Cisco Learning Network Store Promotions Page
Showing posts with label Viruses. Show all posts
Showing posts with label Viruses. Show all posts

7.12.2015

Microsoft's 'feeble' enterprise security and virus protection is the worst

 
Tests carried out by independent security labs AV-Test show that Microsoft is at the bottom of the league when it comes to enterprise security and virus protection. The tests pitted 11 security solutions against each other, and Microsoft's Endpoint Protection 2012 from the Microsoft Management Suite System Center 2012 was found to offer the weakest protection.
 
In both enterprise network security tests and virus detection tests, Microsoft trailed behind the competition in eleventh place. What's particularly concerning is that as the tool tested is bundled software, it's likely that it is precisely what many businesses are relying on for protection.
 
The efficacy of Microsoft's security software for home users has long been questioned, but security is of even greater concern to business and enterprise customers. The antivirus tests carried out by AV-Test showed that Endpoint Protection picked up just 73 percent of infections, compared to between 95 and 100 percent for the ten opponents. It is ultimately labelled as being "much too feeble in the detection of malware". Products from Bitdefender, F-Secure, Trend Micro, Kaspersky Labs, and Symantec all received flawless scores.
 
 
AV-Test's focus on enterprise security throws up Windows 7, which is still very widely used -- over 60 percent of businesses use the operating system. The labs report that just 22 percent of businesses have upgraded to Windows 8.1, and 18 percent are still on Windows XP. But whatever version of Windows is in use, the tests make it clear that switching to an alternative to Microsoft is a very good idea when it comes to security. As the AV-Test puts it:
An economical option for protecting a corporate network is the use of the endpoint module, bundled in the Microsoft Management Suite System Center 2012. The test revealed, however, that this is not to be recommended. The solution was awarded 0 points by the testers in terms of its protection function, and it achieved only 11 out of 18 possible points.
 
The report says that there is now an excellent range of affordable security suites to choose from -- hit the site to check out the results in full.
 
Photo credit: ronfromyork / Shutterstock
 
~ Mark Wilson

5.28.2015

Antivirus products for Linux compared

 
Though Linux is often seen as being immune to malware it's still important to have protection, partly because Linux malware does exist, even if it’s rare, and partly to prevent the passing on of viruses to more vulnerable operating systems like Windows and Android.
 
Independent testing organization AV-Comparatives has been looking at the leading Linux anti-malware offerings to gauge their ease of installation, features and more.
 
Linux has only around a 1.5 percent share of the desktop market so there are relatively few antivirus programs aimed at home users. Also Linux software is usually installed via community-maintained repositories that make it harder to distribute malware.
 
The report doesn't rank the tested programs but does deliver an individual verdict on each. Singled out for praise are BitDefender Antivirus Scanner for Unices, which offers an easy to use graphical interface and good help facilities, ESET has a clear status display and good malware alerts, and eScan too is praised for ease of use though it provides only on-demand scanning and not real-time protection.
 
Kaspersky too is easy to manage and configure as is McAfee, both of which use a web console approach as does TrendMicro's Server Protect for Linux.
 
Others including Comodo Antivirus for Linux, and Dr. Web Anti-virus for Linux come in for criticism for needing use of the terminal for configuration, making them unsuitable for Linux novices. AVG Free Edition for Linux is criticized for being unable to run real-time protection without making the system inoperative.
 
As well as installing antivirus software, AV-Comparatives recommends that Linux users implement some basic security procedures including keeping installed software up to date, only installing from trusted sources, disabling services you don’t use and not logging in as root.
 
The full report with verdicts on all 18 programs tested is available to download from the AV-Comparatives site.
 
Image Credit: maimu / Shutterstock
 
~ Ian Barker

7.01.2014

Latest ransomware, Cryptolocker, hits systems and pocketbooks hard

Cryptolocker, a ransomware Trojan virus, encrypts a victim's files and then demands payment for the key, and is indicative of the lengths nefarious types will go to for a few dollars of ill-gotten gains. 

Ransomware is on the rise and thanks to more than a few nefarious types and their victims, is proving to be an all too common way for electronic extortion to move into an enterprise. In many cases, it proves to be cheaper to pay for the privilege to unlock your data than it would be to remediate the impacted system, which only makes matters worse.
 
 
Take for example Cryptolocker, a ransomware Trojan that encrypts files and can spread in many ways, including in phishing emails that contain malicious attachments or links, or via drive-by download sites. Often, Cryptolocker arrives as a file with a double extension, such as *.pdf.exe and can be hard to recognize, simply because Windows hides file extensions by default - that file may look like a PDF file rather than an executable.
 
