Is Your Organization at Risk? Key Security Threat Findings
The data for the analysis used in this Network Chemistry Wireless Threat Index report was gathered from the thousands of laptops running the RFprotect™ Endpoint product and the more than one million connections they made in offices, on the road, and in homes from May 2006 to November 2006.
Key comparisons with the previous report that was published in May 2006 show that:
- Wireless usage increased by 8.2 percent
- Potential VPN policy violations increased by 11.8 percent
- Attempts to create ad-hoc networks increased by 9.5 percent
- Connections to unknown APs increased by 8 percent
The data continues to highlight the fact that mobile devices are a serious security risk to organizations threatening their assets, data and ability to comply with industry and regulatory mandates. End users will inherently choose productivity over security and IT must transparently assure that the devices are being used in a safe manner that does not put the user or corporate data at risk. The reports can help organizations evaluate where they are at greatest risk, promote best security practices and prioritize investment in wireless security solutions.
Wireless Risk Profile
The data was analyzed to determine and report on the most significant risks and the likelihood that they would be exploited. The wireless risk profile chart describes the various types of wireless related threats that organizations and their endpoints face. The data represents the total percentage of endpoints that have experienced each type of threat. For example, 69 percent of all of the endpoints currently being protected by RFprotect Endpoint have or had the ad-hoc mode enabled.
Each of the risks represented in this chart is significant and can be defined in the following ways:
- Ad-hoc connection - the endpoint has attempted to connect to an ad-hoc network
- Unknown AP connection - the endpoint has connected to an AP which is not previously known
- Unknown Ethernet connection - the endpoint has connected to an Ethernet network which is not previously known
- VPN policy violation - the endpoint has attempted to send network traffic across a connection when a VPN should have been used according to policy
- Network bridging - more than one interface on the endpoint was connected at once, e.g. by being plugged into the corporate LAN at the same time as being connected to a wireless AP or ad-hoc wireless network
- No firewall protection - the endpoint is not running a software firewall
- No virus protection - the endpoint is not running virus protection software
Financial Services Risk Profile
A similar analysis was conducted specifically on data from financial services companies reflecting the leading indicators of wireless risk for that industry.
Another area of focus for the index is on the type of connections used by endpoints. The following chart describes the usage of different interface types that were used when endpoints made a network connection. The analysis shows that wireless is now the preferred method of connectivity. The prevalence of wireless usage highlights the importance of ensuring secure connectivity practices to avoid loss of corporate data and/or misuse of resources.
AP Connection
Ethernet Connection
A critical piece of information for network and security personnel to understand is whether connections are being made to known and or safe networks. The analysis in this component of the index covers the percentage of connections to authorized verses unknown networks. It shows that 44 percent of all wireless access point (AP) connections were with an unknown AP while 19% of all Ethernet connections were with an unknown network.
In addition, users frequently connect outside of the enterprise which expands the network perimeter and risk of data loss. When connections are made with unknown APs or unknown Ethernet networks there are a number of risks including lack of encryption, evil twin, man-in-the-middle and phishing attacks.