***Welcome to ashrafedu.blogspot.com * * * This website is maintained by ASHRAF***

Posts

    Latest Updates

    Monday, May 23, 2022

    Anti – malware software

    Antimalware is a type of software program created to protect information technology (IT) systems and individual computers from malicious software, or malware. Antimalware programs scan a computer system to prevent, detect and remove malware.

    Antimalware software uses three strategies to protect systems from malicious software: signature-based detection, behavior-based detection and sandboxing.

    1. Signature-based malware detection

    Signature-based malware detection uses a set of known software components and their digital signatures to identify new malicious software. Software vendors develop signatures to detect specific malicious software. The signatures are used to identify previously identified malicious software of the same type and to flag the new software as malware. This approach is useful for common types of malware, such as keyloggers and adware, which share many of the same characteristics.

    2. Behavior-based malware detection

    Behavior-based malware detection helps computer security professionals more quickly identify, block and eradicate malware by using an active approach to malware analysis. Behavior-based malware detection works by identifying malicious software by examining how it behaves rather than what it looks like. Behavior-based malware detection is designed to replace signature-based malware detection. It is sometimes powered by machine learning algorithms.

    3. Sandboxing

    Sandboxing is a security feature that can be used in antimalware to isolate potentially malicious files from the rest of the system. Sandboxing is often used as a method to filter out potentially malicious files and remove them before they have had a chance to do damage.

    For example, when opening a file from an unknown email attachment, the sandbox will run the file in a virtual environment and only grant it access to a limited set of resources, such as a temporary folder, the internet and a virtual keyboard. If the file tries to access other programs or settings, it will be blocked, and the sandbox has the ability to terminate it.

    Uses of antimalware

    Antimalware can help prevent malware attacks by scanning all incoming data to prevent malware from being installed and infecting a computer. Antimalware programs can also detect advanced forms of malware and offer protection against ransomware attacks.

    Antimalware programs can help in the following ways:

    • prevent users of from visiting websites known for containing malware;
    • prevent malware from spreading to other computers in a computer system;
    • provide insight into the number of infections and the time required for their removal; and
    • provide insight into how the malware compromised the device or network.

    Malware Infection

    Malware — or “malicious software” — is any program designed to harm your device and data. Several types of malware — including trojans, viruses, ransomware, spyware and worms.

    Malware infection occurs when malware, or malicious software, infiltrates your computer. Malware is a type of software created with the intent of damaging the victim's computer, stealing private information or spying on a computer without the consent of the user.

    A malware infection can cause many problems that affect daily operation and the long-term security of your company. Here are some of the many things malware can do.

    1. Steal Your Sensitive Information - Information theft is one of the most serious and costly results of malware. Once pieces of malware such as spyware and trojans are installed on your device, hackers can gather your personal and company information to sell to third-party sources. This information can include browsing history, passwords, client profiles and other sensitive data.

    2. Slow Your Computer - Once a piece of malware is in action, it begins to consume a large chunk of your computer’s memory. Many types of malware also replicate themselves and fill your hard drive, so there’s little room left for legitimate programs. This loss of space can lead to a sluggish computer, which makes it difficult to carry on with business as usual.

    3. Restrict Access to Your Files - Certain types of malware can damage or delete files and programs on your computer. Unless your data is backed up on another hard drive or cloud server, you won’t be able to regain access to many of these files after a cyber attack.

    One type of malware known as ransomware holds the files on your computer hostage. Ransomware hackers threaten to delete all of your data unless you give them money.

    4. Spread Throughout Your Network - Worms are an especially disruptive type of malware for businesses. Once this malware infects a computer, it replicates itself and spreads throughout the entire network. Most companies operate all their devices on a single network — which means that a worm could damage not just one employee’s computer, but the entire organization.

    5. Disrupt Daily Operations - Adware is specifically a nuisance for business productivity. When installed onto a computer, it enables constant popups and can even redirect your search results to advertisers’ sites — making it hard for anyone to enjoy the functionality of their device.

    Symptoms of Malware

    Some of the most common symptoms of a malware infection include:

    1.      Slow computer

    2.      Lack of storage

    3.      Crashing or freezing

    4.      Pop-ups and unwanted programs

    5.      Spam

    Steps toward minimizing your risk of malware threats:

    ·         Install anti-malware software

    ·         Perform regular employee security training

    ·         Avoid clicking unknown links and pop-ups

    ·         Keep your system up to date

    ·         Implement network security

    Prevent malware infection

    1. Keep software up to date - Software updates patch vulnerabilities so they aren't available to exploits anymore.

    2. Be wary of links and attachments - Email and other messaging tools are a few of the most common ways your device can get infected. Attachments or links in messages can open malware directly or can stealthily trigger a download. Some emails give instructions to allow macros or other executable content designed to make it easier for malware to infect your devices.

    3. Watch out for malicious or compromised websites - When you visit malicious or compromised sites, your device can get infected with malware automatically or you can get tricked into downloading and installing malware. To block malicious websites, use a modern web browser like Microsoft Edge that identifies phishing and malware websites and checks downloads for malware.