Double clicking on the Cryptolocker infected file launches an executable, which infects computers just like any other malware by placing its files in Windows directories and creating registry entries that allow it to restart after a reboot. Cryptolocker also attempts to contact its command and control (C&C) server using a random domain name generation algorithm to try and find a current C&C server. Some sample Crytpolocker domains might look like this:
 
jkamevbxhupg.co.uk
 
uvpevldfpfhoipn.info
 
Once Cryptolocker contacts its C&C, it generates a public/private cryptographic key for the specific computer, using very strong and standard RSA and AES 2048-bit encryption. The private key is only stored on the attacker's C&C servers, but the public key is saved in a registry entry on the computer. Cryptolocker then uses that key pair to encrypt many different types of files on the computer, including 
 
*.odt, *.ods, *.odp, *.odm, *.odc, *.odb, *.doc, *.docx, *.docm, *.wps, *.xls, *.xlsx, *.xlsm, *.xlsb, *.xlk, *.ppt, *.pptx, *.pptm, *.mdb, *.accdb, *.pst, *.dwg, *.dxf, *.dxg, *.wpd, *.rtf, *.wb2, *.mdf, *.dbf, *.psd, *.pdd, *.pdf, *.eps, *.ai, *.indd, *.cdr, *.jpg, *.jpe, *.jpg, *.dng, *.3fr, *.arw, *.srf, *.sr2, *.bay, *.crw, *.cr2, *.dcr, *.kdc, *.erf, *.mef, *.mrw, *.nef, *.nrw, *.orf, *.raf, *.raw, *.rwl, *.rw2, *.r3d, *.ptx, *.pef, *.srw, *.x3f, *.der, *.cer, *.crt, *.pem, *.pfx, *.p12, *.p7b, *.p7c.
 
After the encryption process completes, Cryptolocker displays screen with a warning that requires a payment of either $300 or £200 within 72 hours to regain access to the files.

What should I do if I get infected?

If you are infected with Cryptolocker, the first thing you should do is disconnect the infected PC from the internet. If Cryptolocker can't access its C&C, it can't encrypt files. Disconnecting the machine may prevent further files from being encrypted.
 
There are many tools that will totally clean a Cryptolocker infection, but most victims are more concerned with recovering encrypted files. Unfortunately, you will not be able to crack Cryptolocker's encryption. It uses a very strong and reliable public/private key implementation that is similar to what commercial encryption products use. It would take decades to centuries to crack today.
 
If Cryptolocker encrypts some of your files, you should check if you have a backup, which would be the best chance for recovering the lost data. Adding insult to injury is that there are reports claiming Cryptolocker's decryption does work, and paying the ransom may only result in the loss of your money.

How can I avoid Cryptolocker?

Most commercial antivirus (AV) products can detect many variants of Cryptolocker, which means protection starts with using both host-based and network-based AV products that are kept up to date. However, Cryptolocker's authors are very aggressive at re-packing their malware to make the same executable file look different on a binary level, which helps it evade some AV solutions. In short, though AV helps, some variants may get past some AV solutions. Other defenses are becoming a must as well, such as reputation based defense systems that keep track millions of malicious URLS and web sites. That means access to sites that distribute or support malware can be blocked, effectively preventing infected hosts from reaching C&C servers. 
 
Awareness proves to be one of the best defenses, Cryptolocker typically spreads via some obvious phishing emails. The emails may pretend to be FedEx or UPS related messages, which contain zip files that hide a double-extension executable. Training users to recognize some of the common phishing and malware signs, such as unsolicited emails from shipping providers, double-extension files, links that point to the wrong sites, and so on should prove to be an effective first line of defense. 
 
~ Frank Ohlhorst

8.09.2013

Linux gets hit by a trojan -- it's time to sudo apt-get scared!

When evangelists pontificate the benefits of Linux, the topic of security always comes up. A big selling point of Linux-based operating systems are that they are generally immune to viruses, trojans and malware. However, this is a falsehood -- no OS is 100 percent safe when it comes to these things. According to security company RSA, a team of Russian cyber-criminals have developed a trojan, named "Hand of Thief", which targets Linux.
 
The security company explains that the trojan is "designed to steal information from machines running the Linux OS. This malware is currently offered for sale in closed cybercrime communities for $2,000 USD (€1,500 EUR) with free updates. The current functionality includes form grabbers and backdoor capabilities, however, it's expected that the Trojan will have a new suite of web injections and graduate to become full-blown banking malware in the very near future. At that point, the price is expected to rise to $3,000 USD (€2,250 EUR), plus a hefty $550 per major version release".
 
This seems excessively expensive given Linux's very small footprint with home users. However, it does seem to work against some popular distributions. "The Trojan's developer claims it has been tested on 15 different Linux desktop distributions, including Ubuntu, Fedora and Debian. As for desktop environments, the malware supports eight different environments, including Gnome and KDE", says RSA.
 
According to RSA, the trojan has the following functionality:
  • Form grabber for both HTTP and HTTPS sessions (Firefox, Google Chrome, Chromium, Aurora and Ice Weasel)
  • Block list preventing access to specified hosts
  • Backdoor, backconnect and SOCKS5 proxy
  • Anti-research tool box, which includes anti-VM, anti-sandbox and anti-debugger
While this trojan does seem nasty and scary, it is unlikely to spread easily given Linux users' propensity towards common-sense about installing software. If a user sticks to only installing software from trusted repositories, they should continue to be safe and secure.
 
Linux users, does this new trojan have you worried? Will you be rushing to install Windows? Tell me in the comments.
 
~ Brian Fagioli

4.08.2012

Three-quarters of Mac owners don't use anti-malware software

Early results from our "do you have anti-malware installed on your primary computer" polls are in, and there's some change from the ones conducted last May. More respondents on Mac and Windows use security software, but the split remains polarized: 75 percent of Mac users don't, while 90 percent of their Windows counterparts do. Welcome to the wonderful world of Apple denial. There are no pesticides to save this crop.

Responses are unusually low to both polls. I should know better asking anything over the Easter holiday weekend and start of Passover. I'm re-embedding the polls, hoping to jack up the numbers -- 315 for Mac and 358 for Windows, as I write. But the polarized results are consistent enough with the previous polls, when 86 percent of Windows PC users answered yes and 81 percent of Mac owners no. The difference between the polls is within reasonable margin of error, particularly considering respondents aren't qualified. Responses also could represent increased anti-malware usage in both camps.

I asked the poll following reports that the Flashback Trojan infects more than 600,000 Macs, binding them together as a botnet. Flashback first popped up last summer, so this isn't something new -- just the success as new variants appeared, Apple released updates (often too slowly) and Mac users failed to apply them.

Readers Respond


BetaNews reader Joel Medina uses OS X and Windows, and on the latter runs Microsoft Security Essentials. "But on my mac I rarely install an AV program -- not because I think I'm immune but because it's just so rare that Macs get them because the focus for years for hackers was to attack Windows. But now that Macs are starting to get into mainstream usage I'm considering an antivirus program for my Macs."

Andrew Johnson comments earlier today:
Getting nasties such as Mac Defender or System Tool 2012 or whatever on your computer has always been more about the user's browsing habits than about any supposed flaws, or lack thereof, in the browser and/or operating system. This is not to say that those flaws do not exist, but they would be harder to exploit if most users knew what and how to avoid infection.
Mac has had a pretty good track record up until recently, but I have always said, Apple versus Microsoft is an irritating debate, because it's all code, and if you can write code for it, you can write malicious code. I'm not using the "security through obscurity" argument here, I'm just saying it was always just a matter of time.
On a side note, I find it sad how many people think that their smartphones are unassailable fortresses even though the number of infected mobile devices is on the rise.
The real question to ask: Do you need antivirus software at all? Reader capncoad has an answer for that: "Anti-malware apps are simply a moron detector with no real security. Every time it dings and tell you that it blocked a virus, it's really saying 'moron'...If someone created an antivirus app that caused your PC to shock you every time you downloaded a 200kb executable thinking it was a free song then I think we'd be on to something".

That's the point isn't it? Behavior. Windows 7 and OS X 10.7 are pretty hardened. Often malware infections are about stupid online behavior. "How stupid can people be", maddy143ded writes. "Why download stuff from websites that promise you a song and instead give you a small executable?"

Do I Feel Lucky?

There are lots of reasons, like social media. Your friend whom you trust recommends a link and you click. Or you trust Google and search for band X, only to find SEO poisoning in place. Or you trust Apple marketing statements like "Mac OS X doesn't get PC viruses", creating a false sense of security. Or you're browsing from home, you feel safe and project that feeling to web browsing. Trust is the constant.

Last year I kicked Apple in the groin for making security claims like this: "Mac OS X doesn't get PC viruses", which fosters a false sense of security. Oftentimes, as Flashback and countless Windows malware show, successful attacks are more about social engineering than lax operating system security. Human behavior matters as much, sometimes more. Criminals can break in no matter how good the locks if people open the door for them.

But do they need to install a separate security system (e.g. anti-malware)? I would feel pretty safe using Windows 8 and OS X Snow Leopard without anti-malware software. But then, again, I'm cautious of what I click.

After making Snow Leopard seem like the toughest thing next to the Terminator, the updated OS X security page concedes and recommends:
The Mac is designed with built-in technologies that provide protection against malicious software and security threats right out of the box. However, since no system can be 100 percent immune from every threat, here are some other ways to help keep your information as safe as possible:
  • Download files only from known and trusted websites.
  • Use FileVault 2 to encrypt everything on your Mac.
  • Control access to your Mac by locking your screen after a period of inactivity.
  • Securely delete outdated sensitive files with the Secure Empty Trash command.
As Clint Eastwood playing Dirty Harry said, "You've got to ask yourself one question: Do I feel lucky? Well, do ya, punk?"

~ Joe Wilcox