• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register | Login to Member's Area

 
 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • Information Process Quality Improvement
    19th March - 21st March
    London, United Kingdom
  • Convergence Summit North 2012
    17th April - 18th April
    Manchester, United Kingdom
POPULAR PAPERS
  • Best practices for cloud security by Bloor Research
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Famous Slights - "Lots of folks confuse bad management with destiny." - Kin Hubbard

PAGE TOOLS
  • Request Reprints
  • Tell A Friend
  • Contact Author
RECENT POSTS
  • Getting ahead in the cloud
  • Migrating to Exchange 2010 and email archiving options
  • Best practices for email archiving
  • What did IPv6 Day prove?
  • The security challenges of modern data centres
  • Whitelisting and change control for improving integrity
ADVERTISEMENT
BLOG ARCHIVE
  • January, 2012
  • November, 2011
  • October, 2011
  • August, 2011
  • June, 2011
  • April, 2011
  • February, 2011
  • January, 2011
  • December, 2010
  • November, 2010
  • October, 2010
  • September, 2010
Blogs > Bloor Security Blog

Why web security is best served in the cloud

Fran Howarth By: Fran Howarth, Practice Leader, Bloor Research
Published: 19th February 2010
Copyright Bloor Research © 2010
Logo for Bloor Research

Most business today is conducted electronically, with the internet a prime communications mechanism and resource for finding and sharing information. Yet its importance makes it a prime vector of attack for hackers that are looking to steal information for commercial gain. Because of this, malware threats are actually on the rise after years of tailing off. The 2009 CSI computer crime and security survey recently reported that malware attacks had been experienced by more than 64% of respondents in 2009, up from 50% in 2008, and making this the most prevalent type of attack seen.

Not only are attacks rising in number, but they are also becoming more complex and sophisticated. The number of variants of particular samples of malware is increasing dramatically and hackers are increasingly using blended mechanisms to make their attacks more effective, for example, using a combination of email and web exploits to increase their chances of success.

Traditional malware defences struggle to cope. Vendors struggle to write fixes for new malware variants as they come to light and end-user machines need to be regularly updated so that they have the latest protection. That can be an administrative nightmare if an organisation tries to handle web security issues in-house.

A better strategy can be to outsource the service to experts--and especially those offering software-as-a-service offerings based in the cloud. Such services are backed up by resource centres staffed with researchers who are constantly looking for the latest threats and scanning websites for potential exploits. By using advanced techniques, such as heuristics that look for particular behaviour associated with malware, rather than trying to fix a problem with a signature, so that previously unseen threats can be stopped in their tracks.

And the use of a service based in the cloud means that those threats can be stopped at there point where they are emanating from--the web--so that no exploits actually reach an organisation's network. This not only has the benefit of better protection against web-based threats, but can also mean lowered costs for the organisation as the service is delivered on a subscription basis, meaning there is no capital expenditure required on software licences and the hardware needed to run them.

This subject is discussed in greater detail in a series of papers, of which this is the first: The realities of web security

Reader Comments

Posted: 24th February 2010 | By HN :

This piece makes very little sense. Use of heuristics is ancient news in the AV sector, and the appeal to cloud as the malware answer ignores the obvious problem - these attacks are by and large aimed at end-user desktop PCs that will persist no matter how much business logic and application support you outsource. Is it the author's contention that my office somehow just has no systems left to target, post-cloud?

The messages above were all contributed by IT-Director.com readers. Whilst we take care to remove any posts deemed inappropriate, we can take no responsibility for these comments. If you would like a comment removed please contact our editorial team.

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.



  • Report errors / Make Suggestions
  • | Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761