About Me

Kevin Beets

Kevin Beets

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Peer-to-Peer Goes Both Ways

Wednesday, November 4, 2009 at 1:09pm by Kevin Beets
Kevin Beets

We all know the dangers of peer-to-peer (P2P) networks and their role in distributing malware. Most people who deal with this problem work tirelessly to limit the impact of these potential threat points by (among other things) adding anti-virus, firewalling, watching network flows for P2P traffic, and usually outright banning of P2P applications.

They may, however, be looking the wrong way. The bits and bytes flow in two directions–in and out. Data leakage from a network is just as serious as bringing in malware-laden MP3s, cracked software, or Mov files.

You may be thinking to yourself, “Yeah, but leaking information is for disgruntled employees, or those looking to profit from foreign spies being ‘in the market’ for specific secret data. I don’t employ people who would do that.”

For arguments sake, let’s say that you do in fact employ workers who are of the highest moral character, you’ve firewalled the outside, banned the applications, monitor the network traffic, and updated your anti-virus signatures.

So what happens when one of your employees is out sick–yet a big presentation is still due on Friday? Any chance he or she may take work home to finish when “there just aren’t enough hours in the day”?

The vector does not even need to be company-owned. If an employee is emailed the presentation, or copies it onto a USB device, this is the time that the data is the most vulnerable–it’s out of your control. Most home users do not implement the same security practices that a company does. If that data is moved into a directory reachable by the P2P application, it is reachable by potentially millions of users on the same P2P network. Do you think a file called OurSecretFormula.doc would look enticing?

For those ever-present naysayers, here is a recent example of this occurring.

So the moral of this story is not that this is new or ground breaking–it certainly isn’t. It’s just a reminder to look both ways.

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (0)