%KnoRWP2Iبk9q@ $,Z03fҏ|qhMQDʸ8٬5|zq
OGz2VD
t6cNssCL8.OQ8VO=V9e~@5B,*@9 TH;lvg.~
"FN$d[m$ɦ461R%\wtE!c+Oq"BCֵP^m-&XN0[ڙ7Q Q[t̄фD8q0*+ bz|v+
>̱D,˺mU}"C mNi2"2kp?Lx4
&:i鸉r(\A'w@\E;Y+>p2 HTLhQڒ x
`ic9{ Q}J%&zXƐ!ol5RV v5wBɠ5қ!b cCې?PzE¨ح)_l^^x,yJY]l (ZENB ƩʠZԧ )رTHYxh9"|ZLŎ= Qj5\pZH3M˿kEUӁu.8OQZd~sTJ~KF#`
vc_Aʁ֝:BO҈Θtw)M.%jS1H-TK /(}i1xCتAs%: KUIyI#OTS%[ ;eyr~xjh}RN/ႏ݇2.ˬuxS$}U}:ޫQeT4LSpt'*!X^r7V0lR5V]oY 0"7dTm
8S ?"6J#2oA8]T:FӋpOg潀H R\;Se_j1^mud#EO˘`\hΉseK, UD*{x
]X@I -S\ |