1 of 41

SECURITY

CS 6 -

EFFECTIVE USE OF THE WORLD WIDE WEB

CS 6 – Effective Use of the World Wide Web

2 of 41

DISCLAIMER

  • The content of this presentation (slides) is explicitly for informational purposes only. It is *not* intended to encourage, educate, or facilitate nefarious or illegal activity such as hacking, identity theft, or any other computer relates offense, neither serious nor minor.

CS 6 – Effective Use of the World Wide Web

3 of 41

Malware

Malware is short for malicious software:

computer programs that are designed to conduct unwanted actions on your device.

Computer viruses are malware. So are programs that steal passwords, secretly record you, or delete your data.

CS 6 – Effective Use of the World Wide Web

https://ssd.eff.org/en/glossary/malware

4 of 41

Malware - examples

  • Adware
  • Spyware
  • Viruses
  • Trojans
  • Keyloggers
  • Ransomware

CS 6 – Effective Use of the World Wide Web

5 of 41

Malware - Virus

  • Computer virus - malicious code that attaches itself to a legitimate program or a document that allows macros to run.
    • Designed to:
      • spread to other hosts, i.e. self-replication
      • alter the way the host computer operates
    • Can lie dormant, user unaware device is infected
    • 2 most common types:
      • Executable virus: Attaches itself to programs
      • Macro virus: Attaches itself to macros in documents

CS 6 – Effective Use of the World Wide Web

6 of 41

Malware - Virus

  • How are viruses spread?
    • Email attachments (most common method)
    • Internet file downloads
    • Social media scam links
    • Non-reputable app downloads
    • Links of search results
    • Removable media (i.e. USB drives)

CS 6 – Effective Use of the World Wide Web

7 of 41

Macro - Definition

  • A macro in a document (such as a Word doc or Excel spreadsheet) is:
    • A series of recorded or programmed instructions that automate repetitive tasks
  • The software (i.e. Word or Excel) has options to disable Macro processing.
    • This should be done if opening a downloaded document.

CS 6 – Effective Use of the World Wide Web

https://gcc.gnu.org/onlinedocs/cpp/Macros.html

8 of 41

Malware - Worm

  • Computer Worm - A type of self-replicating malware that spreads across networks by exploiting security vulnerabilities.
    • The vulnerabilities that a worm exploits need not be exclusively software faults.
    • May also exploit configuration errors or operator errors.
  • Worms spread autonomously, meaning they do not need user intervention to replicate and infect other systems.
  • Unlike viruses, worms do not replicate by attaching themselves to a host executable or modifying the system environment to execute the malicious code.

CS 6 – Effective Use of the World Wide Web

9 of 41

Malware - Virus Protection

  • Anti-virus software
    • Avast (free version)
    • Norton
    • McAfee
    • Pay for the service
  • Set up admin account with password
    • Forces all significant changes to system to be password authenticated.
    • Prevents 3rd party download installation, without login
  • Turn-on Automatic Updates
    • https://www.microsoft.com/en-us/windows/ comprehensive-security

CS 6 – Effective Use of the World Wide Web

10 of 41

Automatic Updates - macOS 10.13

CS 6 – Effective Use of the World Wide Web

11 of 41

Operating System Lifecycle

  • Research product software support life cycle.
  • Windows 10 update and retirement (i.e. end of life) calendar: October 2025
  • https://support.microsoft.com/en-us/help/13853/windows- lifecycle-fact-sheet

  • When OS has reached its end of life date, no more updates (even for security-related issues) are made for it

CS 6 – Effective Use of the World Wide Web

12 of 41

Operating System Lifecycle

  • Software is versioned, not supported with updates forever
  • Support for Windows XP Ended
  • https://www.microsoft.com/en-us/windowsforbusiness/end- of-xp-support
  • Support for Windows 7 Ended
  • https://www.microsoft.com/en-us/windows/windows-7-end- of-life-support-information
  • When support ends, then no current or future security patches or bug fixes are published.
  • Software is static and cannot defend against new threats.

CS 6 – Effective Use of the World Wide Web

13 of 41

Stuxnet Worm

  • Uncovered in 2010
  • Infected Nuclear Sites in Iran
  • Caused centrifuges to fail at unprecedented rate
  • Caused computers to turn-off and reboot incessantly
  • Effects were not just system hijacking or information acquisition

CS 6 – Effective Use of the World Wide Web

14 of 41

Malware - Trojan horse

  • Pretend to be a desirable programs, but are malicious. Trojan horses contain a malicious code which, when executed, causes loss or theft of data.
  • Can create a back door on a computer. The back door gives another user access to a system, and possibly allows confidential or personal information to be compromised.
  • Unlike viruses and worms, Trojan horses do not:
  • reproduce by infecting other files
  • self-replicate