    4. Pirated material on compromised websites - Using pirated content is not only illegal, it can also expose your device to malware. Sites that offer pirated software and media are also often used to distribute malware when the site is visited. To stay safe, download movies, music, and apps from official publisher websites or stores.

    5. Don't attach unfamiliar removable drives - Some types of malware spread by copying themselves to USB flash drives or other removable drives. There are malicious individuals that intentionally prepare and distribute infected drives by leaving them in public places for unsuspecting individuals. Only use removable drives that you are familiar with or that come from a trusted source. 

    6. Use a non-administrator account - To help ensure that everyday activities do not result in malware infection and other potentially catastrophic changes, it is recommended that you use a non-administrator account for regular use. By using a non-administrator account, you can prevent installation of unauthorized apps and prevent inadvertent changes to system settings. Avoid browsing the web or checking email using an account with administrator privileges.

    Unauthorized access by outsider

    Unauthorized access is when someone gains access to a website, program, server, service, or other system using someone else's account or other methods.

    Any access to an information system or network that violates the owner or operator’s stated security policy is considered unauthorized access. Unauthorized access is also when legitimate users access a resource that they do not have permission to use.

    The most common reasons for unauthorized entry are to:

    • Steal sensitive data
    • Cause damage
    • Hold data hostage as part of a ransomware attack
    • Play a prank

    The three primary objectives of preventing unauthorized access are:

    • Confidentiality—the protection of sensitive information from unauthorized access
    • Integrity—the protection of sensitive information from unauthorized modification or destruction
    • Availability—the protection of sensitive information and information systems from unauthorized disruption

    The damage from unauthorized access goes beyond time and money; trust and reputation are also casualties.

    Protection of sensitive data should be top of mind and a high priority in all organizations. A defensive, proactive approach to preventing unauthorized access can protect information and systems from disclosure, modification, destruction, and disruption.

    Abuse of Privileges

    Privilege abuse is the fraudulent practice of using an account with additional privileges, also known as a privileged account, to access, exploit, or damage confidential business entities. By impersonating privileged users, attackers hide from the security defenses and maintain a persistent presence because it’s not unusual for privileged users to access your organization’s most sensitive resources.

    Privilege abuse is the direct result of poor access control:  Users have more access rights than they need to do their jobs, and the organization fails to properly monitor the activity of privileged accounts and establish appropriate controls.

    Privileged accounts are a gateway to critical systems and data. Abuse of these powerful accounts can lead to the loss of sensitive data and business intelligence, as well as downtime of systems and applications essential for business operations.

    Privilege abuse can be difficult to detect because many indicators of privilege abuse seem typical behavior for privileged accounts.

    Common Challenges Related to Privileged Accounts

    1. Proliferation of Shared IDs - Employees at some times need to be given additional privileges to perform functions beyond their normal responsibilities. In these situations, organizations might allow privileged users to share one or more common user IDs. This approach is undesirable because it leads to the proliferation of shared IDs, making it difficult to attribute a particular action to a specific individual.

    2. Third-Party Access – Third parties play an increasingly important role in an organization’s IT ecosystem. However, many third parties may not be as secure as the organizations to which they provide services, making them prime entry points for attackers. It is especially important to monitor the activities of third-party vendors if they have access to critical IT systems.

    3. Meeting Compliance Obligations - It is critical for organizations to enforce compliance to industry regulations.

    4. Privilege Creep - Privilege creep is the phenomenon by which employees accumulate high levels of access to IT infrastructure, some of which they are not entitled to have. It occurs when employees obtain login privileges for new systems while retaining access to old ones, even as they change roles and move across the organization. It is important to correlate current permissions and roles with the actual business needs of privileged users on a regular basis.

    The principles of Privileged Access Management are generally:

    • Ensure that only those users who absolutely need access to a given set of privileges on desktops and servers have those privileges, and only for those systems for which they have a need.
    • Ensure that privileged access is only used when it’s needed and “un-granted” when it’s no longer required.
    • Centrally manage privileged access such that access can be granted and revoked quickly.
    • Ensure that there is an audit trail for any privileged operation.

    Physical Theft

    An adversary gains physical access to a system or device through theft of the item. Possession of a system or device enables a number of unique attacks to be executed and often provides the adversary with an extended timeframe for which to perform an attack.

    Most protections put in place to secure sensitive information can be defeated when an adversary has physical access and enough time.

    To mitigate this type of attack, physical security techniques such as locks doors, alarms, and monitoring of targets should be implemented.

    Physical security is a vital part of any security plan and is fundamental to all security efforts--without it, information security, software security, user access security, and network security are considerably more difficult, if not impossible, to initiate.

    The most common physical security risks to organizations:

    1. Tailgating - Tailgating is when an unauthorized person follows an authorized person into a secure area. Tailgating can be limited with the right physical security measures. Anti-tailgating doors make tailgating virtually impossible, but installing them can prove expensive.

    Another way to reduce tailgating is by providing physical security training for your employees. It involves raising awareness among employees and providing them with a rigid physical security policy, including guidance such as not holding doors open to people they don’t recognize. 

