64
Security Awareness: Security Tips for Protecting Ourselves Online Friday, May 20, 2011 Brian Allen, CISSP [email protected] Network Security Analyst Washington University in St. Louis http://nso.wustl.edu/presentations/

Security Awareness: Security Tips for Protecting Ourselves Online

  • Upload
    magar

  • View
    48

  • Download
    0

Embed Size (px)

DESCRIPTION

Security Awareness: Security Tips for Protecting Ourselves Online. Friday, May 20, 2011 Brian Allen, CISSP [email protected] Network Security Analyst Washington University in St. Louis http ://nso.wustl.edu/presentations/. Let’s Talk About…. Facebook /Social Networking - PowerPoint PPT Presentation

Citation preview

Page 1: Security  Awareness: Security Tips for Protecting Ourselves Online

Security Awareness:Security Tips for Protecting Ourselves Online

Friday, May 20, 2011

Brian Allen, [email protected]

Network Security AnalystWashington University in St. Louis

http://nso.wustl.edu/presentations/

Page 2: Security  Awareness: Security Tips for Protecting Ourselves Online

Let’s Talk About…• Facebook/Social Networking• Password Security• AV Products• Home Wireless Router Security• Laptop Security• Safe Web Browsing• Phishing Examples• Online Banking• Virus Example and Case Study

Page 3: Security  Awareness: Security Tips for Protecting Ourselves Online

Facebook/Social Networking:

Page 4: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 5: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 6: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 7: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 8: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 9: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 10: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 11: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 12: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 13: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 14: Security  Awareness: Security Tips for Protecting Ourselves Online

Password Security

Page 15: Security  Awareness: Security Tips for Protecting Ourselves Online

Parents’ Password Cracked On First Try The Onion News Feb 27, 2002

• REDONDO BEACH, CA – Nick Berrigan, 14, successfully hacked into his parents’ AOL account on the first try Tuesday, correctly guessing that “Digby” was their password.

• “They actually used the dog’s name,” said Berrigan, deactivating the parental controls on his AOL account.

Page 16: Security  Awareness: Security Tips for Protecting Ourselves Online

Free Password Managers

1. KeePass – I use this one2. Password Safe

– Bruce Schneier’s Project3. PassPack

– An online password manager

Commercial Password Manager:4. 1Password

-”Works great on iPhone and OS X”

Page 17: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 18: Security  Awareness: Security Tips for Protecting Ourselves Online

Free Antivirus Tools

Page 19: Security  Awareness: Security Tips for Protecting Ourselves Online

Antivirus

• I look for:– the fastest– update themselves automatically– have an easy to use interface

• AVG = http://free.avg.com• AntiVir = http://www.free-av.com• Avast = http://www.avast.com

Page 20: Security  Awareness: Security Tips for Protecting Ourselves Online

From CNET.com Editor ReviewsAVG Popularity: * Total downloads 227,792,675 Avira AntiVir Popularity: * Total downloads 61,994,231 Avast Popularity: * Total downloads 60,978,532

Page 21: Security  Awareness: Security Tips for Protecting Ourselves Online

AVG Interface

Page 22: Security  Awareness: Security Tips for Protecting Ourselves Online

AVG Will Check Every Email

Page 23: Security  Awareness: Security Tips for Protecting Ourselves Online

Avira AntiVir Interface

Page 24: Security  Awareness: Security Tips for Protecting Ourselves Online

AVAST Interface

Page 25: Security  Awareness: Security Tips for Protecting Ourselves Online

Home Wireless Router Tips

Page 26: Security  Awareness: Security Tips for Protecting Ourselves Online

Home Wireless Router Tips

• Change Default Password• Firewall is on by Default• WPA2, not WPA or WEP• MAC Address Filtering• Leave SSID on• No personal info in SSID like Smith_Family

Page 27: Security  Awareness: Security Tips for Protecting Ourselves Online

Change The Default Password

Page 28: Security  Awareness: Security Tips for Protecting Ourselves Online

Firewall Is On By Default

Page 29: Security  Awareness: Security Tips for Protecting Ourselves Online

WPA2

Page 30: Security  Awareness: Security Tips for Protecting Ourselves Online

MAC Address Filtering

Page 31: Security  Awareness: Security Tips for Protecting Ourselves Online

Home Wireless Router Tips

• Change Default Password• Firewall is on by Default• WPA2, not WPA or WEP• MAC Address Filtering• Leave SSID on• No personal info in SSID like Smith_Family

Page 32: Security  Awareness: Security Tips for Protecting Ourselves Online

Laptop Tracking Software

Page 33: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 34: Security  Awareness: Security Tips for Protecting Ourselves Online

Key Questions to Consider

• How hard is it to disable or remove the software?• Who will have access to the collected data?• How many laptops are lost or stolen every year?

Page 35: Security  Awareness: Security Tips for Protecting Ourselves Online

LoJack Pros

• Very difficult to disable• The company, only with the user’s permission,

can log in to:– Take pictures– Erase the hard drive

• Will work with police to recover the laptop

Page 36: Security  Awareness: Security Tips for Protecting Ourselves Online

LoJack Bios Compatibility

AsusDellGammatechGetacGatewayGeneral

Dynamics

HPFujitsuLenovo (IBM

Thinkpad)Motion ComputingPanasonicToshiba

Page 37: Security  Awareness: Security Tips for Protecting Ourselves Online

LoJack Cons

• Bios compatibility does not include Macintosh– 40% student machines are Macs

• Most Expensive - $49 per laptop• The company can get access into laptops,

although it is only to be initiated by the owner after it is reported stolen

Page 38: Security  Awareness: Security Tips for Protecting Ourselves Online

Laptop/USB Encryption

• USB Hardware Encryption – IronKey $$$

• Laptop/USB Encryption – TrueCrypt (Free!)

Page 39: Security  Awareness: Security Tips for Protecting Ourselves Online

Safe Web Browsing

Page 40: Security  Awareness: Security Tips for Protecting Ourselves Online

Four OS Security Tips

• Make sure the operating system has:– Update automatically– Firewall turned on– All accounts have strong passwords– Up-to-date Anti-virus tool

Page 41: Security  Awareness: Security Tips for Protecting Ourselves Online

Link Security Tips

• Don’t click links or open attachments in emails.• If you have any doubt, get confirmation directly

from the sender.• Be wary of messages that include attractive

offers or urgent requests.• Watch out for links that require you to

immediately provide a login and password.• Type the URL directly into Google.

Page 42: Security  Awareness: Security Tips for Protecting Ourselves Online

Browser Security Tips

• I use Firefox as my regular browser.• Firefox will automatically update itself.• Firefox 3 and 4 have Phishing and Malware

Protection on by default. • Use the Add Block Plus Firefox Addon.

Page 43: Security  Awareness: Security Tips for Protecting Ourselves Online

The Top Firefox Addon (By Far)

Page 44: Security  Awareness: Security Tips for Protecting Ourselves Online

Without AdBlock Plus

Page 45: Security  Awareness: Security Tips for Protecting Ourselves Online

With AdBlock Plus

Page 46: Security  Awareness: Security Tips for Protecting Ourselves Online

Phishing Examples

Page 47: Security  Awareness: Security Tips for Protecting Ourselves Online

Phishing Email

Page 48: Security  Awareness: Security Tips for Protecting Ourselves Online
Page 49: Security  Awareness: Security Tips for Protecting Ourselves Online

Spear Phishing Example

<http://michaelkellett com/ez/wustl.html>

Page 50: Security  Awareness: Security Tips for Protecting Ourselves Online

Online Banking

Page 51: Security  Awareness: Security Tips for Protecting Ourselves Online

Important Online Banking Tip

• Never type your bank url into a browserOr click on a url that looks like your bank

