Home > Unified Communications Tips > > Instant messaging security essentials
Unified Communications Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Instant messaging security essentials


Joel Dubin
01.18.2008
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Instant messaging (IM) has proliferated for consumer and business use, and employees use it to communicate among themselves, and often with people outside the organization. It's affordable, easy to deploy, and increases worker productivity.

But that increased connectivity, if not configured securely, can come with a heavy price. IM allows viruses, Trojans and other malware to piggyback into your networks far easier than email attachments. IM messages can contain links to malicious Web sites, and confidential data can be compromised. Spam over IM (SPIM) is also a threat.

For more info:
Visit our resources page on unified communications security.

Read other articles on instant messaging (IM) and presence.

Thus, security for IM is essential. Here are some suggestions and best practices for securing IM without breaking the bank:

  • Designate one IM tool. For internal IM, make sure to use a single enterprise software application. More vendors are offering IM products for SMBs, such as IBM's Lotus Sametime. It installs on its own dedicated server, which is tucked deep inside your company's firewall. Harden that server as you would any other: limit access to authorized users, turn off unnecessary services, install antivirus software and keep patches up to date. Install the client piece of the product only on desktops that have been equally hardened with up-to-date antiviral protection and host-based firewalls.
  • Restrict external IM usage. Allow usage only for employees who have to communicate real time. Don't use consumer IM products from America Online, Yahoo Inc. or Microsoft. Use enterprise instant messaging (EIM) software such as Jabber or Akonix.
  • Make sure your EIM provider offers some kind of encryption. You can always encrypt with Secure Sockets Layer at no extra cost. Remember, IM messages are conventional HTTP traffic, whether the messages go over port 80 or not.
  • Restrict access. Like your internal IM servers, those hosting your EIM should be locked down with restricted access, hardening and updated patches and antiviral protection. They should be hidden behind your company's firewalls, but unlike your internal IM servers, they will need access to the Internet. Make sure to add rules to your firewall allowing access only to your EIM and blocking common ports for consumer IM products.
  • Restrict communication. Configure buddy lists on your EIM to restrict communication to only known and trusted parties. This will prevent a malicious user from trying to access your network via IM.
  • Log and monitor all IM traffic. This can be used to detect malicious inbound traffic, or inappropriate outbound traffic, like someone trying to send out confidential company data or files.

About the author:
Joel Dubin, CISSP, is an independent computer security consultant. He is a Microsoft MVP specializing in Web and application security, and is the author of The Little Black Book of Computer Security, available from Amazon.com. He also runs The IT Security Guy blog at http://www.theitsecurityguy.com.

This article originally appeared on SearchCIO-Midmarket.


Rate this Tip
To rate tips, you must be a member of SearchUnifiedCommunications.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Unified Communications Security
Security concerns for migrating from open source VoIP to UC
Security in a SIP network: Identifying network attacks
SIP network security measures
Security solutions for SIP management
Presence management and security
Complete guide to caller ID spoofing: Safeguarding your resources
Security considerations for unified communications
Alcatel-Lucent Forum: The Dynamic Enterprise
IM security threats and resources
Early adopters of unified communications need to ask about security

Instant Messaging (IM) and Presence
Is unified communications presence good enough?
Instant messaging (IM) tutorial
What UC is and isn't
Is the iPhone a good choice for my business?
Social media challenges reside with users, not technology
Presence management and security
Presence: SIMPLE versus XMPP
Integrating presence into the enterprise
ShoreTel beefs up UC offering for SMBs
SIP tutorial

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
instant messaging  (SearchUnifiedCommunications.com)
presence leveraging  (SearchUnifiedCommunications.com)
real-time communications  (SearchUnifiedCommunications.com)
real-time communications dashboard  (SearchUnifiedCommunications.com)
rich presence  (SearchUnifiedCommunications.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Communications Solutions for Business: Collaboration, Cell Phone Access, and IP Telephony
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts