2016 system security updatefiles.meetup.com/19560011/2016-11-10-security...2016/11/10  · 2016...

24
2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins South Sound IT Olympia, WA 866.827.9889

Upload: others

Post on 10-Sep-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

2016 System Security Update

Surviving and Staying safe in a connected world.

Jim Hutchins South Sound IT Olympia, WA 866.827.9889

Page 2: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Today Current Threats Prevention Mitigation Recovery

Page 3: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Current Threats Ransomware Malware Ransomware Phishing Ransomware DDOS/Intrusion Ransomware

Page 4: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Malware Spotify Free – caused the default browser

to open malware/virus sites HummingBad Android-infecting Malware OSX/Keydnap malware – keylogger Linux/IRCTelnet Internet of Things (IoT) New ATM malware family – Ripper AtomBombing: Brand New Code Injection

for Windows

Page 5: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Malware in the Cloud 2-year old ransomware strain - Virlock Started spreading itself via cloud storage

and collaboration applications “Virlock has effectively weaponized every

data file it encrypts” There are “Cloud Anti-Virus” solutions Represents unmanaged risk

Page 6: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Phishing Targeting individuals Mining social media for information Customized email – with a malicious link Link takes them to a compromised site That site downloads the payload The payload executes in the background

Page 7: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

DDOS Attack DynDNS, aka Dyn.com, attacked by a very

aggressive DDoS attack – October 2016 Paypal, Netflix, Wordcamp, Github, Twitter,

Esty, Soundcloud, Spotify, Amazon, Heroku, Shopify, PagerDuty, ZenDesk, Braintree, Fastly, Cloudflare

IoT devices infected with a botnet (cameras) 500,000 devices were infected and only 10% of

them were used in the attack.

Page 8: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Ransomware Polymorphic - on the fly mutation New (hacker) tools are readily available Rootkits are “everyday person” accessible Device specific versions Billion dollar industry

Page 9: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

December 2015 17% of all observed malware dropped by exploit kits was Ransomware

May 2016 61% of all observed malware dropped by exploit Kits was Ransomware

259% increase in 5 months

Page 10: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins
Page 11: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins
Page 12: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Prevention Common sense Policy & Procedure Anti-virus Anti-exploit Segmented networking Management awareness and buy-in There is no 100%

Page 13: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Malware AV & AE

Malwarebytes ESET

Mobile Prey – lost/stolen 360 Mobile Security Bitdefender/ESET

Page 14: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Phishing

Page 15: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Minimizing impacts DDOS - secondary DNS provider Phishing – Filters/Pre-education Remote Access/Trojans – Outbound

detection/filtering Ransomware/Malware – Backups

Page 16: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

DDNS attacks OpenDNS has DNS server addresses:

208.67.222.222 208.67.220.220

Secondary DNS provider Ingress/Egress Filltering Lock out unexpected transactions

Page 17: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Private VPNs

Page 18: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

TOR: The Onion Routing program

Page 19: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Recovery Phishing - Systems, Training, Policy Ransomware/Malware - Restore data

Page 20: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Phishing Update/improve Email and Firewall filters

and rules Establish/Improve/Expand Phishing

training for users Establish and enforce more rigorous

policies & procedures

Page 21: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Ransomware Wipe & Restore from backup Just save critical files

Wipe & Restore from backup Clean the system with purchased

software Wipe & Restore from backup

Pay someone else to clean it up

Wipe & Restore from backup!!

Page 22: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Backups

Page 23: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

New USB connector – Type C

Page 24: 2016 System Security Updatefiles.meetup.com/19560011/2016-11-10-Security...2016/11/10  · 2016 System Security Update Surviving and Staying safe in a connected world. Jim Hutchins

Ransomware