際際滷

際際滷Share a Scribd company logo
w w w. s a a fd n . o rg
I.T. Nonprofit Technology Seminar
Full-day Seminar on Technology for Nonprofits
Cyber Security 101
June 17, 2014
p: 210-225-2243 | f: 210-225-1980
Email: me@saafdn.org
San Antonio Area Foundation
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Cyber Security 101
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Welcome and Introductions
Mitch Sowards
Founder and CEO of
ENTRUST
Dwayne Williams
Security Expert
UTSA CIAS
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
The Agenda
Introductions and Preliminaries (Mitch)
Email Security (Dwayne)
Web Browsing Security (Dwayne)
Data Encryption Security (Mitch)
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
The 101 Part
We apologize if you have heard some of this
before. But our audience is diverse and many
fundamentals bear repeating.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
The 101 Part
 Start with a good business class firewall device as
opposed to a simply home router.
Such a device will have at least some features to better
control and monitor traffic coming and going
 Practice Safe Computing by exercising good email
handling practices
Practice Safe Computing by exercising good web
browsing habits
Acquire and implement good tools to help you protect
yourself and your important data
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Security
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Is Insecure
Email can be captured and read by anyone
over the Internet
You have no control over the message after
you send it
金From addresses are easily faked
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Organization Policies
Policies are important for all organizations
Acceptable use
Attachments
Links
Education
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Organization Policies
No need to reinvent the wheel
http://www.sans.org/security-
resources/policies/Email_Policy.pdf
http://humanresources.about.com/od/emailp
olicysample/
http://www.securingthehuman.org/resources
/posters
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Donts
Do not open email from unknown senders
Do not open attachments
Do not click links
Do not send sensitive information
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Who Is This Really?
If you dont know the sender, and you didnt
expect it, delete it
No Nigerian prince wants to give you money
Real businesses review email messages for errors
Dont even reply
Any reply or attempt to unsubscribe confirms your email
address for the spammer
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
And Why Did You Send Me This?
Do not open attachments
Delete messages and attachments:
From people you dont know
That are unexpected
If you do know the sender, contact them (not in a
reply to the suspect message) and ask if they sent
the attachment and where they got it.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
I Know You Want To, But
Do not click on links in email messages
From companies you dont do business with
In unexpected messages from anyone
Hover over the link to see where it really goes
Type the address in your browser yourself
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
I Know You Want To, But
http://vtechmart.com/media/system/mod_updates/httpwww.bankofamerica.co
mfinancialtoolsindex.cfmtemplate=planning_tools&calcid=auto01/ection=g
eneric&update=&cookiecheck=yes&destination=/
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Let Me Tell You A Little About Us
Never send sensitive information over email,
including;
Passwords and PINs
Social Security and credit card numbers
Account information
Proprietary data
Sensitive organization information
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
UC Davis
http://email.ucdavis.edu/Email_Best_Practices_0
4_16_08_v4.php
US-CERT http://www.us-cert.gov/cas/tips/
Microsoft
http://www.microsoft.com/security/default.aspx
TEEX:
http://teex.com/teex.cfm?pageid=training&area=
teex&Division=KE&Course=AWR175&templateid=
14&navdiv=KE&online=true
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
What is Phishing?
The act of sending an email to a user falsely claiming to be an
established legitimate enterprise in an attempt to scam the user into
surrendering private information that will be used for identity theft.
The e-mail directs the user to visit a website where they are asked to
update personal information, such as passwords and credit card, social
security, and bank account numbers, that the legitimate organization
already has. The website is bogus and set up only to steal the users
information.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Identify Information
Attackers are looking for your information
User IDs and Passwords
Account numbers
Security codes (ATM PINs)
Contact names
Email addresses
Phone numbers (personal and business)
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Phishing Methods
Phone (Vishing)
Email (Phishing)
Replies
Clicking on links
Social media (Smishing)
TIP: If it sounds too good to be true  then it probably
isnt true.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
Phishing
US-CERT
http://www.us-cert.gov/nav/report_phishing.html
APWG (Anti-Phishing WorkGroup)
http://www.antiphishing.org/
 DISA
http://iase.disa.mil/eta/phishing_v2/phishing_v2/launchPage.htm
 Wombat Security
http://wombatsecurity.com/antiphishingphil
 MediaPro
http://www.mediapro.com/free-anti-phishing-video/
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
What is Malware?
