<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>The Security Catalyst&#187; virus</title>
	<atom:link href="http://www.securitycatalyst.com/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>harnessing the human side of security</description>
	<lastBuildDate>Wed, 25 Jan 2012 15:57:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>harnessing the human side of security</itunes:summary>
	<itunes:author>The Security Catalyst</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/wp-content/plugins/powerpress/itunes_default.jpg" />
	<itunes:subtitle>harnessing the human side of security</itunes:subtitle>
	<image>
		<title>The Security Catalyst&#187; virus</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com</link>
	</image>
		<item>
		<title>When Burning Buildings Become BlasÃ©</title>
		<link>http://www.securitycatalyst.com/2008/12/when-burning-buildings-become-blase/</link>
		<comments>http://www.securitycatalyst.com/2008/12/when-burning-buildings-become-blase/#comments</comments>
		<pubDate>Thu, 04 Dec 2008 21:39:51 +0000</pubDate>
		<dc:creator>Guest Blogger</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=599</guid>
		<description><![CDATA[by Michael Starks Imagine if a building on every street started on fire every day.Â  They are small fires, which cause relatively little damage, and are usually quickly extinguished by the sprinkler system.Â  Every once in awhile, the entire house burns down because the sprinkler system hasn&#8217;t been updated in over a year.Â  Now imagine [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<p class="MsoNormal"><strong><a href="http://www.securitycatalyst.com/wp-content/uploads/2008/12/fire.jpg"><img class="alignleft size-full wp-image-971" title="fire" src="http://www.securitycatalyst.com/wp-content/uploads/2008/12/fire.jpg" alt="fire" width="150" height="150" /></a>by Michael Starks</strong></p>
<p class="MsoNormal">Imagine if a building on every street started on fire every day.<span>Â  </span>They are small fires, which cause relatively little damage, and are usually quickly extinguished by the sprinkler system.<span>Â  </span>Every once in awhile, the entire house burns down because the sprinkler system hasn&#8217;t been updated in over a year.<span>Â  </span>Now imagine that people have come to believe that this is normal and expected, that as long as you keep your sprinkler system updated, you should be OK. And if the sprinkler system does its job, the fires aren&#8217;t a problem.</p>
<p class="MsoNormal">While analogies are never perfect, this is the basic situation we have today with viruses and anti-virus software.<span>Â  </span>Billions of dollars are spent in defending against viruses, with software ranging from simple desktop scanners to multi-tired, enterprise class anti-virus defense ecosystems.<span>Â  </span>When they catch viruses and other forms of malware, we judge them to be successful.<span>Â  </span>We run reports with nice graphs to show management, and as long as the viruses are being caught, we feel our information is safe.</p>
<p class="MsoNormal">While few dispute that anti-virus software is a necessity in a modern computing environment (particularly, one which contains Microsoft Windows), fewer still frame anti-virus in the proper context.<span>Â  </span>How many look at the number of viruses caught, juxtapose them with the effectiveness of the software in catching viruses, and make a plan to reduce the number of viruses detected?<span>Â  </span>In other words, how many ensure the anti-virus software is working as intended, then work to reduce the infection rate?</p>
<p class="MsoNormal">Viruses and other malware are not simple problems to solve, but there are solutions to reducing the number of infections that do not depend on the use of anti-virus software.<span>Â  </span>Among them:</p>
<p class="MsoNormal">-Reducing the rights a user has to run and install software.<span>Â  </span>Do your users run with Administrator rights by default?<span>Â  </span>Why?<span>Â  </span>If they&#8217;re not changing network settings, installing software and looking at logs on a regular basis, most people don&#8217;t need these rights as a part of their normal job.</p>
<p class="MsoNormal">-Educating users about safe computing.<span>Â  </span>When a virus is detected, do you interview the user in an attempt to determine how the infection occurred?<span>Â  </span>Viruses, at least for now, are not spontaneous phenomena.<span>Â  </span>Something happens for that infection to take root.<span>Â  </span>Usually, unsafe computing behavior is involved.</p>
<p class="MsoNormal">-Educating users about appropriate use.<span>Â  </span>Are your users installing personal software or games (see #1), connecting to untrusted networks or surfing to personal web sites?<span>Â  </span>To what extent are you willing to allow for these activities versus the cost of increased virus rates?</p>
<p class="MsoNormal">-Examining the choke points for data entering the network.<span>Â  </span>While the perimeter is becoming increasingly porous, looking at data flow is critical in determining how infections occur.<span>Â  </span>Do most occur from drive-by downloads, or are they due to e-mail attachments?<span>Â  </span>By looking at data flow, protections can be put into place to reduce the chance of viruses entering the network.</p>
