Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Cisco all but kills Cius tablet computer
Windows 8 Update: Steve Ballmer's 80-inch Windows 8 tablet
Gartner: Don't trust cloud provider to protect your corporate assets
Take me out to the ballgame, with 4G
Most OpenOffice users run Windows
Smartphones with quad-core chips and 4G LTE coming soon
Government alarm over cyberattacks validated by terrorists
Lawmakers call on DOJ to reopen investigation into Google Wi-Fi spying
Researchers propose TLS extension to detect rogue SSL certificates
IaaS: Renting on-demand technology
Yahoo Axis may be game changer for search and the troubled company
Android, Apple Own 80% of Global Smartphone Market; Microsoft's Share, 2.2%
Managing Mobile Mania
Proposed New York Legislation Would Ban Anonymous Online Comments
Supercomputer to connect to 400PB of storage via Ethernet
/

VPN vulnerability

Personal firewalls for remote users are recommended to protect the network from hack attacks.

Related linksToday's breaking news
Send to a friendFeedback

Tech InsiderIf you're extending a VPN to your remote workers, you need to keep in mind that those direct and sometimes always-on links into your corporate network are a prime target for hackers.

The explosion of the number of telecommuters means they're tapping into corporate budgets, strategic plans and engineering projects from PCs that are outside the firewall, constituting the weak link in your security defense system.


VPNs take center stage
VPN service providers
Trimble Navigation finds VPNs useful for remote access
Face-off: Build your own VPN or outsource?
Tips for getting remote workers secure
Archive of Network World features
Subscribe to our VPN e-mail newsletters

While this ever-expanding army of telecommuters may be doubling their work efficiency and slicing their drive time, they also may be opening thousands of opportunities for hackers, competitors and thieves to easily slip right into the heart of the company network.

"By and large, telecommuting security is not taken as seriously as it ought to be," says Ken VanWyk, corporate vice president and chief technology officer of Para-Protect, a security consulting and service firm in Alexandria, Va.

"It creates a major backdoor that most companies are not aware of. I'm not saying the sky is falling, but you seriously need to pay attention to these things," he says.

VanWyk and other security experts say most companies feel safe hiding behind a network firewall. Employees may be dialing into the system, but that firewall will keep any unwanted, prying eyes out.

Wrong.

Other network administrators still think they're safe if they wall their network with a firewall and give employees a VPN so they can safely dial in through an encrypted tunnel.

Wrong again.

"If I compromise your home computer, I can follow you right into the network," says Tim Belcher, chief technology officer of RipTech, a security consulting and service provider also in Alexandria. "Working from home is great, but from a security standpoint, it's a significant threat because most security software that companies are employing doesn't protect the home computer.... All someone has to do is hack into a home computer and follow them through an authorized connection."

Security experts and industry analysts agree that corporate firewalls help keep intruders at bay and VPNs safely encase information as it flows between the main office and the home office.

The trouble lies in the ability of an intruder to ride through that tunnel piggybacking on an entrusted user.

"The encrypted tunnel is safe. That link is fine," says Sammy Migues, chief scientist at Infrastructure Defense in Alexandria. "That doesn't mean [the home] computer itself is safe. It has a lot of vulnerabilities.... Once I get onto that home computer, it's almost a certainty that I could execute their VPN client software remotely. If you have to type a password, I could remotely log your key strokes or view your screen and then I would see everything you're seeing."

To get in to your home computer, hackers need to probe IP addresses. Analysts warn that the hacker's job gets easier if the home user has a constant live connection, such as a DSL line, which often has a static IP address. A dial-up connection generally has a different IP address with each connection and while that can also be hacked into, it's certainly more difficult.

The solution to the problem of vulnerable home PCs is to install a personal firewall on the home computer which will help keep intruders out of that desktop, as well as out of the corporate network.

"Statistics show that IP addresses used by dial-up services get scanned [by potential hackers] basically every day," Migues says. "If you got a DSL connection [midweek], I'd bet that you'd be scanned two or three times by the end of the weekend."

As the number of telecommuters continues to increase at Econometrics, a marketing data warehouse in Chicago, securing those off-site links will be a top priority, according to Brian McGuire, chief technology officer.

"I guess there's been a little part of me saying that nobody was listening in, but that's not good since it appears that there probably is [someone listening]," McGuire says. "We know the problem is coming. We know we're going to have to tighten up our security."

Tips for getting remote users secure
There are ways to shore up your remote workers so their connections into the network are a business advantage and not a security threat. Here are some tips from security experts:

  • All remote users should be mandated to use a VPN.

  • All remote users should have a personal firewall. It will not only protect the computer from invasion but also will tell you how many times the connection is being probed.

  • All remote users should have intrusion detection systems to provide an additional layer of information on break-in attempts.

  • the company's IT team should set up the home system instead of letting the user buy something, expense it and set it up themselves. That will give you the chance to take care of vulnerabilities and harden up the system.

  • Make sure that remote users are installing patches and software upgrades as frequently as users in the main office.

  • Computer policies in effect in the office also should hold the same for telecommuters and travelers. If company computers aren't to be used for personal use in the office, the home user shouldn't be surfing the 'Net or letting kids play games on the company system.

  • Monitor what software is being installed on the remote system and restrict it to business use only.

  • The IT team needs to check these systems with the same due diligence it does systems in the office, even if it means doing periodic visits.

  • The traveling worker needs to have sensitive files encrypted.

  • Install access control programs that will ask for a password and then alert an administrator via modem if that password is being put in incorrectly.

  • Traveling workers should be reminded not to leave computers in hotel rooms or cars. Don't let a system with a VPN into the company network out of your sight.

  • Traveling workers also should have multiple layers of security, such as screen locks and boot-up passwords.

  • When choosing a DSL provider, look for one that offers security capabilities.

Related links

Contact Features Writer Sharon Gaudin

Other recent articles by Gaudin

VPNs take center stage
Virtual private networks merge IP technology with encryption to offer significant cost savings on WAN traffic.

VPN service providers
There are plenty of options if you want to outsource your VPN.

Trimble Navigation finds VPNs useful for remote access
Employees find joy in setting up a VPN.

Face-off: Build your own VPN or outsource?
Indus River Networks' Dave Zwicker and Concentric Network's Mark Fisher face off.

Archive of Network World features

Subscribe to our VPN e-mail newsletter


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.