CS 6 – Effective Use of the World Wide Web

15 of 41

Malware - Other

  • Adware - automatically displays or downloads advertising material (often unwanted) when a user is online
  • Spyware - collects personal information about users without their consent
    • Keyloggers - record every keystroke
  • Ransomware - Locks users out of their computer systems or encrypts their files, demanding a ransom payment for their release or decryption (usually have to use Bitcoin)
  • Ransomware Gangs - Organized cyber-criminal groups that develop and deploy ransomware to extort victims by encrypting their data

CS 6 – Effective Use of the World Wide Web

16 of 41

WannaCry Ransomware 05-12-17 to 05-15-17

CS 6 – Effective Use of the World Wide Web

https://upload.wikimedia.org/wikipedia/en/1/18/Wana_Decrypt0r_screenshot.png

17 of 41

Denial of Service Attack (DoS)

  • A denial-of-service (DoS) attack occurs when legitimate users are unable to access information systems, devices, or other network resources due to the actions of a malicious cyber threat actor.
  • Services affected may include web sites, email, online accounts (e.g., banking), or other services that rely on the affected computer or network.

CS 6 – Effective Use of the World Wide Web

18 of 41

Denial of Service Attack (DoS)

  • A denial-of-service is accomplished by flooding the targeted host or network with traffic until the target cannot respond or simply crashes, preventing access for legitimate users.
  • DoS attacks can cost an organization both time and money while their resources and services are inaccessible.

https://www.us-cert.gov/ncas/tips/ST04-015

CS 6 – Effective Use of the World Wide Web

19 of 41

Firewall - Protection

  • A firewall is a security application that acts as a barrier between a computer or network and the outside world
  • Usually, access attempts are blocked, unless you give permission.
  • MS-Windows now comes with a firewall installed.
  • Works on a per-program basis. You can choose what programs are allowed to use your network connection, and in what ways.
  • Macs also have a built-in firewall. Based on programs. More advanced features can be enabled.

CS 6 – Effective Use of the World Wide Web

20 of 41

Zombie Computer

  • When your computer is controlled remotely, without your knowledge, to do bad things.
  • Zombies are part of what is called a botnet.
  • Examples - send spam, infect users to mine bitcoins, participate in a distributed DOS (DDOS) attack

CS 6 – Effective Use of the World Wide Web

21 of 41

Automate - Reminder

  • Things that should happen automatically:
    • Retrieving and installing program updates.
    • Scanning any email attachments and downloads.
    • Schedule computer scans nightly.
    • Schedule backups nightly or use cloud backup software

CS 6 – Effective Use of the World Wide Web

22 of 41

Hackers - Target Large User Bases

  • Majority of the world uses Windows for their laptop/ desktop
  • Most Windows users use Outlook or Outlook Express for their email client
  • Majority of the world uses Chrome
  • If you were going to hack a computer system, which one would you target?
  • Obscurity is not a substitute for security.
  • Still need to be careful.

CS 6 – Effective Use of the World Wide Web

23 of 41

Passwords

  • You should have a unique password for every site or application that you use.
  • How to keep track of all those passwords?
  • Password Manager
  • General idea - Passwords are encrypted in vault (folder). Use a master key to unencrypted and access
  • Should use browser password manager at minimum!

CS 6 – Effective Use of the World Wide Web

24 of 41

Password Checklist

  1. Use letters (UPPERCASE and lowercase), digits, and special characters (!@#$%^&...)
  2. Don’t write down or store in obvious location
    • On your computer
    • In your email
    • On paper
  3. Longer passwords are better (at least 12 chars)
  4. Never use the same password for two sites
  5. Never share your password with anyone, ever
  6. Immediately change a password if compromised
  7. Periodically change passwords, logout and re-login
  8. Use multi-factor authentication

CS 6 – Effective Use of the World Wide Web

25 of 41

Passwords

  • Create as long (num chars) as possible
  • 22-25 characters in length (harder to crack)
  • Use special characters when allowed
  • Use combination of lower case and upper case
  • Can use catchphrases, DoRDo!Yod4
  • Don’t share!
  • Don’t write down!
  • Use multi-factor authentication when available
    • Something you know (PIN, password)
    • Something you have (ATM card, phone)

CS 6 – Effective Use of the World Wide Web

26 of 41

Multi-factor Authentication

  • Multi-factor Authentication (MFA) -
    • Example: two-factor authentication or 2FA security enhancement that allows you to present two pieces of evidence – your credentials – when logging in to an account.
  • Your credentials fall into any of these three categories:
  • something you know (password or PIN)
  • something you have (smart card, smartphone, email address)
  • something you are (fingerprint, or other biometric).
  • Your credentials must come from two different categories to enhance security – so entering two different passwords would not be considered multi-factor.

CS 6 – Effective Use of the World Wide Web

27 of 41

CS 6 – Effective Use of the World Wide Web

28 of 41

Scenario - Gain Trust

  • Scenario A - If someone walked up to you on the street and said…
    • Q: “Would you mind giving me your: social security number, driver’s license number, all of the passwords to your computer accounts, back accounts, credit card numbers, and PINS?”

