· SoftScan Solna Strandväg Solna Sweden The less you hear from us the better Shhh… The less you hear from us the better Shhh…
· Spam & virus trends - is the problem getting bigger? Thursday, 1st of June 2006 Presented by: Diego d’Ambra, SoftScan
· Agenda Is malware/spam an increasing problem? - Some facts - New types of attack How can we stay safe? - 10 suggestions
· Is the problem increasing? Facts: - trends -Virus 0,5 ~ 10 % -Spam 80 ~ 90 % - Sweden is not behind… - Once you’re bitten… -Spyware -Adware -Backdoor proxies -Password stealers/crackers -Downloaders -Spam tools -Defense blockers
· Is the problem increasing? New types of attack -Instant messenger services (IM) -Compromised websites (recipient notified though IM, or poisoned DNS) -Client / Server networks (Faster and intelligent spread) -Phishing (E-bay, Paypal, credit card, online banking systems) -Mobile phones (PDA)
· How can we stay safe? 10 suggestions 1) Know your anti-virus product – Cleanup – ”Panic-button” – Beta signatures 2) Security-sites/services – AVIEN, Bugtrack, ISC, Secunia – Check/report suspicious files Virustotal ( Jotti (
· How can we stay safe? 10 suggestions 3) Software updates (and ensure they are implemented) – Microsoft® SUS/WUSP – Routers / Gate servers 4) IDS – Listen for suspicious traffic TCP port 25, , 445 IRC traffic P2P applications 5) Filter outgoing traffic – Proxy service – Block unneeded ports
· How can we stay safe? 10 suggestions 6) Install an anti-spam system – Probably best to detect Phishing s 7) Security policy (and implement it) – , IM, P2P etc. 8) Install an easy to understand scanning solution – Own signatures – Check MIME type 9) Train users – They are your last defense 10) Check your systems (again and again)
· BREAK…
· SoftScan Solna Strandväg Solna Sweden The less you hear from us the better Shhh… The less you hear from us the better Shhh…
· Newest development - how to stay safe? Thursday, 1st of June 2006 Presented by: Diego d’Ambra, SoftScan
· SoftScan suggestions 5 things you should/must do! 1)Deny s with executable attachments [exe] -Binary check -detects every executable binary 2)Enable [Virus Probability Analyze] (VPA) -Recommended setting: 90 % -Use Paranoid IQS to receive notification 3)Valid addresses -SPF record 4)TLS 5)Filter SMTP traffic -Delete A records such as mail, smtp etc.
· SoftScan suggestions 5 things you should not do! 1)Create MX records, not pointing at SoftScan 2)Allow MX record changes without your agreement/knowledge 3)Remove locally installed anti-virus -Clients / servers -(Except perimeter scanning services) 4)RBL lookup 5)Graylisting / tarpitting
· SoftScan suggestions 5 suggestions regarding the SoftScan system! 1)LDAP -MS AD / Lotus Domino integrated -SSL encrypted connection to SoftScan 2)TLS certificate check -Protects against man-in-the-middle-attacks 3)SMTP rules -Your s, your choice… 4)Report spam 5)Black’n’white -When SoftScan is wrong…
· New features… Archive your s - Optional service that allows you to save a copy of sent/received s POP3 proxy - Private accounts Per user quarantine zone - Less work for the administrator(s) Compliance - Rules and regulations requires companies to meet standards