Advertisment

Tip to enhance web filtering and security

Web filtering that only blocks dodgy sites won't keep users safe from web-borne threats, warns Sophos Labs in a recently published blog

author-image
Sanghamitra Kar
New Update
ID

BANGALORE, INDIA: Web filtering that only blocks dodgy sites won't keep users safe from web-borne threats, warns Sophos Labs in a recently published blog.

Advertisment

In fact, Sophos Labs detects 20,000 to 40,000 malicious URLs every day-and 80pc of those are compromised legitimate websites.

Sophos Global Head of Security Research, James Lyne explains that cyber criminals can infect web users automatically via a drive-by download process that takes less than a second. "Most websites that use outdated techniques for web filtering are not able to do much to prevent these threats. Security appliances and policies which treat every website as the same and scrutinize it for the latest attack techniques will keep a staggering volume of malicious code from getting into your systems."

Sophos suggests three tips for better web security:

Advertisment

In addition to a URL filtering solution that blocks known malicious sites, make sure you perform deep scanning of web traffic as it's accessed to guard against compromised legitimate websites. Real-time reputation filtering protects you from new malicious websites as soon as they come online.

Make sure you're protecting users when they're outside your main office. A UTM can be a cost effective way to provide protection at local sites. For those at-home and traveling workers, use an endpoint security solution that integrates web policy enforcement and web content scanning directly into your laptops.

Keep the endpoints and software well-patched to protect against drive-by downloads that exploit vulnerable software and applications. Limit the number of Internet browsers, applications and plugins in organization to a standardized set and enforce their use as policy.

"Web filtering software and appliances provide additional protections they continuously monitor the database of websites to see if a site has been flagged for malicious activities and stops malicious code and executables before they reach users desktop," says Vinod Kumar, managing director at Satcom Infotech.

tech-news security