Anti-spyware at the Gateway

Mar 07, 2006 81 Replies

Then in that case you should know why companies use things like white/blacklists and filter access to the internet etc.

Jason

How do you know I am not a business owner, in charge of IT services..etc

Why don't you hire people that you trust? Or learn to manage people in otherways besides hiding behind technology.

I am not saying open the door. There are certain obvious sites to block p*rn,ebay...etc. I also agree there are plenty of employees wasting time if you have those sites open. It is foolish, however to think that if you block those sites you somehow turn these people into productive employees.

-Barry

It was an observation based on your position on filtering/content restrictions for workers. I've not found one manager that has workers with internet access that would disagree with locking them out of non- business oriented sites.

The general rule, in anything, is hire people you think you can trust, check on them from time to time, give them a good workplace and safe, and remove any threats to productivity.

After 30 years of being a worker, 20+ years of being a manager I can assure you that even trusted people screw around on the net and cost the company time/money in doing so.

If you don't believe the above, then you're either just another of those unethical workers that believes the man owes him something, or your abusing the system yourself.

If they were ever going to be productive, blocking the freely open internet will return productivity. As I said in another post, there are some that will not be able to stop complaining, which brings down the team/office, and they have to be fired (after a warning). In general, in every company/office we've implemented this, overall productivity has increased in very measurable ways.

In a company I worked at years ago, before category blocking products were really viable, we had a very clear usage policy that most people ignored.

So, I set up a semi-public system where any manager could view the activities of anyone else -- destinations and byte counts. It was all clearly stated as work resources to be used for work purposes and that everything can and would be monitored at all times, in the AUP.

It was incredible how our fully saturated T1 that we were about to spend a very large sum to upgrade (wasn't easy in those days to get beyond T1 where we were) went to an average peak use of 256k in only 2 weeks. Developers were estatic, the time it took them to push out new builds of our product to field machines was cut down to one quarter of previous, and our VPN worked faster than ever.

People were free to do personal surfing etc, just like personal calls. Only now they were actually accountable for it.

People that don't pay attention to what is going over their wires, have no idea...

-Russ.

One nice, expensive lawsuit from somebody you thought you were managing will cure you of not hiding behind technology that could have prevented it, or at very least the capacity to win the case convincingly.

-Russ.

I know, why companies like filtering. I really don't understand, why someone wants to have whitelist filtering. Then you don't need Internet access for your staff at all.

Yours, VB.

Your point is well taken, managing data this way does not magically turn bad employees into good ones. But, it takes away many of the very easy, quick anonymous avenues they have to stray off the track. And also avoid potential liability or other legal issues. While at the same time freeing up your bandwidth and probably reducing your spyware problem too.

-Russ.

I'm calling whitelist filtering nonsense. I'm not calling filtering nonsense in general.

Don't detract from the topic, please.

Yours, VB.

No one uses JUST white lists, the smart ones use category, white, black lists together.

Webwasher by Cyberguard is an excellent product.

formatting link

Of course, this is understood by anyone that understands what Websense (the OP's chosen solution) can do.

-Russ.

If you whitelist by category, you can give rather broad access while still keeping it to the purposes of business or at least business plus harmless personal areas. Websense makes this possible and feasible. At the same time you can block the categories found under the broad headings of "potential liability", "potential security risk" and "potential resource waste" for example.

-Russ.

This does not work at all.

I doubt that. If one single site remains reachable, which supports proxying or even inline gatewaying, then this will not work at all. And there are so many sites, that it is very unlikely, that whitelist filtering in such a way will ever work.

There is no such thing like a categorization of harmless web sites.

Waste. Yes.

"Don't try to solve social problems with technical means. It will not work."

Yours, VB.

And it is completely nonsense. I never saw such a network which was configured this way, that ever detered me from getting arbitrary connection out for longer than two minutes.

This is not too surprising, if one sees the fact, that tunneling can be implemented very easily.

Yours, VB.

Now you sound like Charles Newman - on a properly configured network, properly protected, you would not be able to get out, proxy or tunnel, neither would work. Keep up with the FUD.

Yes it does, it works for what it's designed for.

And since the proxy that most users would be using would not be available, it means that they would have to spend days trying to find one that works, if there was even one they could reach.

This is the first completely true thing I've seen from you.

In many cases, social problems ARE solved by technical means.

On the network like that, that we monitor, we catch the people that do such tunnelling, and they are diciplined for breaching policy.

The rest of them surf around comfortably without risk of going offside of the policy, as technology helps enforce it.

Those that repeatedly try to get around it, show up in the logs as such (repeated denies), and get special "attention". Even your two minute attempt would garner you some special attention, now for deliberately attempting to get around the policies.

-Russ.

You cannot detect arberaty tunneling techniques.

A serious tunneling doesn't produce any log entries, as no implemented policy is violated.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required