<p class="MsoNormal">Notice that all of the points mentioned involve process, education and analysis.<span>Â  </span>None of them involve spending more money on more defense technology.<span>Â  </span>While that may at times be the natural outcome of the process, it should not be the first reaction.</p>
<p class="MsoNormal">Anti-virus software isn&#8217;t perfect; in fact, the ability for anti-virus software to detect modern malicious code has been declining in recent years.<span>Â  </span>While still needed, we need to look our perception of its role in protecting information. Is it our first and only line of defense or is it an alarm that something else has failed?<span>Â  </span>By shifting our thinking to the root causes of infections, and by focusing on solutions to those problems, we can reframe anti-virus software as primarily IDS, rather than IPS.<span>Â  </span>We can set goals for increasing the effectiveness of preventing malicious code, while simultaneously reducing the number of detections found.<span>Â  </span></p>
<p class="MsoNormal">Virus infections are an anomaly that we have been trained to accept as normal.<span>Â  </span>By shifting our thinking towards anti-virus as a rarely activated sprinkler system, we&#8217;ll go a lot further towards keeping our information safe.</p>
<p class="MsoNormal"><!--StartFragment--><span><em>Michael is an Information Security Professional specializing in host-based security, IDS, log analysis and compliance. He believes in applying basic security principles to an ever-changing threat landscape, and is currently exploring the various ways in which human behavior affect the success of security programs. Â He is a founding member of the Rochester, NY chapter of ISSA and has served for both ISSA and OWASP. He currently holds the CISSP, GSNA and A+ certifications. Â In his spare time, Michael enjoys spending time with his wife and daughter, and listening to early twentieth-century blues.</em></span><!--EndFragment--><em>Â  </em></p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/12/when-burning-buildings-become-blase/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Donâ€™t Ignore the Facebook Virus</title>
		<link>http://www.securitycatalyst.com/2008/08/don%e2%80%99t-ignore-the-facebook-virus/</link>
		<comments>http://www.securitycatalyst.com/2008/08/don%e2%80%99t-ignore-the-facebook-virus/#comments</comments>
		<pubDate>Fri, 08 Aug 2008 22:00:53 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=504</guid>
		<description><![CDATA[By David E. Stern, CISSP Every day, dozens of new vulnerability or virus alerts are released to warn and inform the public. The IT community, including those in IT security have become fairly numb to these alerts. For the most part, as long as patches are pushed out, and antivirus signatures are kept up to [...]]]></description>
			<content:encoded><![CDATA[<p><strong>By David E. Stern, CISSP</strong></p>
<p class="MsoNormal">Every day, dozens of new vulnerability or virus alerts are released to warn and inform the public. The IT community, including those in IT security have become fairly numb to these alerts. For the most part, as long as patches are pushed out, and antivirus signatures are kept up to date, these releases make little impact. The occasional worm or botnet will grab headlines, but the accompanying vigilance soon fades. Itâ€™s an unfortunate consequence of the virulent Internet environment.</p>
<p class="MsoNormal">I have never had much interest in using my Facebook account, so when I saw the advisory relating to Facebook and Myspace virus activity, I let it fade into the background noise. In fact, my inbox was filling up with â€œsillyâ€ Facebook notifications to the point of annoyance, so I logged in with the intention of clearing out my connections. Taking stock of the large number of friend associations that I had led me to an AHA moment; EVERYONE uses Facebook.</p>
<p class="MsoNormal">Facebook isnâ€™t just a toy for feinding teens. It is used by people of all ages on all of their computers, whether at work or at home. It is a fertile breeding ground and conduit for Web 2.0 content. In this case, it is the perfect launch pad for a worm: huge market penetration and a very large and mainly clueless wetware population.</p>
<p class="MsoNormal">The same can certainly be said about most other virus outbreaks. But in the case of Facebook, there are simply too many good reasons to make that fateful click. Users may think twice about falling for a phishing scam or even clicking on the dancing pig, but Facebook is the forbidden apple. I am not advocating taking any actions against Facebook use. The resulting effort would be a waste of time.</p>
<p class="MsoNormal">Consider the following example: A toy manufacturer announces a recall of a popular toy due to dangerous chemical contained within. Your child doesnâ€™t have the toy, but you will probably want to make sure that his school and friends donâ€™t have it either.</p>
<p class="MsoNormal">Take the time to generate an internal email blast warning all employees to be extra careful. Spend a little more time looking at security logs. Finally, take a walk over to the help desk manager and ask him to keep an eye out for increased ticket volume.</p>
<p class="MsoNormal">Donâ€™t ignore this one.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/08/don%e2%80%99t-ignore-the-facebook-virus/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

