RSA: Social Networking Security Has Way to Go

執筆者
Brian Prince
Brian Prince
Published: Mar 4, 2010
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

From Koobface to spam to fake Facebook Fan pages, attacks targeting social networks are evolving to bring a new level of insecurity to an enterprise.

In his presentation Wednesday at the RSA Conference in San Francisco, Sophos Senior Technology Consultant Graham Cluley detailed some of the common types of attacks and what needs to be done about them. The attacks spanned from instances of phishing to incidents involving assumed identities, such in one scam where someone created a fraudulent Facebook Fan page for Cluley himself.

“When you’ve got a big enough orchard, there’s going to be some bad apples,” he told the audience.

The attacks work, of course, because people are more trusting of information that appears to be coming from people they know, he said. In a test, researchers created two Facebook profiles – one with a rubber duck as the profile picture and the other one with a cat – and sent out 100 friend requests to people in the same age group as the bogus account holders.

What they found will probably be unsurprising to most security pros – more than 40 percent of the people requested accepted the invites from the fictitious accounts.

“It was actually slightly worse with the cat…because we had people we hadn’t even approached decide to become friends with us, because they (saw) their other friends become friends with us,” Cluley said.

Such tricks can be used to lure users into clicking on malicious links or other content as well. For that reason, social networks need to do a better job of scanning for malicious content, Cluley said. With more people using Facebook instead in place of regular e-mail, users need to get the same level of malware scanning that would expect from their webmail services, he said.

“We need to the social networks to scan that kind of information…there’s too much relying on the users to report bad actors,” he said.

Social networks have their work cut out for them. In a recent survey of 502 IT pros, Sophos found more than 33 percent had received malware through a social networking site.

Facebook cut a deal with McAfee recently to add another layer of security for its users. Last month, the companies announced a deal McAfee would offer the owners of compromised Facebook accounts a free remediation tool, and Facebook users were offered a complimentary six-month subscription of McAfee software.

Advertisement

Noting that many businesses have chosen to ban social networks, Cluley suggested enterprises instead consider educating their employees about social engineering risks, as well as other best practices such as not using the same password for multiple sites.

“Just remember – just because someone says they’re you’re friend, doesn’t mean they necessarily are,” he said.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。