Your Ad Here

Network Security

Filed under: , , by: Network World

What is Network Security:

Network security involves all activities or actions that organizations, enterprises, and institutions undertake to protect the value and ongoing usability of assets like data and the integrity and continuity of operations like queries.

An effective network security strategy requires

  • Identifying the nature of the threats
  • Choose effective set of tools to effectively remove the threats .
Network Security covers how to secure the network from external and internal attacks

External Attacks:
External to the company or organization or network

Internal Attacks:

From within the company network might be intentional or unintentional

Threats to Network Security

  • Insecure network Architectures
  • Broadcast Networks
  • Centralized Servers (Single point of failure)
  • Unused Services and Open Ports
  • Inattentive Administration
  • Inherently Insecure Services like inherent OS or application

Identify the Types of Viruses Part-1

Filed under: , by: Network World

Viruses are classified depending on how they infect the computer systems on a network and include the following types:

Boot Viruses
These viruses attack the boot record, the master boot record, the File Allocation Table (FAT), and the partition table of a computer hard drive, and are often delivered from an infected diskette accidentally placed in the disk drive when starting a computer.

Joshi and Michelangelo are examples of Boot sector viruses.

File Viruses (Trojan Horses)

These viruses attack program files (files with names ending in .exe, .com, .sys, .drv, .ovl, or .bin) by attaching themselves to an executable file. The virus waits in memory for the user to run another program and use the event as a trigger to infect and replicate.

Trojan horse programs are an example of file viruses. A trojan horse is a destructive program that can come concealed as part of software such as a game or a graphics application.

Trojan horses can contain worm and virus programs and are frequently used for embezzlement. These programs can be programmed to self destruct, leaving no evidence, aside from their damage.

Macro Viruses
These viruses attack programs that run macros. The most common of these are in Microsoft Word documents. A macro virus is a malicious macro that starts when a document or a template file in which it is embedded is opened by an application. The macro virus then copies itself onto other documents.

A well known example of macro virus is the Melissa macro virus. Some of the aliases and variants include Melissa, Melissa.a, and W97M/Melissa.a@mm

How to Avoid Getting a Computer Virus or Worm

Filed under: by: Network World

  • Beware of MS Outlook. This software has a horrible reputation for spreading virus through email. Take a look at web based email services like Gmail or Hotmail.
  • Install an anti-virus programs like AVG Free,AVAST,McAfee etc
  • Be sure to scan any email attachment that you receive.
  • Only download from trusted sites, you will regret downloading from the 1st shady website you may come across.
  • Consider switching to a different browser. IE is the most targeted web browser for virus'. Try Opera, Safari, or Firefox!

The Basics of Computer Network Security

Filed under: by: Network World

Author: Ribvar Shafeei

When you first think about computer network security you might picture two security guards watching your computer.

When you first think about computer network security you might picture two security guards watching your computer. Actually computer network security is the line of defense that stops intruders from accessing your computer or network. Detection provides information when somebody tries to access your systems, whether or not they were successful and understanding what they could have done. Information stored on your computers include banking details, credit card credentials and communication logs either chat or email. You can live with someone reading you personal conversations but not when they steal your bank or credit card information.

Intruders often use other computers as a way to launch attacks and disguise themselves as the intruded computer. Custom Malware is one of the biggest network security problems facing the internet. Targeted attacks, designed to be used against a single target, can avoid signature detection. Since the Malware is custom designed to avoid any known signatures and has never been widely released, a signature for it will not exist and no signature detection mechanism will find it, whether in anti-virus software, intrusion detection software, or any other form.

Malware can also be disguised from signature detection by using polymorphic tools that change the code constantly, creating a unique version with a unique signature each time the program is created. Polymorphic toolkits such as:ADMutate, PHATBOT, Jujuskins, TAPioN and CLET put this kind of functionality within the reach of the average skilled malware creator, if not the novice In another separate, but real-life example of stealthy malware, the Gozi trojan existed in the wild for over fifty days in the beginning of 2007, and it has been estimated that the first variant of it infected more than 5,000 hosts and stole account information for over 10,000 users. Gozi's primary function was to steal credentials being sent over SSL connections before they were encrypted and add them to a database server that would dispense them on demand in exchange for payment. Had the malware author made a better choice of the packing utility used, the trojan may have gone much longer before being detected.