Malicious Software = Malware
Software designed and written to
Annoy computer users
Steal information from a computer
or spy on a computer user
Gain control of a computer
Destroy or corrupt information or computer software
Categorized by type (how the malware spreads) and
by the malicious activity performed
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Spyware/Adware
Spyware is computer software that gathers
information about a computer user (such as browsing
patterns or credit card numbers) and then transmits this
information to an external entity without the knowledge
or informed consent of the user.
Adware or advertising-supported
software is any software application
in which advertisements are displayed
while the program is running. Display ads appear in pop-
up windows or through a bar that appears on a
computer screen.
http://www.jellico.com/spyware.html
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Keep your system up to date
Use anti-virus and anti-spyware/adware
Use email and external devices safely
Be careful where you
browse!
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Keep Up To Date
Set automatic updates for computers
Microsoft
Adobe
Apple
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Use a antivirus, anti-spyware, and anti-adware
Free Anti-virus Options
AVG
Avast!
Microsoft Security Essentials
Comodo Antivirus
Avira AntiVir Personal
Panda Cloud Antivirus
Immunet Protect Free
Digital-defender Antivirus
PC Tools AntiVirus Free
http://freebies.about.com/od/computerfreebi
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
Download.com
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
Some anti-virus and security companies
Kaspersky http://www.kaspersky.com/
McAfee http://www.mcafee.com/us/threat_center/
Panda Security http://www.pandasecurity.com/usa/
Sophos Labs http://www.sophos.com/
Symantec http://www.symantec.com/index.jsp
Trend http://us.trendmicro.com/us/home/
About.com
 http://antivirus.about.com/od/virusdescriptions/Latest_Malware_and_Vulnerabilities.htm
HowStuffWorks.com
 http://computer.howstuffworks.com/worst-computer-viruses.htm
Web Browsing
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Objectives
Keep your browser updated
Practice safe web browsing
Look for the lock
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Browser Security Features
Automatic updates
Safety features
Pop-up blockers
Anti-spyware
Anti-virus
Anti-phishing
Manage cookies
Manage passwords
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
 Avoid downloading freeware or shareware
 Theres no such thing as a free lunch.
 Free downloads come with a price, maybe:
 Your name and email address
 Other contact information
 Ads on the screen
 A keystroke logger
 A trojan horse
 Other malware
Practice Safe Web Browsing
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Practice Safe Web Browsing
 Avoid Peer-to-Peer (P2P) Networks
 Using P2P network is very risky
 You may unknowingly download infected files
 You may unknowingly install adware and malware
http://www.buzzle.com/articles/some-web-browsing-habits-to-stay-immune-from-starware-and-spyware.html
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Practice Safe Web Browsing
Avoid other danger zones
Pornography, or anything like unto it
Gambling sites
Warez
Offer free or very low cost versions of popular software,
movies, music, etc.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Practice Safe Web Browsing
 Check the address
 Hackers create sites with common misspellings of
popular sites.
 The misspelled site may present you with ads, surveys,
or even try to download malware onto your computer.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Use a secure website - Look for an "s" after http in the Web address
of the page you enter your credit card or other personal information
(https://www.amazon.com)
Look for a padlock in the bottom right of browser
Extended Validation SSL certificate  address bar on your browser
will turn green
Look for a trusted 3rd party logo on the page (verisign, TRUSTe)
Use an add-on filter to help identify and block previously reported
suspicious websites
Keep browser versioning up to date to avoid vulnerabilities
Research the company (forums, customer feedback, privacy and
return policies)
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Browser add-ons
McAfee Site Advisor http://mcafee-
siteadvisor.software.informer.com/
 Trusteers Rapport
https://www.trusteer.com/download-trusteer-
rapport
K9
http://www1.k9webprotection.com/
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Sandbox tools/techniques
http://www.sandboxie.com/
Virtual Machine (www.vmware.com)
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
How To Protect Yourself
Purchase or subscribe to web filtering
devices or services
Examines traffic in real time to block known
threats
Provides blacklist and whitelists
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Where Can I Find More Info?