• Always let Google find it for you– Should be the first link

Page 52: Security  Awareness: Security Tips for Protecting Ourselves Online

Virus Example and Case Study:

Page 53: Security  Awareness: Security Tips for Protecting Ourselves Online

First: Different Types of Infections

• Viruses – Rely on users to spread: email attachments, links in an email

• Worms – can spread on their own• Trojans – A malicious file that appears to be

legitimate• Bots – A worm that phones home to a

Command & Controller so the attacker can give it instructions

Page 54: Security  Awareness: Security Tips for Protecting Ourselves Online

What Do The Infections Do?

• Send Spam• Attack other machines• Set up a Phishing site• Act as a proxy for other malicious traffic• Download spyware/adware to the machine• Run a keylogger

Page 55: Security  Awareness: Security Tips for Protecting Ourselves Online

Koobface Botnet

• Koobface made an estimated $2m since July 2009• It makes money by selling scareware (fake anti-virus),

doing click fraud and other scams.• Koobface targets Facebook and other sites.• 400,000+ bots; 20,000+ fake Facebook accounts• Tricks users to execute malware disguised as Flash

updates needed to view shocking content.• The malware turns PCs into zombie drones under the

control of hackers.• http://www.theregister.co.uk/2010/11/15/koobface_take_down/

Page 56: Security  Awareness: Security Tips for Protecting Ourselves Online

Fake Anti-Virus Screen Shot

Page 57: Security  Awareness: Security Tips for Protecting Ourselves Online

KoobFace Botnet

• How it works in one example:• Koobface is a Russian based botnet• The threat arrives as a Facebook private

message that contains a supposed link to a youtube video

Page 58: Security  Awareness: Security Tips for Protecting Ourselves Online

Don’t Click the LINK!

Page 59: Security  Awareness: Security Tips for Protecting Ourselves Online

Koobface Example Continued

• Users who are tricked into clicking the link are redirected to other pages until they finally end up at a spoofed YouTube site called YuoTube

Page 60: Security  Awareness: Security Tips for Protecting Ourselves Online

Don’t Trust the “Adobe Flash Update”!

Page 61: Security  Awareness: Security Tips for Protecting Ourselves Online

How KoobFace works

• It navigates through users’ FB pages to search for their friends.

• It phones home to get the actual message that the worm will then spread to your friends.

• McAfee says it is not unusual to see 10,000 Koobface variants in one month.

• http://blogs.mcafee.com/mcafee-labs/malware-at-midyear-a-summary

• TrendLabs considers Zeus and Koobface to be the most prolific malware families

• http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/tm101hthreat_report.pdf

Page 62: Security  Awareness: Security Tips for Protecting Ourselves Online

Koobface Targets MacOSX

• A new version of Koobface attacks Mac OSX spreads through Facebook.

• Security company Intego says this version uses a malicious Java applet to attack users.

• http://krebsonsecurity.com/2010/10/koobface-worm-targets-java-on-mac-os-x/

Page 63: Security  Awareness: Security Tips for Protecting Ourselves Online

Thank You!

Brian Allen, [email protected]://nso.wustl.edu

Page 64: Security  Awareness: Security Tips for Protecting Ourselves Online

Password Managers:KeePass: http://keepass.infoPassword Safe: http://schneier.com/passsafe.htmlPassPack: http://www.passpack.com1Password ($): http://agilebits.com/onepassword Antivirus:AVG: http://free.avg.comAntiVir: http://www.free-av.comAvast : http://www.avast.com Laptop Tracking:LoJack($): http://www.absolute.com/en/lojackforlaptops/home.aspx USB/Laptop Encryption:Ironkey($): https://www.ironkey.comTrueCrypt: http://www.truecrypt.org Firefox Ad Blocker:AdBlock Plus https://addons.mozilla.org/en-US/firefox/addon/adblock-plus

Brian Allen [email protected]