CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

14
CITA 250 Defense Demo

Transcript of CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Page 1: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

CITA 250

Defense Demo

Page 2: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Laws of Defense

• 10 Immutable Laws of Security

http://technet.microsoft.com/en-us/library/cc722487.aspx

Page 3: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Common Attacks and Defenses

Page 4: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Common Attacks and Defenses

Page 5: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Common Attacks and Defenses

Page 6: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Examples

• Google Hacking Defense http://www.informit.com/articles/article.aspx?p=170880&seqNum=4

• Buffer Overflow Defense

http://nsfsecurity.pr.erau.edu/bom/

Page 7: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Web Bug

• 1-pixel by 1-pixel image file

• Referenced in an <img> tag

• Usually works with a cookie

• Purpose similar to that of spyware and adware

• Comes from third-party companies specializing in data collection

Page 8: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Web Bug Defense

• For e-mail, turning off HTML display and displaying only the text

• Ghostery https://www.ghostery.com/

Page 9: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Hoax Defense

• Computer Virus Myths at http://vmyths.com/

• Rogue/Suspect Anti-Spyware Products & Web Sites http://www.spywarewarrior.com/rogue_anti-spyware.htm

Page 10: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Surf Defense

• Never double click on unknown email attachments

• Never double click links in unsolicited emails

• Never trust pop-up messages

Page 11: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Windows OS Defense

• Unhide file extensions

• Disable autorun (Tweak UI)

Page 12: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Commerce Defense

• Better Business Bureau

http://www.bbb.org/

• Looking for HTTPS

• Use credit card, NOT debit card

• Keep transaction records

Page 13: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Encryption

• Web content encryption: HTML Guardian

http://www.protware.com/

(YouTube Video at http://www.youtube.com/watch?v=sIOxL2HgMac)

• Wireless encryption: WEP, WPA, WPA2

Page 14: CITA 250 Defense Demo. Laws of Defense 10 Immutable Laws of Security .

Testing Defense

• ShieldsUP! from GRC

http://www.grc.com/