Cyber Security Websites
 US-CERT http://www.us-cert.gov/cas/tips/
 Microsoft http://www.microsoft.com/security/default.aspx
Safe browsing
 US-CERT  Evaluating Your Web Browsers Security
Settings http://www.us-cert.gov/cas/tips/ST05-001.html
 Miscroft Online Safety
http://www.microsoft.com/protect/fraud/finances/shopping_us.aspx
 Get Safe Online http://www.getsafeonline.org/
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Data Encryption
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
Two Options
1. Encrypt at source and destination
(while at rest)
2. Encrypt only in transit
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
Encryption at Source
1. Acquire (purchase or free) personal email certificate and install it.
This allows emails to be encrypted.
2. Exchange a signed email with your correspondents in advance
so that they will be able to decrypt your future encrypted emails.
3. At time of email composition, click the button as shown on the
next slide.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
Encryption at Source
1. Pros
a) Sensitive data is fully encrypted as the outbound message is created. No matter how it gets
sent, only persons with your decryption key will be able to read the message.
b) The message remains encrypted as stored at rest on your recipients computers. If they ever
lose the decrypt key you provided, even they will not be able to read it.
2. Cons
a) You must remember to choose to encrypt.
b) Personal certificates expire and must be renewed and then new decrypt keys must be sent out
to all correspondents
c) If recipients lose the decrypt key, they will not be able to read even old messages. (This
happens when a recipient gets a new computer and old messages were encrypted with old,
expired keys.)
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Email Encryption
Encryption in Transit
1. Pros
a) Data remains unencrypted at both source and destination. You can keep such messages in your
mailbox forever and always be able to read them. Same for your recipients.
b) Often messages can be encrypted by policy (if credit card or SSN are detected within the body
of the message or if keywords are in the subject line). You dont have to remember to
encrypt.
c) No need to share encrypt/decrypt keys with anyone in advance
2. Cons
a) Policies can miss some critical messages.
b) Sometimes recipients systems are unable to receive messages encrypted in transit. In those
cases alternate clunky mechanisms kick in or the message is bounced.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Many Options
1. Purchased Products (benefits can include key escrow)
a) Symantec PGP
2. Free Open Source Products
a) Truecrypt (bad news! Now unsupported, never was really validated)
3. Free Built In with Windows 8 Pro or Windows 8 Enterprise (also
built-in with Windows 7 Ultimate or Windows 7 Enterprise)
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
1. Computer must have Trusted Platform Module (TPM) support
pre-installed
2. TPM must be enabled
1. Can be done manually in the BIOS of a computer
2. Dell provides a Custom Configuration Toolkit that allows you
to make a little executable program that a user could run to
enable TPM.
3. Computer must have a System Partition of at least
300MB.
1. If System Partition is too small, Bitlocker will shrink your C:
drive and expand the System Partition.
2. If no System Partition is present, Bitlocker will create one
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
1. Before encryption begins, you will be asked to store a text file
with a Recovery Key. You must have this key to access the
system if anything goes wrong or if you need to boot the system
into Safe Mode. DONT LOSE THE RECOVERY KEY!
2. On a new PC with no real contents, encryption will take 2-3 hours.
3. On an older PC with lots of contents, encryption will take 4-5
hours.
4. You can work while encryption is occurring, but the encryption
will take longer and your system will be slow during the process.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
1. About 1 in 20 attempts will fail (before encryption begins)
a) Messed up boot record. (FIXMBR often repairs it)
b) Out of Date BIOS
2. We have encrypted over 200 machines and none have
ever failed after the encryption process started.