    2. Theft of documents - Sensitive documents can easily become unaccounted for - and fall into the wrong hands.

    One of the best ways to prevent the theft or accidental revelation of documents and sensitive information is to institute a clear-desk policy. A clear-desk policy, which means ensuring that all desks are cleared and all documents are put away at the end of the workday, makes it less likely that sensitive documents are left in vulnerable locations.

    In order to prevent the theft of documents, it is also essential to institute access control and prevent unaccounted visitors from entering your workplace. 

    3. Unaccounted visitors - Unaccounted visitors pose a serious risk, as it is impossible to know if they were present if an incident occurs. Access control with swipe-card-access or ID doors is essential for business security, but you should also ensure that all visitors are accounted for by supplying them with visitor passes. Have a log of entry to later verify when a person was within your premises.

    4. Stolen identification - An access control system only works if everyone uses their own identification. If people are going in and out of your promises using someone else’s identification, the result is the same as if you had no access control at all.

    Employees need to be educated on the importance of protecting their IDs or access cards. Without training, employees will often share or lend each other their cards, making it hard to properly monitor access. Employees may also be careless with their IDs unless the importance of protecting them is demonstrated.

    5. Social engineering - Social engineering attacks rely on manipulating your employees, often using information that they have managed to gain to impersonate someone else, or abusing basic human empathy to gain access to secure areas and networks.

    Social engineering attacks can come in a huge variety of different forms. This is one of the reasons why it is so difficult to combat. 

    The first step towards combating social engineering is to make a thorough physical security risk assessment and consider how someone could get through the protections that are in place. Raising awareness about social engineering among your employees is also key, as understanding the risks that social engineering can pose will help your employees be more alert to any suspicious activity or contacts.

    Intrusion

    Computer intrusions occur when someone tries to gain access to any part of your computer system.

    Computer intruders or hackers typically use automated computer programs when they try to compromise a computer’s security. There are several ways an intruder can try to gain access to your computer. They can:

    1. Access your computer to view, change, or delete information on your computer.
    2. Crash or slow down your computer.
    3. Access your private data by examining the files on your system.
    4. Use your computer to access other computers on the Internet.

    A network intrusion refers to any unauthorized activity on a digital network. Network intrusions often involve stealing valuable network resources and almost always jeopardize the security of networks and/or their data.

    An intrusion is any activity that is designed to compromise your data security. This can be through more menacing and pervasive formats like ransomware or unintentional data breaches by employees or others connected to your network.

    Web Security challenges

    For security teams, the number of controls they can implement to secure a web application in production is limited while for the attackers, there is no limit on the number of attack vectors they can exploit. 

    To maintain a reasonable level of security, a comprehensive set of tools are required to protect their technical infrastructure from data breaches, malware attacks, and service disruptions. These tools must cover the server, network, storage devices, email servers, etc.

    The five most common web application security challenges:

    Code Injection

    Using code injection techniques, the attackers can exploit vulnerabilities in a web application by inserting their malicious code. Code injection vulnerabilities are often found in the text input field for users. Common types of code injection vulnerabilities include SQL injection, OS command attacks, dynamic evaluation attacks, and shell injection.

    Standard measures to avoid code injection vulnerability include avoiding vulnerable code and filtering input. One of the most effective ways to filter application input is implementing a web application firewall (WAF). 

    Data Breach 

    Some of the common causes of data breaches include misconfiguration, lost hardware, malware infection, and compromised credentials.

    In order to avoid data breaches, a wide range of good security practices are required. For example, SSL encryption, access-level privileges, regular scanning activities, and organizing regular training sessions for employees to practice good security practices such as identifying phishing attacks, setting up strong passwords, enabling two-factor authentication, etc.  

    The outcomes of a data breach are multi-fold. Apart from economic and reputational losses, many countries now mandatorily require a victim organization to report the data breach to the relevant regulatory authority. 

    Malware Infection 

    Malware includes ransomware, virus, trojan horses, worms, spyware, and adware. Email spam continues to be the primary vector of malware attacks.

    Malware can be delivered from various sources such as free downloads, fake websites, phishing websites, USB storage devices, etc. Hence, having a robust email filtering system is an essential requirement. Just like data breaches, training sessions for employees is another necessity to prevent an organization’s technical infrastructure from getting infected. 

    DDoS Attacks 

    With the size of DDoS attacks increasing every year, organizations can be affected even without being targeted. Many service providers have started offering DDoS protection services with real-time monitoring to mitigate such attacks as their infrastructure is capable of absorbing an enormous amount of incoming request, while they are being identified and filtered. 

    Malicious Insiders 

    The threat of malicious insiders is an evergreen. As a mandatory principle, an organization must follow the principle of least privilege, i.e., an employee shall have minimum access level privileges. An access control policy is a good starting point. Along with policy implementation, an organization can monitor transactions and activity logs for broader insights.  

    If a malicious insiders attack is detected and identified, access level privileges of the concerned insider must be revoked immediately.  

    Network session analysis

    Network session analysis Network session analysis is a method of monitoring network activity and availability to identify issues, such as ...