55% of online users have been infected with spyware

23
55% of online users have been infected with spyware http://www.aladdin.com/airc/security-statist ics.aspx for 2005

description

55% of online users have been infected with spyware. http://www.aladdin.com/airc/security-statistics.aspx for 2005. 21,100,283 unique malware binaries collected in the last 12 months. http://www.shadowserver.org/wiki/pmwiki.php/Stats/Malware. - PowerPoint PPT Presentation

Transcript of 55% of online users have been infected with spyware

Page 1: 55% of online users have been infected with spyware

55% of online users have been infected with spyware

http://www.aladdin.com/airc/security-statistics.aspx for 2005

Page 2: 55% of online users have been infected with spyware

21,100,283 unique malware binaries collected in the last 12 months

http://www.shadowserver.org/wiki/pmwiki.php/Stats/Malware

Page 3: 55% of online users have been infected with spyware

Malware cost estimated at $169-204 billion for 2004

http://www.aladdin.com/airc/security-statistics.aspx

Page 4: 55% of online users have been infected with spyware

Only 7% of companies officially run Service Pack 2

http://www.aladdin.com/airc/security-statistics.aspx as of 2005

Page 6: 55% of online users have been infected with spyware

As of Tuesday, April 13, 2010 http://www.shadowserver.org/wiki/pmwiki.php/Stats/DroneMaps

Page 7: 55% of online users have been infected with spyware

DIGITAL AEGISProtecting You From The World

Page 8: 55% of online users have been infected with spyware

AgendaOpportunityLimitationsWhat we didProblemsExternal/Network TestsPhysical Client TestsLooking BackFuture GoalsQuestions

Windows XPWindows 7Gentoo LinuxWindows 2008 R2Pfsense Firewall

Boxes

Page 9: 55% of online users have been infected with spyware

Opportunity Small to medium sized companies Can’t afford large security applications Don’t need a lot of services Target of script kitty/automated attacks Often become part of bot-nets Can leak personal or financial information Result in serious legal or financial

consequences

Page 10: 55% of online users have been infected with spyware

Limitations Only focused on small to medium

businesses Only running a few basic services Not protecting against Zero Day threats Not providing physical building/box

security Focused on Script Kitty and automated

attacks Low rate of false alarms Proprietary software

Page 11: 55% of online users have been infected with spyware

What We Did Windows XP

Basic Settings User Accounts/ auditing Registry Services User rights/ File permissions Internet Explorer GPO

Page 12: 55% of online users have been infected with spyware

What We Did Windows 7

Basic Settings Elevated Pre-installed Security

Permissions UAC Remote Desktop AutoPlay

Microsoft Security Essentials Managing Local Accounts Applying GPO

Page 13: 55% of online users have been infected with spyware

What We Did Gentoo Linux

Hardened Base Rolling Release Custom Compiled Kernel

No loadable modules – All built in PAX Buffer and heap overflow protection

Chroot Environment Latest patched Apache - Statically compiled

Binaries Strict IPtables Firewall Disabled Root Account – sudo AIDE

Page 14: 55% of online users have been infected with spyware

What We Did Pfsense Firewall Boxes

Nat Firewall Block all Unused Ports MAC Filtering Snort IDS

Detect common scans, exploits and attacks Automated Blocking those exceeding threshold

Snort LAN sniffing Inappropriate activity

HTTP sniffing – porn, racist Common malware communication

Squid/SquidGuard Access Control Lists – Who allowed what and when Blacklisting/White listing

Page 15: 55% of online users have been infected with spyware

What We Did Windows 2008 R2

Basic Settings Windows 7 Settings DNS Active Directory Exchange Domain GPO

Page 16: 55% of online users have been infected with spyware

Problems Exchange

Issues installing on a new install of Server 2008 R2

Uninstall Issues Format

Solution Followed 3 separate guides Manual install of packages Prep commands

Page 17: 55% of online users have been infected with spyware

Problems Windows XP

Local GPO application Administrator lockout CD/USB blocking

Solution Workaround suggested by Windows Snapshots Online Administrative Template

Page 18: 55% of online users have been infected with spyware

Problems Windows 7

New Operating system In-Depth Security analysis Zero Day Threats

Solutions Work with what you can get Windows 2008 GPO Default Settings

Page 19: 55% of online users have been infected with spyware

External/Network Tests Nmap Scans from Outside Network

Gateway Results Nmap Scans from Inside Client Network

Linux Machine Results Windows 7 Results Windows XP Results Server Results

Back Track AutoPwn Scans Zero successful exploits

Page 20: 55% of online users have been infected with spyware

Physical Client Tests Boot from CD Recovery Console Safe Mode User Permissions Password Strength Command line CD/USB blocking Internet explorer settings

Page 21: 55% of online users have been infected with spyware

Looking Back Better Firewall Hardware Waiting for Newest Pfsense Version Possibly different OS for firewalls Windows XP Exchange Linux Clients

Page 22: 55% of online users have been infected with spyware

Future Goals Snort Rules Full DNS black list Network traffic finger printing Implement in a small business setting Look at distribution Training

Page 23: 55% of online users have been infected with spyware

Questions ?