What is HTML Smuggling?
In modern web applications, most of the processing and rendering of web content occurs on the client-side (user’s web browser) rather than the server-side. This architecture allows for the dynamic, responsive and interactive web browsing experience you’ve come to know well, but it also introduces a security risk known as HTML smuggling.
Forcepoint ONE Demo: Remote Browser Isolation (RBI)
HTML Smuggling versus traditional security measures
Traditional antivirus software, Web Application Firewalls and other security solutions are often ineffective at combating HTML smuggling. This is due to the obfuscated nature of the malicious code, the fact it appears as a legitimate resource, and that it is often hidden from the server-side of security solutions.
Fortunately, Forcepoint Remote Browser Isolation (RBI) effectively isolates and prevents HTML smuggling attacks.
How Forcepoint RBI works:
- Isolation: Web sessions are executed in an isolated environment, effectively air gapping all executable code. This separation acts as a barrier and stops the payload from executing.
- Zero Trust: All websites are treated as potentially dangerous. As a result, all file downloads, even those found in safe sites, are prevented.
- Content sanitization: Forcepoint RBI removes any unnecessary code from the web session without any interference or interruption to the end users’ web browsing experience.
- Disposable sessions: Since Forcepoint RBI executes each web session in an isolated environment, the isolated container is torn down and all web session data, including malware, is destroyed once the user terminates the session.
How Forcepoint Remote Browser stops HTML Smuggling:
- Prevents direct access to local resources: If malicious code is smuggled into a user's browser or the user accidentally executes malicious code via drive by downloads or click-less malware, the malware is prevented from reaching local resources, such as files and sensitive data due to the session being isolated.
- Eliminates cache manipulation: HTML smuggling relies on manipulating browser caches to deliver the payload. Forcepoint RBI stops this attack vector by entirely bypassing the local browser cache. In case the code manages to compromise the cache, no harm will come as it will be contained in the isolated environment.
- Reduces the attack surface: Limit the potential entry points and vulnerabilities hackers can exploit. The more of the web you isolate with Forcepoint RBI, the smaller the attack surface is for your organization
Watch this video to see how easy it is to implement Forcepoint RBI in under one minute: