Showing posts with label Internet Security. Show all posts
Showing posts with label Internet Security. Show all posts

Thursday, June 19, 2008

Review on Internet Security: More than 1 million computer viruses in circulation now (April 11,2008)

Recently, there were more than 1 million malware including computer viruses, worms and Trojans circulating in the internet from the Symantec bi-annual Internet Security Threat Report. These might be resulted from a huge numbers of new malicious codes being created by the cyber crime groups.

One of the reasons is criminals increasingly using Trojans as their main tool to gain access to other computer and use that route to download and install a variety of other malicious programs. Besides, some malicious installations happen when websites are visited or programs, such as online games are started up. There is also a growth in professional digital criminal underground, these experts are expected to be paid to steal information and aiming for new victims.

Besides, most of the malicious codes are targeted on Microsoft Window's based PC. These malware will utilize popular communication tools to spread worms by sending through email and instant messages, Trojan horses dropped from websites and virus-infected files downloaded from p2p connections. Malware will also seek for vulnerable systems, making their entry quiet and easy. In fact, there are 90% of people using Microsoft Window's platform, so it is very risky if we let our Window's systems vulnerable to attack without any proper safeguards.

Please refer to the source of the issue here. <click here>

How Safe Is Your Data?

Generally, there are three situations that expose us to the risk of data loss or data stolen:

1. Malicious attack from internet
Nontechnical attack is when perpetrator uses deception or persuasion to trick users into revealing their personal information or conducting actions that compromise the security of their network. Technical attack is conducted using software and systems knowledge or expertise, such as spyware, malware, viruses, worms, and Trojan horse.


2. Stolen hardware
Data stored on laptops, external hard disks, CDs, and other portable storage devices are loss and exposed to potential abuse when the hardware are stolen.




3. Faulty hardware
Without proper backup systems, any data stored in the computer will be loss permanently if the hard disk becomes faulty and unrecoverable.



Now, let’s have a quick view of a few cases where the users’ data were stolen.
· April 2007, University of California, San Francisco (due to hacker)
The University’s server which contained confidential information such as names, social security numbers and bank account details of 46,000 students, faculty and staff was hacked into.
· April 2007, Georgia (due to stolen hardware)
A company lost a CD consisting 2.9 million Georgia residents’ names, social security numbers, addresses and members identification for recipients of Medicaid and other medical programme which belonged to Georgia Department of Community Health.
· 2006, Own experiences (due to key logger)
My brother’s MSN and his online games’ accounts were hacked. This unknown person was using his MSN chat room, messing around with his games’ characters and spamming mails using his hotmail account.

In conclusion, as an internet user, we must be very careful in handling our data. Hence, proper anti-virus, anti-spyware and strong firewall programs are necessary. Frequent data backup and data encryption are also very important.

Safeguard of personal and financial data

We can protect our personal and financial document against potential fraud by eliminate our own paper trail. A shredder can work for a few sheets paper at a time. We can also contact a commercial shredder to do it if we have a large quantity of sheets. Likewise, we can also review the monthly statements which can alert us to possible fraudulent charges. We may also find legitimate charges for services which are redundant or unnecessary. We must always guard our social security number by make sure that anyone asking for our social security number is really needs it and do not print the social security number on checks or high visible places.
Besides that, we should choose the PIN number wisely.
A combination of uppercase and lowercase letters and numbers will be more secure. While using the Internet, we must be cautious from become a victim of a phishing scam. So we should verify any request for personal information before you give out any sensitive data. Anti-virus software, firewall and anti-spyware software must be installed in our computer and always keep them up to date. These can protect us against viruses and Trojan horses that may steal or modify the data on your own computer.

Phishing

Phishing is a scam in which the attacker sends an email purporting to be from a valid financial or E-Commerce provider. The email often uses fear tactics in an effort to trap the victim into visiting a fraudulent website. The particular website looks like the valid E-Commerce or banking site. The victim is instructed to login to their account and enter sensitive financial information such as usernames, passwords, account IDs, ATM PINs or credit card details. Subsequently, this information will be sent to the attacker who then uses it to engage in credit card and bank fraud.

However, it is easy to prevent a phishing scam. For example, do not open the link and key in your personal information when you received an email from a bank that you have never opened an account. Besides, a phishing scam always has a lot of words misspelled because sometimes the scammers operate a phishing with a second language and poor grammar. So you can realize it is a phishing if you look at the message carefully. Another way to prevent is examine the link provide to see whether does it really go where it appears to go. For instance, the scammer will tell you that you can access to the government’s top secret database at www.topsecretxxx.gov but if you click the link you will find that you have been entered to another web site.