Dark Alleys/Internet Security

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    1 Event

    Dark Alleys/Internet Security - Presentation Transcript

    1. Avoiding the Dark Alleys of the Internet Extension in the Connected Age NC Cooperative Extension March 24, 2009 Presented by Greg Parmer Alabama Cooperative Extension System
      • Security is kind of like air. It is easy to take for granted until it goes missing.
    2. Security Topics
      • Updates/Patches
      • Passwords
      • E-Mail
      • Surfing
      • Router/Firewall
    3. Updates/Patches Why “if it ain’t broke, don’t fix it” doesn’t apply here!
    4. Updates/Patches
      • Operating System
      • Anti-virus
      • Applications
    5. @Risk Example
      • Widely Deployed Software
      • (1) CRITICAL: Adobe Acrobat and Reader JavaScript Method Buffer Overflow Vulnerability (APSB09-04)
      • (2) CRITICAL: Autonomy KeyView SDK "wp6sr.dll" Buffer Overflow Vulnerability
      • (3) MODERATE: GNOME glib Base64 Functions Mutiple Integer Overflow Vulnerabilities
      • (4) MODERATE: PPLive Multiple URI Handlers Code Execution Vulnerabilities
    6. MS Windows Security
      • Install virus protection software
      • Turn on the Windows firewall
      • Turn on Windows updates
      • Use Windows Security Center
      • Use limited accounts
      • Use password for every account
    7. Virus Protection Software
      • Install & routinely update virus protection software
        • Sophos
        • McAfee
        • AVG
        • ClamAV
    8. Windows Firewall
      • Choose “On”
      Only unblock programs that you trust
    9. Windows Updates
      • Select “Automatic (recommended)”
      • Select “Everyday”
      • Choose an appropriate time
      • Leave computer on! (check sleep/ hibernate)
    10. Security Center
      • Ensures:
        • Firewall is on
        • Automatic updates are installed
        • Virus protection installed & up-to-date
    11. Security Center Click on the shield to fix the problem You don’t want the RED or Yellow shield
    12. Limited Accounts
      • Prohibited from installing software
        • Prevents installation of malware/viruses
        • User has access to currently installed software
      • Prohibited from accessing Administrator’s documents & settings
        • Prevents changes to administrator password
        • Prevents access to Administrator’s Documents, Desktop, etc.
      • Create/modify system accounts under “ Control Panel/User Accounts ”
    13. Limited Accounts
      • Easily switch between accounts
      • Leave programs running while others login (windows-L)
    14. Passwords? How to stop the sharing madness
    15. Passwords
      • HR system controls your $$
      • Banks control your $$
      • No reason to share passwords because you can use:
        • Network file shares
        • Shared files/folders
        • Remote Desktop
        • E-mail Proxy
        • Web 2.0 products
    16. Managing Passwords
      • Trade-offs
        • Different passwords for different systems
        • Require passwords to change
      • Password Managers
        • Password Safe
          • http://passwordsafe.sourceforge.net
        • Others
          • http://www.lifehack.org/articles/technology/10-free-ways-to-track-all-your-passwords.html
      • Choosing a good pass phrase
        • “ 1wbiDCH” (I was born in Dale County Hospital)
        • http://www.aces.edu/extconnections/2006/10/
    17. Safely Using Email Avoid hoaxes and phishing attempts
    18. Hoaxes
      • Trickery
      • Please forward
      • Usually harmless
      • Waste time and resources
    19. Phishing Clues
      • Return address appears to be legitimate
      • Warns of consequences unless urgent action is taken
      • No personal info or account name/number in message
      • Name of link doesn’t match destination
        • Name of link: https://www.firstnational.com
        • Destination of link: http://www.sargonas.con/firstnational/login.htm
      • http://www.wikipedia.org/wiki/Phishing
      • http://jdorner.blogspot.com/2007/03/every-now-and-then-i-come-across.html
      • http://www.aces.edu/extconnections/2006/12
    20. Viruses & Trojans
      • When you receive an attachment via e-mail, think about it before you click to open. Is there ANYTHING suspicious about the message?
      • Just because you know the “sender” doesn’t mean the message is legitimate.
    21. Don’t Become A Victim
      • “ Google” a sentence from the message to see if it’s a hoax or phishing attempt – add snopes to the search terms
      • Be wary of any web links you get via e-mail
    22. Surfing Read the Warnings
    23. S is for secure
      • Passwords deserve
        • “ https”
      • Check the SSL box
        • “ imaps”
        • “ pops”
    24. Read & Heed
    25. Plain-text Protocols
    26. Secure Protocol
    27. Home Routers Insurance that works for you!
    28. Home Routers
      • One internet connection, multiple computers
      • Firewall protection
      • Access restrictions
    29. One Internet Connection
    30. Firewall Protection
      • One-way valve that lets you out, but doesn’t let intruders in
        • Prevents unauthorized access to your computer(s)
        • Hides your computer(s) from the internet while still allowing access to the internet
    31. Access Restrictions
      • Control when a computer can access the internet
        • Deny/Allow by website or keyword
      • Multiple configurations
        • Everyday or only on school days etc.
        • All the time, or only between 4p.m. & 10p.m, etc.
    32. Secure Wireless
      • Disable wireless, if you’re not using it
      • Most routers can be configured w/a CD
      • What can be done manually?
        • Change the SSID (wireless network name)
        • Disable SSID Broadcast (make it invisible)
        • Require a password to join the wireless network
        • Restrict by MAC address
    33. Other References
      • SANS
        • https://www.sans.org/newsletters/
      • The National Institute on Media and the Family
        • http://www.mediafamily.org/network_guides.shtml
      • Bruce Schneier
          • “ Beyond Fear”
        • http://www.schneier.com
    34. Thank You Greg Parmer gparmer @ auburn.edu
    SlideShare Zeitgeist 2009

    + John DornerJohn Dorner Nominate

    custom

    235 views, 0 favs, 0 embeds more stats

    By Greg Parmer, Auburn University

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 235
      • 235 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 1
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories