Friday, October 21, 2011

New Mac Virus

Although viruses are much rarer in the Mac world than in Windows, they are not unheard of.  CNET reports that a new Trojan has been discovered that pretends to be an installer for Adobe Flash.  Once embedded, it attempts to send your personal information to remote computers.  CNET says that while this is the latest attack to surface, there are others out there as well.

Compared to Windows malware, Mac attacks are pretty rudimentary, much less common, and easier to spot.  In this case, all you have to remember is to never install Adobe Flash from a pop-up window that appears on your screen.  Instead, go to the Adobe website and get it from there.  However, it's a good idea for Mac users to install anti-virus software even though at the present, the risk of infection is pretty small.

To learn more about this latest Mac attack, check out the CNET article here.

Tuesday, October 18, 2011

Is Your Firewall Good Enough for Today's Threats?

When was the last time you thought about the firewall that protects your network from outside intrusion?  Do you even know if your network has a firewall ?  And if it does, is it good enough to protect against threats being mounted by today's hackers ?  Just what is a firewall, anyway?

In simple terms, a firewall is a device that looks at the data traffic coming into your network to detect and block unauthorized access.  It compares the data with a set of rules in its memory to reject transmissions determined to be malicious.  Firewalls can be either hardware devices or software that runs on your computer.  For a network of any size, you need a hardware firewall.  You can usually find it built into the router at the head of your network.

Many small businesses use inexpensive routers/firewalls designed primarily for residential use.  Such firewalls have limited ability to detect today's sophisticated threats.  Even a business-grade firewall, especially one more than a couple of years old, may be susceptible.  As hackers become more sophisticated in their attacks, the industry has responded with next-generation firewalls that combine traditional stateful packet inspection with advanced intrusion detection capabilities.

A recent article in CSO Online magazine explains the limitations of traditional firewalls and the benefits of next-generation firewalls: Next-generation firewalls: in depth.  It's fairly technical, but the key point is that to protect against many of today's threats you need a firewall that combines traditional inspection with advanced intrusion detection techniques to perform deep packet inspection.  Such a firewall also gives you considerable flexibility in deciding who has access to which applications.  For example, your marketing department can be granted access to Twitter and Facebook to maintain your company's on-line presence while other departments are blocked from access.

Take a look at your network's firewall.  It's the first line of defense against malicious intruders, so it's not an area where you want to scrimp with your investment.  If your firewall is several years old or if it's a product more suitable for residential use, give serious consideration to upgrading to a true next-generation firewall.  And if you need help selecting and installing the right product, give TeamLogic IT a call.  We have experience with many kinds of solutions and can guide you to the best one for your network.

Wednesday, October 12, 2011

Where Do Malware Threats Come From?

Many people think that most malware gets into your system through sofware vulnerabilities that haven't yet been discovered and fixed by the manufacturer.  These kinds of attacks (called "zero-day vulnerabilities") make headlines and can lead you to believe there's not much you can do to stop them.  If the software manufacturer hasn't discovered the threat and issued a patch to fix it, what can you do?

A recent study by Microsoft found that such beliefs are largely unfounded.  Using software tools they deploy to track such events, they found that only 0.01% of all attacks exploit zero-day vulnerabilities.  Nearly 50% of attacks use social engineering techniques to trick the user into clicking a link or revealing private information (see my last blog entry for more on this story).  What can you do to protect yourself?  Besides the obvious of not clicking on suspicious links or disclosing private information to strangers, you should also make sure you are running the most recent versions of your applications.  According to outside tests, for example, Internet Explorer 9 is more resistant to malware attack than any other browser.  Here's a link to an Information Week story about the Microsoft study: Zero-Day Threats Exaggerated, Says Microsoft Report.

Sunday, October 2, 2011

Employees are a Company's Biggest Security Risk

Hackers are continually evolving the ways they attack business computer networks.  While "brute force" attacks in which the hacker makes multiple attempts in quick succession to guess a user's password are still common, sophisticated hackers have moved toward more sinister methods of attack.  Imagine getting an email from your boss, addressed to you and your closest colleagues, describing a change to the project you are working on and asking you to open an email attachment for more details.  Only the email isn't from your boss, it's from a hacker who used such resources as Facebook, Twitter, and LinkedIn to learn enough about you and your job to craft a legitimate-looking email.  Opening the email introduces a virus into the network that lets the hacker gain unchecked access.  This is just one of the ways hackers are circumventing traditional safeguards.  Here's an article from the Wall Street Journal that should be required reading for every employee in your business: What's a Company's Biggest Security Risk? You!