This document contains information from a seminar on cyber security 101 for nonprofits held by the San Antonio Area Foundation. The seminar covered email security, web browsing security, and data encryption. It provided best practices for securing email such as using policies, not opening attachments from unknown senders or clicking links in emails. It also discussed threats like phishing and malware, and steps to protect against these such as using antivirus software and keeping systems updated. The document gave an overview of the seminar agenda and topics to be covered.
1 of 55
Download to read offline
More Related Content
I.T. Security I.T. | S.A. 06-17-14
1. w w w. s a a fd n . o rg
I.T. Nonprofit Technology Seminar
Full-day Seminar on Technology for Nonprofits
Cyber Security 101
June 17, 2014
p: 210-225-2243 | f: 210-225-1980
Email: me@saafdn.org
San Antonio Area Foundation
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
2. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Cyber Security 101
3. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Welcome and Introductions
Mitch Sowards
Founder and CEO of
ENTRUST
Dwayne Williams
Security Expert
UTSA CIAS
4. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
The Agenda
Introductions and Preliminaries (Mitch)
Email Security (Dwayne)
Web Browsing Security (Dwayne)
Data Encryption Security (Mitch)
5. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
The 101 Part
We apologize if you have heard some of this
before. But our audience is diverse and many
fundamentals bear repeating.
6. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
The 101 Part
Start with a good business class firewall device as
opposed to a simply home router.
Such a device will have at least some features to better
control and monitor traffic coming and going
Practice Safe Computing by exercising good email
handling practices
Practice Safe Computing by exercising good web
browsing habits
Acquire and implement good tools to help you protect
yourself and your important data
7. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Security
8. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Is Insecure
Email can be captured and read by anyone
over the Internet
You have no control over the message after
you send it
金From addresses are easily faked
9. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Organization Policies
Policies are important for all organizations
Acceptable use
Attachments
Links
Education
10. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Organization Policies
No need to reinvent the wheel
http://www.sans.org/security-
resources/policies/Email_Policy.pdf
http://humanresources.about.com/od/emailp
olicysample/
http://www.securingthehuman.org/resources
/posters
11. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Donts
Do not open email from unknown senders
Do not open attachments
Do not click links
Do not send sensitive information
12. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Who Is This Really?
If you dont know the sender, and you didnt
expect it, delete it
No Nigerian prince wants to give you money
Real businesses review email messages for errors
Dont even reply
Any reply or attempt to unsubscribe confirms your email
address for the spammer
13. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
And Why Did You Send Me This?
Do not open attachments
Delete messages and attachments:
From people you dont know
That are unexpected
If you do know the sender, contact them (not in a
reply to the suspect message) and ask if they sent
the attachment and where they got it.
14. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
I Know You Want To, But
Do not click on links in email messages
From companies you dont do business with
In unexpected messages from anyone
Hover over the link to see where it really goes
Type the address in your browser yourself
15. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
I Know You Want To, But
http://vtechmart.com/media/system/mod_updates/httpwww.bankofamerica.co
mfinancialtoolsindex.cfmtemplate=planning_tools&calcid=auto01/ection=g
eneric&update=&cookiecheck=yes&destination=/
16. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Let Me Tell You A Little About Us
Never send sensitive information over email,
including;
Passwords and PINs
Social Security and credit card numbers
Account information
Proprietary data
Sensitive organization information
17. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
UC Davis
http://email.ucdavis.edu/Email_Best_Practices_0
4_16_08_v4.php
US-CERT http://www.us-cert.gov/cas/tips/
Microsoft
http://www.microsoft.com/security/default.aspx
TEEX:
http://teex.com/teex.cfm?pageid=training&area=
teex&Division=KE&Course=AWR175&templateid=
14&navdiv=KE&online=true
18. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
What is Phishing?
The act of sending an email to a user falsely claiming to be an
established legitimate enterprise in an attempt to scam the user into
surrendering private information that will be used for identity theft.
The e-mail directs the user to visit a website where they are asked to
update personal information, such as passwords and credit card, social
security, and bank account numbers, that the legitimate organization
already has. The website is bogus and set up only to steal the users
information.
19. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Identify Information
Attackers are looking for your information
User IDs and Passwords
Account numbers
Security codes (ATM PINs)
Contact names
Email addresses
Phone numbers (personal and business)
20. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Phishing Methods
Phone (Vishing)
Email (Phishing)
Replies
Clicking on links
Social media (Smishing)
TIP: If it sounds too good to be true then it probably
isnt true.
21. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
Phishing
US-CERT
http://www.us-cert.gov/nav/report_phishing.html
APWG (Anti-Phishing WorkGroup)
http://www.antiphishing.org/
DISA
http://iase.disa.mil/eta/phishing_v2/phishing_v2/launchPage.htm
Wombat Security
http://wombatsecurity.com/antiphishingphil
MediaPro
http://www.mediapro.com/free-anti-phishing-video/
22. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
What is Malware?
Malicious Software = Malware
Software designed and written to
Annoy computer users
Steal information from a computer
or spy on a computer user
Gain control of a computer
Destroy or corrupt information or computer software
Categorized by type (how the malware spreads) and
by the malicious activity performed
23. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Spyware/Adware
Spyware is computer software that gathers
information about a computer user (such as browsing
patterns or credit card numbers) and then transmits this
information to an external entity without the knowledge
or informed consent of the user.
Adware or advertising-supported
software is any software application
in which advertisements are displayed
while the program is running. Display ads appear in pop-
up windows or through a bar that appears on a
computer screen.
http://www.jellico.com/spyware.html
24. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Keep your system up to date
Use anti-virus and anti-spyware/adware
Use email and external devices safely
Be careful where you
browse!
25. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Keep Up To Date
Set automatic updates for computers
Microsoft
Adobe
Apple
26. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Use a antivirus, anti-spyware, and anti-adware
Free Anti-virus Options
AVG
Avast!
Microsoft Security Essentials
Comodo Antivirus
Avira AntiVir Personal
Panda Cloud Antivirus
Immunet Protect Free
Digital-defender Antivirus
PC Tools AntiVirus Free
http://freebies.about.com/od/computerfreebi
27. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
Download.com
28. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
Some anti-virus and security companies
Kaspersky http://www.kaspersky.com/
McAfee http://www.mcafee.com/us/threat_center/
Panda Security http://www.pandasecurity.com/usa/
Sophos Labs http://www.sophos.com/
Symantec http://www.symantec.com/index.jsp
Trend http://us.trendmicro.com/us/home/
About.com
http://antivirus.about.com/od/virusdescriptions/Latest_Malware_and_Vulnerabilities.htm
HowStuffWorks.com
http://computer.howstuffworks.com/worst-computer-viruses.htm
30. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Objectives
Keep your browser updated
Practice safe web browsing
Look for the lock
31. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Browser Security Features
Automatic updates
Safety features
Pop-up blockers
Anti-spyware
Anti-virus
Anti-phishing
Manage cookies
Manage passwords
32. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Avoid downloading freeware or shareware
Theres no such thing as a free lunch.
Free downloads come with a price, maybe:
Your name and email address
Other contact information
Ads on the screen
A keystroke logger
A trojan horse
Other malware
Practice Safe Web Browsing
33. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Practice Safe Web Browsing
Avoid Peer-to-Peer (P2P) Networks
Using P2P network is very risky
You may unknowingly download infected files
You may unknowingly install adware and malware
http://www.buzzle.com/articles/some-web-browsing-habits-to-stay-immune-from-starware-and-spyware.html
34. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Practice Safe Web Browsing
Avoid other danger zones
Pornography, or anything like unto it
Gambling sites
Warez
Offer free or very low cost versions of popular software,
movies, music, etc.
35. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Practice Safe Web Browsing
Check the address
Hackers create sites with common misspellings of
popular sites.
The misspelled site may present you with ads, surveys,
or even try to download malware onto your computer.
36. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Use a secure website - Look for an "s" after http in the Web address
of the page you enter your credit card or other personal information
(https://www.amazon.com)
Look for a padlock in the bottom right of browser
Extended Validation SSL certificate address bar on your browser
will turn green
Look for a trusted 3rd party logo on the page (verisign, TRUSTe)
Use an add-on filter to help identify and block previously reported
suspicious websites
Keep browser versioning up to date to avoid vulnerabilities
Research the company (forums, customer feedback, privacy and
return policies)
37. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Browser add-ons
McAfee Site Advisor http://mcafee-
siteadvisor.software.informer.com/
Trusteers Rapport
https://www.trusteer.com/download-trusteer-
rapport
K9
http://www1.k9webprotection.com/
38. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Sandbox tools/techniques
http://www.sandboxie.com/
Virtual Machine (www.vmware.com)
39. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Purchase or subscribe to web filtering
devices or services
Examines traffic in real time to block known
threats
Provides blacklist and whitelists
40. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
Cyber Security Websites
US-CERT http://www.us-cert.gov/cas/tips/
Microsoft http://www.microsoft.com/security/default.aspx
Safe browsing
US-CERT Evaluating Your Web Browsers Security
Settings http://www.us-cert.gov/cas/tips/ST05-001.html
Miscroft Online Safety
http://www.microsoft.com/protect/fraud/finances/shopping_us.aspx
Get Safe Online http://www.getsafeonline.org/
41. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Data Encryption
42. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
Two Options
1. Encrypt at source and destination
(while at rest)
2. Encrypt only in transit
43. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
Encryption at Source
1. Acquire (purchase or free) personal email certificate and install it.
This allows emails to be encrypted.
2. Exchange a signed email with your correspondents in advance
so that they will be able to decrypt your future encrypted emails.
3. At time of email composition, click the button as shown on the
next slide.
44. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
45. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
Encryption at Source
1. Pros
a) Sensitive data is fully encrypted as the outbound message is created. No matter how it gets
sent, only persons with your decryption key will be able to read the message.
b) The message remains encrypted as stored at rest on your recipients computers. If they ever
lose the decrypt key you provided, even they will not be able to read it.
2. Cons
a) You must remember to choose to encrypt.
b) Personal certificates expire and must be renewed and then new decrypt keys must be sent out
to all correspondents
c) If recipients lose the decrypt key, they will not be able to read even old messages. (This
happens when a recipient gets a new computer and old messages were encrypted with old,
expired keys.)
46. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
Encryption in Transit
1. Pros
a) Data remains unencrypted at both source and destination. You can keep such messages in your
mailbox forever and always be able to read them. Same for your recipients.
b) Often messages can be encrypted by policy (if credit card or SSN are detected within the body
of the message or if keywords are in the subject line). You dont have to remember to
encrypt.
c) No need to share encrypt/decrypt keys with anyone in advance
2. Cons
a) Policies can miss some critical messages.
b) Sometimes recipients systems are unable to receive messages encrypted in transit. In those
cases alternate clunky mechanisms kick in or the message is bounced.
47. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Many Options
1. Purchased Products (benefits can include key escrow)
a) Symantec PGP
2. Free Open Source Products
a) Truecrypt (bad news! Now unsupported, never was really validated)
3. Free Built In with Windows 8 Pro or Windows 8 Enterprise (also
built-in with Windows 7 Ultimate or Windows 7 Enterprise)
48. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
1. Computer must have Trusted Platform Module (TPM) support
pre-installed
2. TPM must be enabled
1. Can be done manually in the BIOS of a computer
2. Dell provides a Custom Configuration Toolkit that allows you
to make a little executable program that a user could run to
enable TPM.
3. Computer must have a System Partition of at least
300MB.
1. If System Partition is too small, Bitlocker will shrink your C:
drive and expand the System Partition.
2. If no System Partition is present, Bitlocker will create one
49. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
50. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
1. Before encryption begins, you will be asked to store a text file
with a Recovery Key. You must have this key to access the
system if anything goes wrong or if you need to boot the system
into Safe Mode. DONT LOSE THE RECOVERY KEY!