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
1. In a networked business environment, the IT people can deploy a
Group Policy that will capture the Recovery Key and store it in
the network directory for safekeeping (in addition to the text file
you can store before encryption starts)
2. In a business environment, the IT people can deploy the
Microsoft Bitlocker Administration and Monitoring (MBAM)
toolkit.
a) Allows remote encryption/decryption
b) Allows remote suspension of Bitlocker protection (to allow safe
mode reboots)
c) Allows self-service access to recovery keys
d) Has reporting
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
Whole Disk Encryption
Windows Bitlocker
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org
QUESTIONS
57
303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
p: 210.225.2243 | f: 210.225.1980 | saafdn.org

More Related Content

I.T. Security I.T. | S.A. 06-17-14

  • 1. w w w. s a a fd n . o rg I.T. Nonprofit Technology Seminar Full-day Seminar on Technology for Nonprofits Cyber Security 101 June 17, 2014 p: 210-225-2243 | f: 210-225-1980 Email: me@saafdn.org San Antonio Area Foundation 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215
  • 2. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Cyber Security 101
  • 3. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Welcome and Introductions Mitch Sowards Founder and CEO of ENTRUST Dwayne Williams Security Expert UTSA CIAS
  • 4. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org The Agenda Introductions and Preliminaries (Mitch) Email Security (Dwayne) Web Browsing Security (Dwayne) Data Encryption Security (Mitch)
  • 5. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org The 101 Part We apologize if you have heard some of this before. But our audience is diverse and many fundamentals bear repeating.
  • 6. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org The 101 Part Start with a good business class firewall device as opposed to a simply home router. Such a device will have at least some features to better control and monitor traffic coming and going Practice Safe Computing by exercising good email handling practices Practice Safe Computing by exercising good web browsing habits Acquire and implement good tools to help you protect yourself and your important data
  • 7. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Email Security
  • 8. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Email Is Insecure Email can be captured and read by anyone over the Internet You have no control over the message after you send it 金From addresses are easily faked
  • 9. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Organization Policies Policies are important for all organizations Acceptable use Attachments Links Education
  • 10. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Organization Policies No need to reinvent the wheel http://www.sans.org/security- resources/policies/Email_Policy.pdf http://humanresources.about.com/od/emailp olicysample/ http://www.securingthehuman.org/resources /posters
  • 11. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Email Donts Do not open email from unknown senders Do not open attachments Do not click links Do not send sensitive information
  • 12. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Who Is This Really? If you dont know the sender, and you didnt expect it, delete it No Nigerian prince wants to give you money Real businesses review email messages for errors Dont even reply Any reply or attempt to unsubscribe confirms your email address for the spammer
  • 13. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org And Why Did You Send Me This? Do not open attachments Delete messages and attachments: From people you dont know That are unexpected If you do know the sender, contact them (not in a reply to the suspect message) and ask if they sent the attachment and where they got it.
  • 14. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org I Know You Want To, But Do not click on links in email messages From companies you dont do business with In unexpected messages from anyone Hover over the link to see where it really goes Type the address in your browser yourself
  • 15. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org I Know You Want To, But http://vtechmart.com/media/system/mod_updates/httpwww.bankofamerica.co mfinancialtoolsindex.cfmtemplate=planning_tools&calcid=auto01/ection=g eneric&update=&cookiecheck=yes&destination=/
  • 16. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Let Me Tell You A Little About Us Never send sensitive information over email, including; Passwords and PINs Social Security and credit card numbers Account information Proprietary data Sensitive organization information
  • 17. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Where Can I Find More Info? UC Davis http://email.ucdavis.edu/Email_Best_Practices_0 4_16_08_v4.php US-CERT http://www.us-cert.gov/cas/tips/ Microsoft http://www.microsoft.com/security/default.aspx TEEX: http://teex.com/teex.cfm?pageid=training&area= teex&Division=KE&Course=AWR175&templateid= 14&navdiv=KE&online=true
  • 18. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org What is Phishing? The act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The e-mail directs the user to visit a website where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has. The website is bogus and set up only to steal the users information.
  • 19. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Identify Information Attackers are looking for your information User IDs and Passwords Account numbers Security codes (ATM PINs) Contact names Email addresses Phone numbers (personal and business)
  • 20. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Phishing Methods Phone (Vishing) Email (Phishing) Replies Clicking on links Social media (Smishing) TIP: If it sounds too good to be true then it probably isnt true.
