Latest news
Zscaler released IPAbuseCheck, free web service which will allow them to query a dynamic ThreatLabZ database to identify whether any of their endpoint clients and IP addresses are being used for malicious purposes.Users who leverage the service will now be able to identify and clean-up compromised endpoint clients that are unintentionally participating in some form of Internet proxy abuse—including brute-force web logins, forum spamming, pay-per action cheating, open proxy scanning, DDoS attacks and web-site scraping.
The service combines a simple web interface with an extensive database that contains IP addresses that have attempted to forward abusive or unwanted traffic through one or more Zscaler cloud proxies.
Unlike other publicly available services and tools, IPAbuseCheck provides a different perspective on Internet abuse. Lists that track forum spamming and other types of Internet abuse, for example, often log the 'source' IP address from the perspective of the spammed web server. This approach, however, will often result in the identification of a source address that represents a proxy IP address that is being abused, as opposed to the actual infected client. IPAbuseCheck is different than standard blacklists in that the clients listed have specifically attempted some form of Internet abuse through one or more web proxies within Zscaler's global security cloud.
"Malicious or compromised clients leverage proxies to distribute and/or mask their origin when conducting forms of abuse," said Mike Geide, senior researcher at Zscaler ThreatLabZ. "We've seen so many IP addresses bang against our proxies hundreds of thousands of times the past few months, attempting to brute-force web logins. Yet, searching for these IPs against multiple blacklists does not identify them as being offensive. This new IPAbuseCheck service will provide another helpful resource to identify and clean-up compromised endpoint clients."
Client IP addresses listed in the IPAbuseCheck database include both those that are intentionally used for abuse and those that are from infected hosts that are unknowingly abusing proxies on the internet.
Zscaler's service provides policy and security enforcement through its proxies from its customers. Valid Zscaler customers must first authenticate to the Zscaler cloud before being able to use these proxies. Transactions listed in the IPAbuseCheck database are from non-authenticated clients attempting to utilize one or more Zscaler proxies in an open manner – as a way to distribute and mask traffic for their abuse.


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





