Commentary
USB And SMB Is A Risky Mix
Drive-based threats may pose a larger risk to your business than drive-by attacks -- and USB drives may pose the largest threat of all.Drive-based threats may pose a larger risk to your business than drive-by attacks -- and USB drives may pose the largest threat of all.Threats carried by USB drives, and brought inside your network by employees -- either deliberately or, more likely, in complete ignorance of the risk -- continue to worsen.
Panda reported recently that malware launched from USB drives accounted for a quarter of SMB infections last year.
More SMB Insights
White Papers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
Reports
More >>Webcasts
- Effective IT Inventory and Asset Management: From Quagmire to Quick Fix
- Maximize ROI with Database Consolidation onto Private Clouds
Big organizations are getting flash-drive slammed too, including the biggest of all -- a recently revealed 2008 attack on U.S. military networks was launched from a USB flash drive.
It's easy to see why the crooks are taking the USB route to your material. Flash drives are cheap, increasingly powerful and absurdly easy to use: plug in the drive and you're ready to go.
Unfortunately, with Auto-Run malware, the crooks are ready to go too.
The Pentagon's solution to its flash drive problem was to ban the drives for a year. Not a bad solution -- and one every business should consider, at least for as long as it takes to put into place a proper removable storage device policy and monitoring tools.
That policy should include:
Clear and straight forward delineations of what drives can and cannot be plugged into your system. In addition to flash drives, removable memory in cameras, phones, as well as music players and other USB devices should be included in the policy.
Auto-Run and Auto-Play should be disabled (although hackers are on the lookout for ways around even disabled auto-run features.
Under no circumstances should unfamiliar USB drives and devices be introduced into the network. Even if the drive comes from a seemingly reputable source, it can carry malware, as recipients of an infected IBM flash drive tchotchke learned to their dismay.
Finally, give some serious thought and budget consideration to implementing business-wide port and device monitoring. You and your security manager should know every time a device is introduced into a port, whether in compliance with your USB device policy or not.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
Research & Reports
SMEs and the Cloud: How Much Is Too Much?
This exclusive downloadable research report examines how outsourcing certain IT functions to a service provider can pay off for small and midsize businesses, even more than for large enterprises. But go too far into the cloud, and you may suffer in terms of maintaining agility and responsiveness to market forces.
Secure Design on a Dime: Our Top 5 Best Practices for SMEs
This exclusive downloadable research report details the security tools that small shops need, at a minimum, to prepare for the increasingly complex security and compliance environment that exists today and the top 5 ways growing businesses can stretch their IT budgets.
Current SMB Issue
- 6 Steps To Modern Data Center Architecture: A phased data center upgrade makes technical and financial sense. Randy George suggests six steps to follow.
- Manage Your Managed Service Provider: Michael A. Davis discusses strategies for how the make your MSP work for you.
- And much more!
SMB Whitepapers
- Building a Business-Ready Mobile Infrastructure
- Shared Storage for SMB Server Bundles
- No Compromise, Cost Effective, VMware Storage for the SMB
- Three unique technologies provide users with a truly modern storage experience
- Rethinking Backup and Recovery: Disk vs. Tape
- Server Room Solutions: How small to midsize IT businesses can make their IT budgets appear larger than they are
- Top Three Microsoft Exchange Concerns and EMC Solutions



