Top five security risks for instant messaging in 2005
April 13, 2005
The rapid growth of IM has exposed organizations to numerous security risks, including threats from unmanaged and unmonitored IM and P2P usage.
The IMlogic Threat Center, the industry.s first global consortium to provide threat detection and protection for instant messaging (IM) and peer-topeer (P2P) applications, is publishing the Top 5 Security Risks for Instant Messaging in 2005.
These findings are based on research and analysis of reported incidents and events on the global IM networks as reported and tracked by the IMlogic Threat Center.
1. Blended Threats Include Instant Messaging
According to the IMlogic Threat Center, 4 of the top 10 most damaging Internet threats in 2004 used IM and P2P as a vector for infection. As both legitimate and unapproved use of instant messaging clients and peer-to-peer networking increases, new worms and viruses are increasingly using these mechanisms to spread. Though IM and P2P specific threats are growing at greater than 100% a year, a review of over 300 incidents reported to the IMlogic Threat Center suggests the most pervasive IM and P2P threats are incorporated into blended threats such as Netsky and MyDoom.
2. Identity Theft, Spoofing, and Phishing over IM
Few companies actualy know who has registered for names on their corporate domain. What would you do if you got an IM from your.boss@yourcompany.com? Organizations do not recognize their domains and identities are often abused.
3. Advanced Spyware and SPAM over IM
Few companies recognize that their employees may click on links inside of IM conversations that link to spyware and adware.
4. Information Security Leaks over IM
Most employees surveyed say they use IM because it circumvents IT security policy.
5. Targeted Attacks on Enterprise Domains
As organizations deploy enterprise IM, they will increasingly become targets for viruses, phishing attacks, and SPIM. Organizations will be broadcasting their identities to the Internet and welcoming. themselves to attacks without appropriate IM security infrastructure.