Showing posts with label firewall. Show all posts
Showing posts with label firewall. Show all posts

9.15.2007

Comments on Slashdot - Re Ameritrade Fiasco...

I recently responded to a comment made on Slashdot about one of their articles. The article covered an audit made of Ameritrade's system and the fact that it had a 'back-door' in it. One of the readers made a comment that seems reasonable at first, but belies the difficulty of security a computer or a network.

Below is the text of my reply and here is a link to the original comment by mkraft and a link to the original Slashdot article.
---------------------------------------------------------------------

mkraft: In reference to your statement "How does unauthorized code even get into a financial institution's systems? The banking systems should never be accessible via public networks, only private ones, so this should never have happened."

It, unfortunately, is not that easy. As soon as one computer is connected to another computer (via wireless, wired networks or 'sneaker-net'), problems with security start to cascade. If a computer has a USB port, a CD drive, DVD drive, or a network connection, it is nearly impossible to lock down - malware will find it's way onto the machine.

The U.S. and foreign governments spend a fortune trying to lock down some of their most sophisticated computers and networks and still they leak like a sieve.

Although we may wish that it were otherwise, we can hardly expect for a company whose bottom line is the profit margin, to spend all that it takes to secure even one computer...

Consider the magnitude of the problem:
- Keep the network holes plugged as much as possible
- Keep the operating system patched
- Keep all of the applications (including the off-the-shelf and home-grown applications) patched - Keep all security software patched and updated
- Most importantly, keep all employees from doing anything remotely silly or risky

Many of the items above, are nearly impossible to do well - for example...if a typical patch for a piece of software arrives ~5 days after the vulnerability is announced, what is the financial institution supposed to do for those 5 days? NOTE: the 5 days is a fictitious number - no one achieves that high a speed in issuing and applying patches...but it illustrates the point...

There is no way for an underpaid, overworked security staff to plug EVERY hole - especially in the world of zero day exploits. The hackers, on the other hand, have automated tools that can plug at the problem 24/7 until they find even one, overlooked hole...
--
Chalmer

2.08.2007

Hacked in 39 seconds...

Just a quick point of reference regarding how prevalent probes and scans are on the Internet.

When you connect to the Internet, your computer is almost immediately being scanned by the bad guys. The researchers in this article found that their test computers were assaulted 2,244 times in 24 hours, or an average of every 39 seconds.

What does the astute reader do to keep themselves safe? Keep your defenses up - anti-virus, firewalls, etc.

Chalmer

1.04.2007

Firewalls: the big picture

In fire protection, a firewall is a solid, fire resistive barrier that keeps fire burning on one side of the wall from burning valuable material on the other side of the wall. In computing, a firewall serves a similar purpose: separate bad guys and your valuable data. Firewalls come in two flavors: software (computer programs) or hardware (equipment or stand-alone boxes). There are benefits and disadvantages to both:

Software Firewalls:

  • Generally installed directly on your computer
  • Goes everywhere your computer goes (important if you use a laptop)
  • Often fairly inexpensive and/or free
  • Uses your computer's processor to do it's work, which can sometimes bog down your computer slightly (Modern computers should not be tremendously affected.)
Hardware Firewalls:
  • Installed physically on the cable or network that connects you to the Internet
  • Generally NOT portable (important if you use a laptop)
  • Does not use any of your computer's processing power to do it's job
  • Can be more expensive and takes up space on your desk
What do firewalls do:

Firewalls help separate two worlds. The world of the bad guys and your world. Firewalls work to keep traffic from traveling in both directions: keeps attacks out (inbound filtering) and keeps your private info in (outbound filtering).
  • Inbound filtering:
    • Probes and scans: bad guys often try to probe or scan your computer and your network to see what programs you have, what operating system you run, what ports you have open and what files or other information you have. With this info, they can
      decide which attacks would be most effective.
    • Flooding and Denial-of-Service: bad guys may try to prevent legitimate people from reaching your computer or network, by flooding your computer with traffic.
    • Bad or malformed traffic: some messages sent to your computer can actually cause your computer to lock up or crash, because it does not understand the message and gets "confused".
    • Storage: Some bad guys don't want anything off your computer, but they may want to put something on it. The bad guys will sometimes store pirated software or child porn images on other people's computers, so keeping the bad guys off your machine is critical

  • Outbound filtering:
    • Phone home: Just like E.T. wanted to "phone home" sometimes you will get infected by viruses or other junk from the bad guys. Often, these programs will want to phone home to get more instructions, to send your private info to the bad guys or to
      open up gateways so that more powerful programs can be installed secretly on your computer.
If you don't have a firewall installed, get one. Some of them include firewalls from Norton, McAfee, Comodo, Sunbelt/Kerio, ZoneAlarm, etc. Most are available for download off the Internet. Some are free. Some will cost you.

Chalmer

12.31.2006

New Year Resolutions: Anti-virus, Firewall and Anti-Spyware

Happy New Year!

With the New Year upon us and everyone in the throes of new resolutions, I propose three information security resolutions:

  • Set up anti-virus software
  • Set up a firewall
  • Set up anti-spyware software
All of these are fairly simple and well worth your effort. In the next few articles, we will discuss the hows and whys of these three resolutions. See you soon!

Chalmer

Google