  • 21. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Where Can I Find More Info? Phishing US-CERT http://www.us-cert.gov/nav/report_phishing.html APWG (Anti-Phishing WorkGroup) http://www.antiphishing.org/ DISA http://iase.disa.mil/eta/phishing_v2/phishing_v2/launchPage.htm Wombat Security http://wombatsecurity.com/antiphishingphil MediaPro http://www.mediapro.com/free-anti-phishing-video/
  • 22. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org What is Malware? Malicious Software = Malware Software designed and written to Annoy computer users Steal information from a computer or spy on a computer user Gain control of a computer Destroy or corrupt information or computer software Categorized by type (how the malware spreads) and by the malicious activity performed
  • 23. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Spyware/Adware Spyware is computer software that gathers information about a computer user (such as browsing patterns or credit card numbers) and then transmits this information to an external entity without the knowledge or informed consent of the user. Adware or advertising-supported software is any software application in which advertisements are displayed while the program is running. Display ads appear in pop- up windows or through a bar that appears on a computer screen. http://www.jellico.com/spyware.html
  • 24. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org How To Protect Yourself Keep your system up to date Use anti-virus and anti-spyware/adware Use email and external devices safely Be careful where you browse!
  • 25. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Keep Up To Date Set automatic updates for computers Microsoft Adobe Apple
  • 26. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org How To Protect Yourself Use a antivirus, anti-spyware, and anti-adware Free Anti-virus Options AVG Avast! Microsoft Security Essentials Comodo Antivirus Avira AntiVir Personal Panda Cloud Antivirus Immunet Protect Free Digital-defender Antivirus PC Tools AntiVirus Free http://freebies.about.com/od/computerfreebi
  • 27. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Where Can I Find More Info? Download.com
  • 28. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Where Can I Find More Info? Some anti-virus and security companies Kaspersky http://www.kaspersky.com/ McAfee http://www.mcafee.com/us/threat_center/ Panda Security http://www.pandasecurity.com/usa/ Sophos Labs http://www.sophos.com/ Symantec http://www.symantec.com/index.jsp Trend http://us.trendmicro.com/us/home/ About.com http://antivirus.about.com/od/virusdescriptions/Latest_Malware_and_Vulnerabilities.htm HowStuffWorks.com http://computer.howstuffworks.com/worst-computer-viruses.htm
  • 30. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Objectives Keep your browser updated Practice safe web browsing Look for the lock
  • 31. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Browser Security Features Automatic updates Safety features Pop-up blockers Anti-spyware Anti-virus Anti-phishing Manage cookies Manage passwords
  • 32. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Avoid downloading freeware or shareware Theres no such thing as a free lunch. Free downloads come with a price, maybe: Your name and email address Other contact information Ads on the screen A keystroke logger A trojan horse Other malware Practice Safe Web Browsing
  • 33. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Practice Safe Web Browsing Avoid Peer-to-Peer (P2P) Networks Using P2P network is very risky You may unknowingly download infected files You may unknowingly install adware and malware http://www.buzzle.com/articles/some-web-browsing-habits-to-stay-immune-from-starware-and-spyware.html
  • 34. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Practice Safe Web Browsing Avoid other danger zones Pornography, or anything like unto it Gambling sites Warez Offer free or very low cost versions of popular software, movies, music, etc.
  • 35. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Practice Safe Web Browsing Check the address Hackers create sites with common misspellings of popular sites. The misspelled site may present you with ads, surveys, or even try to download malware onto your computer.