Intruders are discovering new vulnerabilities or loop holes every day. Developers or computer vendors often provide patches that cover up previous loop holes. A "zero-day" attack is an attack that targets a vulnerability for which there is no solution easily available. Once the vendor releases a patch, the zero-day exposure has ended. A recent example of a critical zero-day vulnerability was the Windows Animated Cursor Remote Execution Vulnerability that was patched by MS07-01719 (Microsoft Security Bulletin 925902). This was considered a critical hole because it could allow remote code of the attackers' choosing to be executed. A security research company called Determina notified Microsoft of the problem on December 20, 2006. The vulnerability was publicly announced on March 28 2007. On April 2nd, Determina released a video demonstration of Metasploit using exploit code against Vista. Microsoft then released the patch on April 3, 2007 ending at least six days of zero-day exposure. Exploit code that targeted this vulnerability was active in the wild for at least several days, if not several weeks before the patch was released Even after a patch is released, many organizations take several days to get around to updating systems with the patch. Most of the time it is your job to download and install these patches. It is a good idea to check for updates at least once a day or use an enterprise tool to manage updates on your network.

How can an intruder infiltrate my system? Well intruders have numerous tools available that provide them access to your system. Tools such as:

• Paros Proxy
• Metasploit Framework
• Aircrack
• Sysinternals
• Scapy
• BackTrack
• P0f
• Google
• WebScarab
• WebInspect
• Core Impact
• IDA Pro
• Rainbow Crack

If your organization has an Internet connection or one or two disgruntled employees (and whose doesn't!), your computer systems will get attacked. From the five, ten, or even one hundred daily probes against your Internet infrastructure to the malicious insider slowly creeping through your most vital information assets, attackers are targeting your systems with increasing viciousness and stealth. You need to understand attackers' tactics and strategies in detail so you can find vulnerabilities and discovering intrusions.Equipping yourself with a comprehensive incident handling plan is vital in protecting your organization against attackers.

About Author

Ribvar Shafeei is a Principal Consultant for BSecure,offering network services and computer network security services in Syndey Australia. For more information visit http://www.bsecure.com.au

Article Source: http://www.1888articles.com

Remove Virus Heat

Filed under: by: Network World

Author: Brainbox

So you have Virus Heat on your system but alreaedy have anti-virus software. So how did you get infected in the first place? Learn how and what you need to do to remove it and protect yourself.

Virus Heat is known as rouge spyware software. Many people who have anti-virus software installed on their system wonder how it got through in the first place. The answer is simple. Anti-Virus software does not protect against spyware.

How do you know when you have Virus Heat?

This answer is simple. Virus Heat is the name of the spyware program that pops up right away when you boot up your computer. It looks like a legitament anti-virus program. This software runs a quick fake scan on start up and then tells you that you are infected with all kinds of things. Your home page is normally highjacked as well and you most likely have a ton of pop-ups as well. In addition most people have a security shield that is active in their system tray.

How do I remove Virus Heat from my computer?

There are many different ways to remove Virus Heat form your system. The more important thing to consider first is full protection. You got infected because you did not have proper protection. It amazes me how many people just want to remove a virus or spyware but not consider full protection. Your just going to get in the same book again and next time it might be something far worse then Virus Heat.

Something you can try to do to remove Virus heat is go into you control panel and simply remove this software. Often times this works. It does not always work but it’s quick to try. Another great way is to do a system restore. If you were infected with Virus Heat just a few days ago then chances are this will work. You will still need to install anti-spyware software for full protection.

I already had protection so why did I get infected and why won’t my software remove it?

This simple answer is not all anti-spyware software is the same. Only a few anti-spyware programs are actually good at removing Virus Heat once infected. Many do a very poor job at preventing spyware in the first place. Any program that is free will not do an adequate job at protecting your system. It seems I have to fight with people over this all the time but after being in the computer field for a dozen years and repairing thousands of computers that have this free software to protect them I know for a fact it just is not enough.

Most of the time people get infected with Virus heat from a fake video codec. They are asked to download and install some software to watch a video or listen to music and that is how they became infected.

About Author

For step by step instructions and multiple different ways to remove this spyware check out our Virus Heat site. As well if you need a pro to help you remove this threat then head over to Online Computer Repair.

Article Source: http://www.1888articles.com/author-brainbox-4969.html