hacker update rick shaw – president,corpnet security, inc. mick johannes – cto, corpnet...

8
Hacker Update Rick Shaw – President,CorpNet Security, Inc. Mick Johannes – CTO, CorpNet Security, Inc.

Upload: amice-potter

Post on 18-Dec-2015

217 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Hacker Update Rick Shaw – President,CorpNet Security, Inc. Mick Johannes – CTO, CorpNet Security, Inc

Hacker Update

Rick Shaw – President,CorpNet Security, Inc.Mick Johannes – CTO, CorpNet Security, Inc.

Page 2: Hacker Update Rick Shaw – President,CorpNet Security, Inc. Mick Johannes – CTO, CorpNet Security, Inc

Hacker Update - Topics

What are they after? Why should I be concerned? Where am I vulnerable? How will they do it? What can I do about it?

Page 3: Hacker Update Rick Shaw – President,CorpNet Security, Inc. Mick Johannes – CTO, CorpNet Security, Inc

Hacker Update – What are they after?

Malicious Mischief – Deface your site. Make your services/resources unavailable.

Information Vandalism – Intentional destruction of data/availability. May occur with/without reasons/provocation.

Information Espionage – Theft or destruction of information for profit. Maybe motivated/associated with competitive corporate environments.

Page 4: Hacker Update Rick Shaw – President,CorpNet Security, Inc. Mick Johannes – CTO, CorpNet Security, Inc

Why Should I Be Concerned?

The threat is real. Hackers/Crackers are well informed/equipped.

Maintain a competitive advantage.

Protect data/electronic corporate assets.

Protect customer data.

Protect reputation.

Page 5: Hacker Update Rick Shaw – President,CorpNet Security, Inc. Mick Johannes – CTO, CorpNet Security, Inc

Where am I vulnerable?

Email ServersWeb ServersFTP ServersBackdoor ModemsMis-configured hardware/operating systemsOut of box configured hardware/operating systemsSoftware/Firmware without current revisions/patchesLack of knowledge/understanding of security issues

by employees

Page 6: Hacker Update Rick Shaw – President,CorpNet Security, Inc. Mick Johannes – CTO, CorpNet Security, Inc

How will they do it?

Port ScanningPort Re-directionSpoofingDenial of Service AttacksOperating System VulnerabilitiesTrojan-Horse AttackPassword CrackingBack DoorsPacket Sniffing

Page 7: Hacker Update Rick Shaw – President,CorpNet Security, Inc. Mick Johannes – CTO, CorpNet Security, Inc

What can I do about it?

Close your ports! (Design before you deploy)Patch your software/firmware!Implement strong password controls!Strong/current enterprise anti-virus controls!Enable and review your logs!Implement intrusion detection solutions!Have policies and escalation procedures!Educate your users!!!

Page 8: Hacker Update Rick Shaw – President,CorpNet Security, Inc. Mick Johannes – CTO, CorpNet Security, Inc

Questions?