Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience...

34
Improving Windows Security Multiple Layers of Security Part 1 The Villages Computer Plus http://www.villagescp.com/ Bob Walton et al. May-16-2013 Security.1 1

Transcript of Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience...

Page 1: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Improving Windows Security Multiple Layers of Security

Part 1

The Villages Computer Plus http://www.villagescp.com/

Bob Walton et al. May-16-2013

Security.1 1

Page 2: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Links: Multiple Layers of Security

1. Tools for a Safer PC

https://krebsonsecurity.com/tools-for-a-safer-pc/

2. Ninite web-site

https://ninite.com/

3. FileHippo UpdateChecker

http://www.filehippo.com/updatechecker/

4. Secunia PSI web-site

https://secunia.com/vulnerability_scanning/personal/

5. Learn how to enable JavaScript in the most popular web browsers.

http://activatejavascript.org/en/instructions

6. NoScript Firefox Add-On

https://addons.mozilla.org/en-US/firefox/addon/noscript/?src=search

7. NotScripts: Google Chrome Extension

https://chrome.google.com/webstore/detail/notscripts/odjhifogjcknibkahlpidmdajjpkkcfn

8. Installing and Configuring EMET (VIDEO)

https://www.microsoft.com/en-us/showcase/details.aspx?uuid=7683a9cb-28c9-428f-ada6-8adafd2efbee

9. Enhanced Mitigation Experience Toolkit v3.0

https://www.microsoft.com/en-us/download/details.aspx?id=29851

Security.1 2

Page 3: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Credentials: Brian Krebs

Security.1 3

Page 4: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Overview: Multiple Layers of Security

• Explain Bad Guy uses for your PC

• Layers of Security – Obey 3 Basic Rules of Safety

– Keep up-to-date with Updates

– Put a Leash on JavaScript

– Use Enhanced Mitigation Experience Toolkit

– Prop up Your Passwords

– Harden your Hardware

– Set Default DNS servers

– Use Antivirus Software

– Force Apps to Play in the Sandbox

– Use post-compromise remedies

Security.1 4

Page 5: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Bad Guy uses for your PC

Security.1 5

Page 6: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

The Scrap Value of a Hacked PC (1)

Security.1 6

Page 7: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

The Scrap Value of a Hacked PC (2)

Security.1 7

Page 8: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

The Scrap Value of a Hacked PC (3)

Security.1 8

Page 9: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

The Scrap Value of a Hacked PC (4)

Security.1 9

Page 10: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Overview: Multiple Layers of Security

• Explain Bad Guy uses for your PC

• Layers of Security

– Obey 3 Basic Rules of Safety

Security.1 10

Page 11: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Krebs’s 3 Basic Rules for online safety

Security.1 11

1) If you didn’t go looking for it, don’t install it

2) If you installed, update it

3) If you no longer need it, get rid of it!

Page 12: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Overview: Multiple Layers of Security

• Explain Bad Guy uses for your PC

• Layers of Security

– Obey 3 Basic Rules of Safety

– Keep up-to-date with Updates

Security.1 12

Page 13: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Keep Up-to-Date with Updates

Security.1 13

1) Secure By Design’s: Ninite

2) FileHippo’s: Update Checker

3) Secunia’s: Personal Software Inspector

4) Microsoft’s: Security Update

Page 14: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Ninite

Security.1 14

Page 15: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Ninite Updater

Security.1 15

Page 16: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

FileHippo Updater

Security.1 16

Page 17: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

FileHippo Updater

Security.1 17

Page 18: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Keep Up-to-Date with Updates

Security.1 18

Page 19: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Secunia PSI Updater

Security.1 19

Page 20: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Overview: Multiple Layers of Security

• Explain Bad Guy uses for your PC

• Layers of Security

– Obey 3 Basic Rules of Safety

– Keep up-to-date with Updates

– Put a Leash on JavaScript

Security.1 20

Page 21: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Managing JavaScript

Security.1 21

Most Web sites use JavaScript, a powerful scripting

language that helps make sites interactive.

Unfortunately, a huge percentage of Web-based attacks

use JavaScript tricks to foist malicious software and

exploits onto site visitors.

To protect yourself, it is critically important to have an easy

method of selecting which sites should be allowed to run

JavaScript in the browser.

Page 22: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

JAVA Control

Security.1 22

Page 23: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

JAVA Control

Security.1 23

Page 24: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

JavaScript Control

Security.1 24

Page 25: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

JavaScript Control

Security.1 25

0

Page 26: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

JavaScript Control

Security.1 26

0

Page 27: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

JavaScript Control: NoScript (Firefox)

Security.1 27

Page 28: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

JavaScript Control: NotScripts (Chrome)

Security.1 28

Page 29: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Overview: Multiple Layers of Security

• Explain Bad Guy uses for your PC

• Layers of Security

– Obey 3 Basic Rules of Safety

– Keep up-to-date with Updates

– Put a Leash on JavaScript

– Use Enhanced Mitigation Experience Toolkit

Security.1 29

Page 30: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

EMET

Security.1 30

EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security of commonly used applications, whether they are made by a third-party vendor or by Microsoft.

EMET allows users to force applications to use one or both of two key security defenses built into Windows Vista and Windows 7 — Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).

Page 31: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

EMET

Security.1 31

Put very simply, DEP is designed to make it harder to exploit security vulnerabilities on Windows, and ASLR makes it more difficult for exploits and malware to find the specific places in a system’s memory that they need to do their dirty work.

EMET can force individual applications to perform ASLR on every component they load, whether the program wants it or not.

Page 33: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Links: Multiple Layers of Security

1. Tools for a Safer PC

https://krebsonsecurity.com/tools-for-a-safer-pc/

2. Ninite web-site

https://ninite.com/

3. FileHippo UpdateChecker

http://www.filehippo.com/updatechecker/

4. Secunia PSI web-site

https://secunia.com/vulnerability_scanning/personal/

5. Learn how to enable JavaScript in the most popular web browsers.

http://activatejavascript.org/en/instructions

6. NoScript Firefox Add-On

https://addons.mozilla.org/en-US/firefox/addon/noscript/?src=search

7. NotScripts: Google Chrome Extension

https://chrome.google.com/webstore/detail/notscripts/odjhifogjcknibkahlpidmdajjpkkcfn

8. Installing and Configuring EMET (VIDEO)

https://www.microsoft.com/en-us/showcase/details.aspx?uuid=7683a9cb-28c9-428f-ada6-8adafd2efbee

9. Enhanced Mitigation Experience Toolkit v3.0

https://www.microsoft.com/en-us/download/details.aspx?id=29851

Security.1 33

Page 34: Improving Windows SecurityEMET Security.1 30 EMET, short for the Enhanced Mitigation Experience Toolkit, is a free tool from Microsoft that can help Windows users beef up the security

Thank You!

Security.1 34