Next time you get infected, take a few minutes and learn from the experience.
You get infected and luckily your antivirus detects it and tells you as much in a nifty little pop up window. (In a majority of cases, that’s about the only way you’ll know you got infected or came in contact with malware.) What do you do? Do you thank your antivirus software and carry on? Do you wonder whether it caught everything? Or if it will come back? Do you get curious about how or why? Do you care?
I’ll answer the last question. You better. Your computer holds keys to your financial data, whether you’ve ever logged on to an online banking or financial site from it. It contains information about you that can be used fraudulently and to gain more information about you. It can also reveal information about your friends, family and co-workers, thanks to the boom in social networking. Carelessness puts not only you, but everyone you interact with online at risk.
If your computer gets 0wned (fully controlled by an attacker) the attacker has more control over your computer than you do, because they know how to use it in ways you likely haven’t imagined. For example, at work, you might not have access to personally identifiable information (PII), but your actions can lead to a compromised host and an internal launching point for deeper attacks that will. The PII could be ex-filtrated without ever coming in contact with your computer. Scary, eh? Potentially very damaging to all involved too.
What can you do? Endpoint security software (firewalls, antivirus and IPS) can do a moderately effective job of protecting your host. In most cases, the fault of an infection isn’t that the security vendors “missed” it. They catch a lot and work hard at getting better and stopping more. Harder than you do I bet. Eh? Computers have software and hardware that can help detect and prevent malicious attacks. What do you use?
From the keyboard to the chair is your responsibility. Be responsible! Educate yourself. Learn to defend yourself and identify attacks on you. As long as you aren’t willing to put in some effort to learn about how you can be attacked, how you can identify those attacks, and how you can avoid them in the future, you are the biggest unpatchable vulnerability affecting your computer.
If you still don’t care, then thanks for stopping by and may your fortunes be secure. If you do care, then lets talk a little about attacks and defenses.
You’ve likely heard about phishing emails and spam containing malicious attachments or links. Some of these are very sophisticated and seem very trustworthy. Trust nothing when computing. Any email, attachment, or link you encounter via email or social networking should be considered untrustworthy until you’ve ascertained the source is valid and the source intended the information for you. Think about whether the person who posted that link on your Facebook profile is the type who would have validated the information. If there is even the slightest doubt about whether it’s secure, consider it insecure until you have verbally spoken with the sender and taken measures to identify if the link or file is malicious. (Virustotal allows you to submit potentially malicious files for scanning by more than 35 a/v vendors and gives you a good idea if the file is good or bad. They also have a URL scanner if you’re unsure about a link. Neither of these are 100% assurances however, so you start to see how this is about reducing risk, not eliminating it.)
Sometimes even the wisest are fooled if the scam is good enough or they are caught with their guard down. And sometimes the completely innocent are victimized. Drive by downloads take advantage of browsing-related vulnerabilities to exploit a computer without the user doing anything other than browsing to the wrong site at the wrong time. Malvertisements use social engineering to entice users to run a program, such as the Fake A/V attacks. And those of us who like Macs need to get over the false notion that Mac OS X is more secure. It’s binary code written by humans and potentially vulnerable to being exploited by humans. Mac’s are gaining popularity and with that will come attention and attacks.
A familiarity with what your programs are supposed to look like can help you identify anomalous behavior. Know what your antivirus alerts look like so when you see a fake one it’s obvious you’re being attacked. Patching is another solid defense. At the bare minimum always patch operating systems, browsers, and the Adobe products Flash, Shockwave, Reader and Acrobat as soon as patches become available…on all platforms.
I highly recommend Secunia PSI for Windows users. It’s free for home use and will monitor your computer for updates specific to your hardware and the software installed. It provides assistance with remediation as well, providing links to patches or details on how to close the gaps.
I bet you’d be hard pressed to find anyone who has used the Internet for more than a year who hasn’t run into something malicious, whether they are aware of it or not. People cling to guns for self-defense from an enemy they’ll likely never encounter. Yet they’ll pay no attention to a virus detection or the fact that their computer “might” be infected. I realize education and awareness aren’t as exciting as guns, but they’ll protect you from a whole lot more than a gun probably ever will.