    • A: “NO!” (and get away from this person)

  • Scenario B - If someone walked up to you on the street wearing a formal blue suit or uniform, and showed you a badge indicating she was a detective or government agent, and asked the same question…
    • You should pause and be reluctant to hand over personal information. Namely a warrant, or other legally binding obligation.

CS 6 – Effective Use of the World Wide Web

29 of 41

Malicious Social Engineering

  • Malicious “social engineers”
    • use manipulation, deception and influence to persuade an employee or contractor to unwittingly disclose secure information
    • or persuade someone to perform an action which grants unauthorized access to an organization’s information systems
    • can occur in person, over the phone, or online

  • Malicious imposters can be a bigger threat to the security of your organization since less technical skill is needed.

CS 6 – Effective Use of the World Wide Web

30 of 41

Phishing - What is it?

History - Phishing was first described in 1987, Internet was in use, WorldWideWeb was not invented until 1990-1991.

Password Harvesting Fishing

  • Email is designed to appear from a reputable organization’s legitimate source, e.g. Bank of America, Google, IRS
  • Uses actual content from the reputable organization’s site,

e.g. logos, images, and fonts.

  • Some go to such extremes as to use the actual customer service or help line toll-free phone number.
  • Easy to get duped

CS 6 – Effective Use of the World Wide Web

04/21/18

31 of 41

Phishing - Cheat Sheet

  • Skepticism Saves
    • Before entering information, think: “How did I get to this company?” Typing their URL or web searches are okay; clicking a link in an email or on a social network site is not.
    • Pay attention to the domain name of the company

CS 6 – Effective Use of the World Wide Web

32 of 41

Phishing - Cheat Sheet

  • Skepticism Saves
    • How likely is it that you are owed money you don’t know about, or that a company bothers its customers to do an audit?
    • Open attachments only when you know who sent them and why.
    • Only give information online when you have initiated the transaction yourself by going to the company.

CS 6 – Effective Use of the World Wide Web

33 of 41

Phishing - Protection

CS 6 – Effective Use of the World Wide Web

34 of 41

Phishing - What can you do?

  • Take your time, evaluate all messages you will reply to
    • Is there a sense of urgency? If yes, that is bad…
    • Does the email look legitimate?
    • Do you expect messages from sender?
    • Is there a previous message (legitimate) to compare to?
    • Can you initiate contact through independent means?
    • Is there a phone number you can call instead?
    • Can you initiate contact via website?

CS 6 – Effective Use of the World Wide Web

35 of 41

*ishing

  • Smishing - uses text messages
  • Vishing - uses phone calls or voice mails
  • Quishing - uses QR codes

CS 6 – Effective Use of the World Wide Web

36 of 41

Device location & recovery

  • Google and Apple offer device location assistance services
  • Determine location
    • GPS - sensor in phone measure time signals take to reach satellites
    • GPS tracking - not done by satellites, rather software on phone that logs GPS location of phone
    • Cell tower triangulation
  • Find, lock, or erase your lost phone or computer

CS 6 – Effective Use of the World Wide Web

37 of 41

SPAM*

  • The term spam is widely believed to derive from a Monty Python skit in which the word “spam” was chanted by Vikings to drown out restaurant conversation about spam (food).
  • Showed unwanted input impedes legitimate communication.
  • Over 50% of all emails sent over the Internet are spam
  • If "junk" email is spam, is there a term for legitimate email? There is, and as you might expect, that term is ham, mostly used by anti-spam software developers.
  • source: Fluency 7 by Snyder

CS 6 – Effective Use of the World Wide Web

38 of 41

SPAM Origins

CS 6 – Effective Use of the World Wide Web

39 of 41

Virtual Private Network (VPN)

  • A virtual private network, or VPN, is an encrypted connection over the Internet from a device to a network
  • The encrypted connection helps ensure that sensitive data is safely transmitted.
  • It prevents unauthorized eavesdropping web traffic.
  • Allows user to conduct work remotely.

  • Review Best VPN 2020 (CNET):

  • Source: Cisco

CS 6 – Effective Use of the World Wide Web

40 of 41

Backup Data

  • Use physical devices/services to store most recent saves.
  • Better to automate, so you do not forget
  • Closer last save is to your most recent edits the better
  • Examples:
    • Azure (Microsoft)
    • Google Cloud or Drive
    • Dropbox
    • Box
    • Etc.

CS 6 – Effective Use of the World Wide Web

41 of 41

Data Breaches

  • Expose large volumes of data at once
  • Can affect hundreds millions of users
  • One attack, perhaps cumulative, large breach
  • Often attack centers on a single individual
  • Exploits an individual’s weakness or practice
  • Be vigilant
  • Take seriously
  • Personal responsibility - be a reliable employee or member of corporation or entity
  • Be accountable to your employer
  • Be accountable to yourself

CS 6 – Effective Use of the World Wide Web