  • 36. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org How To Protect Yourself Use a secure website - Look for an "s" after http in the Web address of the page you enter your credit card or other personal information (https://www.amazon.com) Look for a padlock in the bottom right of browser Extended Validation SSL certificate address bar on your browser will turn green Look for a trusted 3rd party logo on the page (verisign, TRUSTe) Use an add-on filter to help identify and block previously reported suspicious websites Keep browser versioning up to date to avoid vulnerabilities Research the company (forums, customer feedback, privacy and return policies)
  • 37. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org How To Protect Yourself Browser add-ons McAfee Site Advisor http://mcafee- siteadvisor.software.informer.com/ Trusteers Rapport https://www.trusteer.com/download-trusteer- rapport K9 http://www1.k9webprotection.com/
  • 38. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org How To Protect Yourself Sandbox tools/techniques http://www.sandboxie.com/ Virtual Machine (www.vmware.com)
  • 39. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org How To Protect Yourself Purchase or subscribe to web filtering devices or services Examines traffic in real time to block known threats Provides blacklist and whitelists
  • 40. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Where Can I Find More Info? Cyber Security Websites US-CERT http://www.us-cert.gov/cas/tips/ Microsoft http://www.microsoft.com/security/default.aspx Safe browsing US-CERT Evaluating Your Web Browsers Security Settings http://www.us-cert.gov/cas/tips/ST05-001.html Miscroft Online Safety http://www.microsoft.com/protect/fraud/finances/shopping_us.aspx Get Safe Online http://www.getsafeonline.org/
  • 41. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Data Encryption
  • 42. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Email Encryption Two Options 1. Encrypt at source and destination (while at rest) 2. Encrypt only in transit
  • 43. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Email Encryption Encryption at Source 1. Acquire (purchase or free) personal email certificate and install it. This allows emails to be encrypted. 2. Exchange a signed email with your correspondents in advance so that they will be able to decrypt your future encrypted emails. 3. At time of email composition, click the button as shown on the next slide.
  • 44. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Email Encryption
  • 45. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Email Encryption Encryption at Source 1. Pros a) Sensitive data is fully encrypted as the outbound message is created. No matter how it gets sent, only persons with your decryption key will be able to read the message. b) The message remains encrypted as stored at rest on your recipients computers. If they ever lose the decrypt key you provided, even they will not be able to read it. 2. Cons a) You must remember to choose to encrypt. b) Personal certificates expire and must be renewed and then new decrypt keys must be sent out to all correspondents c) If recipients lose the decrypt key, they will not be able to read even old messages. (This happens when a recipient gets a new computer and old messages were encrypted with old, expired keys.)
  • 46. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Email Encryption Encryption in Transit 1. Pros a) Data remains unencrypted at both source and destination. You can keep such messages in your mailbox forever and always be able to read them. Same for your recipients. b) Often messages can be encrypted by policy (if credit card or SSN are detected within the body of the message or if keywords are in the subject line). You dont have to remember to encrypt. c) No need to share encrypt/decrypt keys with anyone in advance 2. Cons a) Policies can miss some critical messages. b) Sometimes recipients systems are unable to receive messages encrypted in transit. In those cases alternate clunky mechanisms kick in or the message is bounced.
  • 47. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Whole Disk Encryption Many Options 1. Purchased Products (benefits can include key escrow) a) Symantec PGP 2. Free Open Source Products a) Truecrypt (bad news! Now unsupported, never was really validated) 3. Free Built In with Windows 8 Pro or Windows 8 Enterprise (also built-in with Windows 7 Ultimate or Windows 7 Enterprise)
  • 48. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Whole Disk Encryption Windows Bitlocker 1. Computer must have Trusted Platform Module (TPM) support pre-installed 2. TPM must be enabled 1. Can be done manually in the BIOS of a computer 2. Dell provides a Custom Configuration Toolkit that allows you to make a little executable program that a user could run to enable TPM. 3. Computer must have a System Partition of at least 300MB. 1. If System Partition is too small, Bitlocker will shrink your C: drive and expand the System Partition. 2. If no System Partition is present, Bitlocker will create one
  • 49. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Whole Disk Encryption Windows Bitlocker
  • 50. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Whole Disk Encryption Windows Bitlocker 1. Before encryption begins, you will be asked to store a text file with a Recovery Key. You must have this key to access the system if anything goes wrong or if you need to boot the system into Safe Mode. DONT LOSE THE RECOVERY KEY! 2. On a new PC with no real contents, encryption will take 2-3 hours. 3. On an older PC with lots of contents, encryption will take 4-5 hours. 4. You can work while encryption is occurring, but the encryption will take longer and your system will be slow during the process.
