tfh
Volume 17, Number 43 -- November 10, 2008

Web 2.0 Internet Apps: Spyware, Malware, and Trojans Galore

Published: November 10, 2008

by Timothy Prickett Morgan

While IT departments are understandably excited about the possibilities of so-called Web 2.0-style online applications and how they might be used within their organizations, these same IT shops are equally perplexed about how they are going to control and secure the use of these online applications among their end users.

In a way, this is an echo of how the commercialized Internet first entered corporations in the mid-1990s. And it did not enter from the data center, but from the end user desktops. And ditto for the wide use of PCs in the mid-1980s and then graphical user environments in the mid-1990s as Windows 3.X took off, now that I think about it. Sometimes, end users get way out in front of the IT department. But guess who gets to clean up the mess and support the technologies that have not been properly vetted yet?

FaceTime Communications, which sells a Web gateway security appliance that aims to add a layer of security to Web and collaboration software, commissioned a survey of over 500 IT managers and the employees at their companies (in North American and Europe) to assess the usage of collaboration, social networking, and other Web 2.0 applications such as those hosted by Google, Microsoft, IBM, and a host of others (pun intended) and the security risks these applications present. This is the fourth annual such survey that FaceTime has done, and the security situation is getting worse, not better, even as deployment of these applications within the enterprise (either officially or unofficially) is on the rise.

The data gathered from the survey is presented in a report entitled The Collaborative Internet: Usage Trends, Employee Attitudes and IT Impact, which you can read an executive summary of at this link.

The use of Web 2.0 applications is nearly universal now in some form or another at the companies surveyed, with 97 percent reporting they are using such software in their day to day business. That's up from an 85 percent penetration in the 2007 survey. Web conferencing, streaming audio, and Web-based email are the top such applications. Some 72 percent of employees say they are using Web conferencing now, up from 72 percent in the survey last year. IT managers reported that the number of Web 2.0 applications in use has quadrupled since the 2005 survey, and now a company, on average, has 9.3 different Web 2.0 apps being used in day-to-day business. Two-thirds of those surveyed said they had eight or more, so clearly there are some companies in the poll that have lots and lots of Web 2.0 applications to pull up the class average like that. A little more than half of the employees access social media sites at work each day, and 79 percent of employees use sites including Facebook, LinkedIn, YouTube, and such at work for business reasons. (Yes, I am laughing, and you probably are, too.) Some 74 percent of end users actually fessed up and said they use their PC at work for personal reasons, usually to look at personal email, to do personal banking, or to surf the Web.

Now, given what FaceTime does, you'd expect they were interested in how the use of these applications affect the security situation on corporate networks. As it turns out, some 73 percent of IT managers in the poll said they had at least one security incident relating to the use of Web 2.0-style apps. Among the larger companies polled--wait for the hook--IT managers project that it costs them, on average, $125,000 a month to cope with security remediation for Web 2.0 applications because of malware (viruses, Trojan horses, worms, and other nasties), spyware, data leakage, compliance, and other issues. The typical security issue takes 22 person-hours to remediate. The estimates above are based on a $70 per person-hour cost, and even midrange companies (presumably fairly large midrange shops) polled were reckoning a cost of $50,000 per month. IT managers polled reported an average of 34 security incidents relating to Web 2.0 applications per month. Companies with fewer than 100 employees had 10 incidents, on average, while those with 5,000 employees or more reported an average of 68 incidents. Clearly, being smaller doesn't help all that much, and that is probably a function of the more rigid network security and compliance framework at the larger companies.

This year was the first time that FaceTime asked questions about intellectual property and regulatory compliance issues, and found that 37 percent of IT managers said that these apps gave them compliance issues and another 27 percent said that these apps resulted in the unintended release of corporate data.


RELATED STORIES

IBM Rolls Out WebSphere and Web Enablement for i V7.0

WebFacing Lives On, in HIS and HATS

IBM Adds Web Services and SOA Tools to the System i

IBM Enhances Web Enablement Bundle, But for V5R4 Only

IBM Beefs Up Web Enablement for i5/OS Bundle



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
SEAGULL SOFTWARE

Need to update those green-screen apps?

Need a way to reduce training time for new users?

Need to bring back-office data to the Web for employees and customers?

Update your System i apps with LegaSuite GUI.

See how so many companies use Seagull Software to create GUIs from green-screens without any changes to their code. Watch a short, narrated demo today.

www.seagullsoftware.com/green


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

BCD:  Attend a Presto How To technical webinar, November 19
COMMON:  Join us at the 2009 annual meeting and expo, April 26-30, Reno, Nevada
Vision Solutions:  A $20 gas card for completing a short i5/OS DR survey

 

 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Linux Beacon
Why Blade Servers Still Don't Cut It, and How They Might

Intel Keeps Both Arms Swinging with Xeons, Jabs with Itanium

Microsoft Ponies Up Another $100 Million for Novell Linux

Mad Dog 21/21: Newtonian Economics

Two More Xeon-Based Galaxy Servers from Sun

Four Hundred Stuff
Seagull Unveils New LegaSuite Reporting Tool

Spectrum Manages 'E-Assets' with SCM Tool

ProData Expands Database Support in DBU

Micro Focus Works on COBOL Standardization, Training

Oracle Launches 'Best Practice Center' for SOA-Enabling JDE EnterpriseOne

Big Iron
For Some Customers, the Mainframe Is Green

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
OPNQRYF Has No "If" But You Can Fake It

Embed PJL Statements in a Workstation Customizing Object

Admin Alert: Avoiding Restoration Problems with Remote Output Queues

System i PTF Guide
November 1, 2008: Volume 10, Number 44

October 25, 2008: Volume 10, Number 43

October 18, 2008: Volume 10, Number 42

October 11, 2008: Volume 10, Number 41

October 4, 2008: Volume 10, Number 40

September 27, 2008: Volume 10, Number 39

The Windows Observer
Citrix Addresses Performance with XenApp 5

Server Buyers Shop Like It's 1999 in the Second Quarter

Intel Keeps Both Arms Swinging with Xeons, Jabs with Itanium

Mad Dog 21/21: Newtonian Economics

Microsoft Does Something About Those SQL Injection Attacks

The Unix Guardian
What the Heck Is the Midrange, Anyway?

Overseas and Notebook Sales Offset Printer Declines for HP in Q3

Two More Xeon-Based Galaxy Servers from Sun

Mad Dog 21/21: Newtonian Economics

Intel's Nehalems to Star at IDF, AMD Pitches Shanghai

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

BCD
PowerTech
Seagull Software
Maximum Availability
Minnesota Computers Corporation


Printer Friendly Version


TABLE OF CONTENTS
A Few More Strands in the DNA of the Midrange

The Winds of Change: How Presidential Politics Informs IT Transformation

Wholesalers Making Adjustments During Economic Storm

As I See It: Growing a (Non-Binding) Conscience

Tight Credit Squeezes IT Equipment Leases

But Wait, There's More:

Wherefore Art Though, O Power Blade Services for i? . . . Former IBMer Blocked from Taking Job at Apple . . . Web 2.0 Internet Apps: Spyware, Malware, and Trojans Galore . . . Agilysys Touts Cost Cutting Ahead of Financials . . . IBS Under Pressure in Q3, Divests Brasilian Unit . . .

The Four Hundred

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement