Month: April 2018

How Does WebTitan Work?

TitanHQ’s WebTitan is a powerful web filtering solution that helps businesses control the web content that can be accessed by its employees, but how does WebTitan work and how can the solution improve an organization’s security posture?

Why Are Web Filters Necessary?

Many businesses choose to implement a web filtering solution to prevent employees from accessing inappropriate web content such as pornography or to stop work computers from being used to download illegal content such as pirated films, music, and TV shows. A category-based web filter allows businesses to block certain types of web content with ease, such as adult material and P2P file sharing websites.

While content filters can achieve those aims, perhaps a more important function of web filters is to block web-based threats such as malware and phishing websites. Many businesses choose to deploy WebTitan to block these threats, but how does WebTitan work?

How Does WebTitan Work?

WebTitan Cloud is a 100% cloud-based web filtering solution that serves as a semi-permeable membrane between an organisation’s users and the Internet. When an end user attempts to access a particular URL that does not violate an organization’s acceptable Internet use policy, the request is honoured. Since there is no latency, the speed at which the website is loaded is the same as if no filtering mechanism is in place.

Unknown to the user, when an attempt is made to access a webpage, the DNS request is sent to WebTitan Cloud which determines whether the request should be allowed or denied.

If the user attempts to access a gambling website and the gambling category has been blocked through WebTitan Cloud, the user will be advised that their request has been denied and access to the site will be prevented. But how does WebTitan work as far as malicious websites are concerned? How are malicious URLs identified and blocked?

How Does WebTitan Block Access to Malicious Websites?

How does WebTitan determine which URLs are benign and which ones are malicious, and how are those checks performed in real-time?

To block malicious sites, WebTitan uses a crowd-sourced approach and obtains a constant stream of URLs for analysis. These ActiveWeb URLs come from websites actively visited by a global network of customers through high traffic markets such as subscriber analytics, networks security, IOT, and ad tech.

This traffic is used to train WebTitan’s human-supervised Machine Learning Systems to detect, monitor, and categorize threats. Using in house and third-party tools, WebTitan performs link, content, static, heuristic, and behavioural anomaly analyses to categorize threats. When threats are detected, the WebTitan team profiles, tests and validates those threats. Once threats have been validated, they are blocked with false positives used to train the system to improve future accuracy.

In contrast to many DNS-based systems, which only work at the domain level, WebTitan works at the path level and is capable of blocking individual webpages rather than entire domains. The majority of malicious URLs in the WebTitan database are marked as malicious at the path level – 99.7% of IP-based URLs and 88.35% of non-IP-based URLs.

WebTitan performs checks of websites that have previously been marked as malicious to determine whether they still contain malware or other threats. The WebTitan Malicious Detection Solution revisits up to 300,000 sites to check whether they are still infected or have been cleaned, and the database is updated accordingly. Sites previously marked as malicious can be accessed once they have been determined to be safe.

What Web-Based Threats Does WebTitan Block?

There are ten main web-based threats that WebTitan protects against:

  • Malware distribution points
  • Ad fraud
  • Botnets
  • Spyware and questionable software
  • Phishing and other fraudulent sites
  • Command and Control (C2) servers
  • Malware call-home addresses
  • Compromised sites and links to malware
  • Spam URLs
  • Cryptocurrency mining

With WebTitan, businesses not only have highly granular control over the types of sites that can be visited by their employees, a wide range of malicious sites are also blocked, preventing malware and ransomware infections, data theft, data exfiltration and fraud.

You can view further information about WebTitan on this link. (PDF)

FAQs

How can the WebTitan web filter be deployed?

WebTitan Cloud is hosted in the TitanHQ cloud, although it is possible to host the solution in your own private cloud if you wish. WebTitan Gateway is a software solution that is deployed as a virtual appliance on customers’ existing hardware. If you are unsure what option is best for you, give the sales team a call and they will ask some questions and will recommend the best deployment option to meet the needs of your business.

Is WebTitan a good choice for MSPs?

TitanHQ is the leading provider of cloud-based cybersecurity solutions for MSPs serving the SMB market. TitanHQ considered the needs of MSPs at the design stage and ensured the product has all the features MSPs need. MSP-friendly features include multiple hosting options, easy integration into backend systems through a suite of APIs, you have the option of WebTitan as a white-label product, and you get dedicated account managers, flexible pricing, and generous margins.

How much does the WebTitan web filter cost?

WebTitan web filter pricing is totally transparent and there are no hidden costs. There are discounts based on the number of users and length of the contract, and we are sure you will find the pricing extremely competitive. The best bet is to contact us for an accurate quote; however, as a guide, the solution can cost as little as $1 per user, per month.

Does the WebTitan web filter provide a real-time view of Internet activity?

Yes. Through the reports options, it is possible to view Internet activity in real-time and drill down to see the web content that individual users are accessing. It is also possible to generate alerts when users attempt to access restricted websites and to schedule reports.

Is WebTitan suitable for Schools?

WebTitan is used by many schools to prevent students from accessing age-inappropriate content. WebTitan has highly granular controls for precision filtering, which ensures important educational web content is not blocked. The solution can be used to control the content that can be accessed on the school premises as well as protecting students when using school-issued laptops at home.

EITest Web-Based Malware Distribution Network Disrupted

A web-based malware distribution network that was redirecting around 2 million website visitors a day to compromised websites hosting exploit kits has been disrupted, crippling the malware distribution operation. The web-based malware distribution network – known as EITest – was using compromised websites to redirect web visitors to sites where exploits were used to download malware and ransomware, as well as redirect users to phishing websites and tech support scams that convinced visitors to pay for fake software to remove non-existent malware infections.

Due to the scale of the operation, removing the redirects from compromised websites is a gargantuan task. Efforts to clean up those sites are continuing, with national CERTs notified to provide assistance. However, the web-based malware distribution network has been sinkholed and traffic is now being redirected to a safe domain. Proofpoint researchers were able to seize a key domain that was generating C&C domains, blocking the redirects and re-routing them to four new EITest domains that point to an abuse.ch sinkhole.

The sinkhole has only been in operation for a month – being activated on March 15 – yet already it has helped to protect tens – if not hundreds of millions – of website visitors. In the first three weeks alone, an astonishing 44 million visitors had been redirected to the sinkhole from around 52,000 compromised websites and servers.

The majority of the compromised websites were running WordPress. Malicious code had been injected by taking advantage of flaws in the CMS and plugins installed on the sites. Vulnerabilities in Joomla, Drupal, and PrestaShop had also been exploited to install the malicious code.

The web-based malware distribution network has been in operation since at least 2011, although activity increased significantly in 2014. While previous efforts had been made to disrupt the malware distribution network, most failed and others were only temporarily successful.

The malicious code injected into the servers and websites primarily redirected website visitors to an exploit kit called Glazunov, and to a lesser extent, the Angler exploit kit.  Those exploit kits probed for multiple vulnerabilities in software to download ransomware and malware.

The threat actors behind EITest are believed to have responded and have attempted to gain control of the sinkhole, but for the time being those efforts have been thwarted.

How to Improve Security and Block Web-Based Malware Attacks

While it is certainly good news that such a major operation has been disrupted, the scale of the operation highlights the extent of the threat of web-based attacks. Spam email may have become the main method for distributing malware and ransomware, but organizations should not ignore the threat from web-based attacks.

These attacks can occur when employees are simply browsing the web and visiting perfectly legitimate websites. Unfortunately, lax security by website owners can easily see their website compromised. The failure to update WordPress or other content management systems and plugins along with poor password practices makes attacks on the sites a quick and easy process.

One of the best cybersecurity solutions to implement to reduce the risk of web-based attacks is a web filter. Without a web filter in place, employees will be permitted to visit any website, including sites known to host malware or be used for malicious purposes.

With a web filter in place, redirects to malicious websites can be blocked, downloads of risky files prevented, and web-based phishing attacks thwarted.

TitanHQ is the leading provider of cloud-based web filtering solutions for SMBs and enterprises. WebTitan Cloud and WebTitan Cloud for WiFi allow SMBs and enterprises to carefully control the website content that can be accessed by their employees, guest network users, and WiFi users. The solution features powerful antivirus protections, uses blacklists of known malicious websites, and incorporates SSL/HTTPS inspection to provide protection against malicious encrypted traffic.

The solution also allows SMBs and enterprises to enforce their acceptable internet usage policies and schools to enforce Safe Search and YouTube for Schools.

For further information on how WebTitan can protect your employees and students and prevent malware infections on your network, contact TitanHQ today.