  • 51. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Whole Disk Encryption Windows Bitlocker 1. About 1 in 20 attempts will fail (before encryption begins) a) Messed up boot record. (FIXMBR often repairs it) b) Out of Date BIOS 2. We have encrypted over 200 machines and none have ever failed after the encryption process started.
  • 52. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Whole Disk Encryption Windows Bitlocker 1. In a networked business environment, the IT people can deploy a Group Policy that will capture the Recovery Key and store it in the network directory for safekeeping (in addition to the text file you can store before encryption starts) 2. In a business environment, the IT people can deploy the Microsoft Bitlocker Administration and Monitoring (MBAM) toolkit. a) Allows remote encryption/decryption b) Allows remote suspension of Bitlocker protection (to allow safe mode reboots) c) Allows self-service access to recovery keys d) Has reporting
  • 53. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org Whole Disk Encryption Windows Bitlocker
  • 54. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org QUESTIONS 57
  • 55. 303 Pearl Parkway, Suite 114 | San Antonio, TX 78215 p: 210.225.2243 | f: 210.225.1980 | saafdn.org

Editor's Notes

  • #3: 07/16/96
  • #6: From The College of New Jersey (http://www.tcnj.edu/~it/security/tips/email.html): Think of it as sending a postcard written in pencil. As the card is delivered it makes numerous stops and can be altered or read by various people.
  • #7: From The College of New Jersey (http://www.tcnj.edu/~it/security/tips/email.html): Think of it as sending a postcard written in pencil. As the card is delivered it makes numerous stops and can be altered or read by various people.
  • #9: From The College of New Jersey (http://www.tcnj.edu/~it/security/tips/email.html): Think of it as sending a postcard written in pencil. As the card is delivered it makes numerous stops and can be altered or read by various people.
  • #12: Do not enter the address in the to field until the email message is completely done written, edited, attachments added, then you cant mistakenly send it too soon. From http://www.businessknowhow.com/growth/email-mistakes.htm
  • #16: Direct you to a Web site which infects your computer with malicious programs as the page is loaded. These programs can allow someone to use your computer to send spam, track key strokes to collect sensitive information, or set up repositories of inappropriate content.
  • #18: If you receive an Email that requests sensitive information like this consider it to be an attempt to use the information to commit fraud or other crimes. Legitimate organizations should not ask you to jeopardize the security of sensitive information.
  • #33: Turn on automatic updates for your browser. The updates will add the latest security features and blacklists to help keep you and your browser safe. Most browsers can be set to automatically download and install updates to the browser software, as well as updates to help defend against bogus sites and software. IE Tools>Windows Update, Check for updates Firefox Tools>Options, Advanced, click the Update tab Chrome Automatically updates Safari Automatically updates Opera Tools>Preferences, click the Advanced tab, click Security Most browsers have built-in pop-up blockers and phony/bad site detectors. IE - Tools>Internet options>Privacy. Check the Turn on Pop-up Blocker box or click Settings. Firefox Tools>Options>Content Chrome Wrench>Under the Hood>Content Settings Safari Cog>Block Pop-Up Windows or Cog>Preferences>Security Opera Tools>Quick Preferences The user can change the settings in all browsers to automatically clear the history after a certain time or after every session. IE - Tools>Internet options>General, in the Browsing history section, click Settings Firefox Tools>Options>Privacy, in the History section, in the Firefox will: drop-down choose Use custom settings for history Chrome Wrench>Options>Under the Hood>Content Settings Safari Cog>Preferences>General Opera Tools>Preferences>Advanced>History The user can also change how the browser handles cookies. IE Tools>Internet options>Privacy>Advanced Firefox Tools>Options>Privacy. Click Remember History, choose Use custom settings for history. Chrome Wrench>Options>Under the Hood>Content Settings Current browsers (Except IE) can all manage passwords as well. Firefox Tools>Options>Security Chrome Wrench>Options>Personal Stuff Safari Cog>Preferences>AutoFill Opera Tools>Preferences>Forms
  • #36: Sites that offer nude, or nearly nude pictures of celebrities are often just lures to sites that will infect your computer
  • #37: The survey or other forms may be an attempt to harvest log in or other personal data.
  • #45: 07/16/96
  • #59: 07/16/96