2. On a new PC with no real contents, encryption will take 2-3 hours.
3. On an older PC with lots of contents, encryption will take 4-5
hours.
4. You can work while encryption is occurring, but the encryption
will take longer and your system will be slow during the process.
51. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
1. About 1 in 20 attempts will fail (before encryption begins)
a) Messed up boot record. (FIXMBR often repairs it)
b) Out of Date BIOS
2. We have encrypted over 200 machines and none have
ever failed after the encryption process started.
52. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
1. In a networked business environment, the IT people can deploy a
Group Policy that will capture the Recovery Key and store it in
the network directory for safekeeping (in addition to the text file
you can store before encryption starts)
2. In a business environment, the IT people can deploy the
Microsoft Bitlocker Administration and Monitoring (MBAM)
toolkit.
a) Allows remote encryption/decryption
b) Allows remote suspension of Bitlocker protection (to allow safe
mode reboots)
c) Allows self-service access to recovery keys
d) Has reporting
53. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
54. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
QUESTIONS
57
55. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
#6: From The College of New Jersey (http://www.tcnj.edu/~it/security/tips/email.html): Think of it as sending a postcard written in pencil. As the card is delivered it makes numerous stops and can be altered or read by various people.
#7: From The College of New Jersey (http://www.tcnj.edu/~it/security/tips/email.html): Think of it as sending a postcard written in pencil. As the card is delivered it makes numerous stops and can be altered or read by various people.
#9: From The College of New Jersey (http://www.tcnj.edu/~it/security/tips/email.html): Think of it as sending a postcard written in pencil. As the card is delivered it makes numerous stops and can be altered or read by various people.
#12: Do not enter the address in the to field until the email message is completely done written, edited, attachments added, then you cant mistakenly send it too soon. From http://www.businessknowhow.com/growth/email-mistakes.htm
#16: Direct you to a Web site which infects your computer with malicious programs as the page is loaded. These programs can allow someone to use your computer to send spam, track key strokes to collect sensitive information, or set up repositories of inappropriate content.
#18: If you receive an Email that requests sensitive information like this consider it to be an attempt to use the information to commit fraud or other crimes. Legitimate organizations should not ask you to jeopardize the security of sensitive information.
#33: Turn on automatic updates for your browser. The updates will add the latest security features and blacklists to help keep you and your browser safe.
Most browsers can be set to automatically download and install updates to the browser software, as well as updates to help defend against bogus sites and software.
IE Tools>Windows Update, Check for updates
Firefox Tools>Options, Advanced, click the Update tab
Chrome Automatically updates
Safari Automatically updates
Opera Tools>Preferences, click the Advanced tab, click Security
Most browsers have built-in pop-up blockers and phony/bad site detectors.
IE - Tools>Internet options>Privacy. Check the Turn on Pop-up Blocker box or click Settings.
Firefox Tools>Options>Content
Chrome Wrench>Under the Hood>Content Settings
Safari Cog>Block Pop-Up Windows or Cog>Preferences>Security
Opera Tools>Quick Preferences
The user can change the settings in all browsers to automatically clear the history after a certain time or after every session.
IE - Tools>Internet options>General, in the Browsing history section, click Settings
Firefox Tools>Options>Privacy, in the History section, in the Firefox will: drop-down choose Use custom settings for history
Chrome Wrench>Options>Under the Hood>Content Settings
Safari Cog>Preferences>General
Opera Tools>Preferences>Advanced>History
The user can also change how the browser handles cookies.
IE Tools>Internet options>Privacy>Advanced
Firefox Tools>Options>Privacy. Click Remember History, choose Use custom settings for history.
Chrome Wrench>Options>Under the Hood>Content Settings
Current browsers (Except IE) can all manage passwords as well.
Firefox Tools>Options>Security
Chrome Wrench>Options>Personal Stuff
Safari Cog>Preferences>AutoFill
Opera Tools>Preferences>Forms
#36: Sites that offer nude, or nearly nude pictures of celebrities are often just lures to sites that will infect your computer
#37: The survey or other forms may be an attempt to harvest log in or other personal data.