Want to be more secure? Don’t be stupid
The ideal way to defend against most network vulnerabilities is to deal with the simplest attack vectors, according to Australia’s Defence Signals Directorate (DSD).
The DSD’s analysis has credibility and clout, because it’s based on analysis of real attacks launched against Australian government networks. And according to its latest work, as much as 85 percent of attacks can be addressed with four relatively straightforward defences.
These are, in order: keep applications patched and use the latest version of applications (Flash, the Acrobat PDF viewer, Microsoft office and Java are singled out); patch operating system vulnerabilities; minimize the number of users with administrative access to systems (while making sure that your BOFH doesn’t use an admin account for e-mail and browsing); and whitelist your applications.
Not completely: actually, the DSD includes 35 recommendations. But to knock off the maximum number of attack vectors with the least effort, those four strategies have serious bang-for-buck.
There are others that are worth mentioning – such as whitelisting e-mail content, sanitizing attachments, blocking spoofed e-mail addresses with a sender policy framework, Web content filtering (including HTTPS and SSL domains), multi-factor authentication and so on. But the large four should be everybody’s starting point.
Such advice would hardly be newsworthy, except for one thing: the large number of successful attacks shows us just how few people can get the basics right.
Interestingly, the DSD research also indicates that attackers are looking for bang-for-buck. The same analysis for 2010 found that the four strategies outlined above would have only repelled 70 percent of attacks. Attackers, it seems, can be just as interested in convenience as those they attack. ®
source : go.theregister.com
Other Post:
- Steve Jobs speaks Flash, 'lying S.O.B devs', sex, and Gizmodocrime
- HP Pavilion dm3 13-inch Laptop Price Cut
- AMD Driver Autodetect
- Oracle loses another open storage star
- Photoshop CS5 One-on-One--New from O'Reilly: Your Guide to Photoshop CS5's New Features and Functionality
- Oracle Exadata gains certification for SAP applications
- Samsung NS310 10.1-Inch Netbook
- Microsoft to devs: Don't ruin Win 8 launch with crap code
- Aus start-ups get in the Silicon Valley house
- iPhone 4 Bumper Case Fix Okayed by Consumer Reports
Details :
Submited at Monday, July 25th, 2011 at 2:00 am on News by Alina
Comment RSS 2.0 - leave a comment - trackback
