Friday, July 17, 2009

Understanding Patches

Cyber Security Tip ST04-006

When vendors become aware of vulnerabilities in their products, they often
issue patches to fix the problem. Make sure to apply relevant patches to
your computer as soon as possible so that your system is protected.

What are patches?

Similar to the way fabric patches are used to repair holes in clothing,
software patches repair holes in software programs. Patches are updates that
fix a particular problem or vulnerability within a program. Sometimes,
instead of just releasing a patch, vendors will release an upgraded version
of their software, although they may refer to the upgrade as a patch.

How do you find out what patches you need to install?

When patches are available, vendors usually put them on their websites for
users to download. It is important to install a patch as soon as possible to
protect your computer from attackers who would take advantage of the
vulnerability. Attackers may target vulnerabilities for months or even years
after patches are available. Some software will automatically check for
updates, and many vendors offer users the option to receive automatic
notification of updates through a mailing list. If these automatic options
are available, we recommend that you take advantage of them. If they are not
available, check your vendors' websites periodically for updates.

Make sure that you only download software or patches from websites that you
trust. Do not trust a link in an email message—attackers have used email
messages to direct users to malicious websites where users install viruses
disguised as patches. Also, beware of email messages that claim that they
have attached the patch to the message—these attachments are often viruses
(see Using Caution with Email Attachments for more information).
______________________________
___________________________________

Both the National Cyber Security Alliance and US-CERT have identified this
topic as one of the top tips for home users.
_________________________________________________________________

Author: Mindi McDowell
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Note: This tip was previously published and is being re-distributed
to increase awareness.

Originally Published at: http//www.us-cert.gov/cas/tips/ST04-006.html

Wednesday, July 1, 2009

Understanding Anti-Virus Software

Cyber Security Tip ST04-005


Anti-virus software can identify and block many viruses before they can
infect your computer. Once you install anti-virus software, it is important
to keep it up to date.

What does anti-virus software do?

Although details may vary between packages, anti-virus software scans files
or your computer's memory for certain patterns that may indicate an
infection. The patterns it looks for are based on the signatures, or
definitions, of known viruses. Virus authors are continually releasing new
and updated viruses, so it is important that you have the latest definitions
installed on your computer.

Once you have installed an anti-virus package, you should scan your entire
computer periodically.
* Automatic scans - Depending what software you choose, you may be able to
configure it to automatically scan specific files or directories and
prompt you at set intervals to perform complete scans.
* Manual scans - It is also a good idea to manually scan files you receive
from an outside source before opening them. This includes

* saving and scanning email attachments or web downloads rather than
selecting the option to open them directly from the source
* scanning media, including CDs and DVDs, for viruses before opening any
of the files

What happens if the software finds a virus?

Each package has its own method of response when it locates a virus, and the
response may differ according to whether the software locates the virus
during an automatic or a manual scan. Sometimes the software will produce a
dialog box alerting you that it has found a virus and asking whether you
want it to "clean" the file (to remove the virus). In other cases, the
software may attempt to remove the virus without asking you first. When you
select an anti-virus package, familiarize yourself with its features so you
know what to expect.

Which software should you use?

There are many vendors who produce anti-virus software, and deciding which
one to choose can be confusing. All anti-virus software performs the same
function, so your decision may be driven by recommendations, particular
features, availability, or price.

Installing any anti-virus software, regardless of which package you choose,
increases your level of protection. Be careful, though, of email messages
claiming to include anti-virus software. These messages, supposedly from
your ISP's technical support department, contain an attachment that claims
to be anti-virus software. However, the attachment itself is in fact a
virus, so you could become infected by opening it (see Using Caution with
Email Attachments
for more information).

How do you get the current virus information?

This process may differ depending what product you choose, so find out what
your anti-virus software requires. Many anti-virus packages include an
option to automatically receive updated virus definitions. Because new
information is added frequently, it is a good idea to take advantage of this
option. Resist believing email chain letters that claim that a well-known
anti-virus vendor has recently detected the "worst virus in history" that
will destroy your computer's hard drive. These emails are usually hoaxes
(see Identifying Hoaxes and Urban Legends for more information). You can
confirm virus information through your anti-virus vendor or through
resources offered by other anti-virus vendors.

While installing anti-virus software is one of the easiest and most
effective ways to protect your computer, it has its limitations. Because it
relies on signatures, anti-virus software can only detect viruses that have
signatures installed on your computer, so it is important to keep these
signatures up to date. You will still be susceptible to viruses that
circulate before the anti-virus vendors add their signatures, so continue to
take other safety precautions as well.
______________________________
___________________________________

Both the National Cyber Security Alliance and US-CERT have identified this
topic as one of the top tips for home users.
_________________________________________________________________

Authors: Mindi McDowell, Allen Householder
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Note: This tip was previously published and is being re-distributed to
increase awareness.

Terms of use

http//www.us-cert.gov/legal.html

This document can also be found at

http//www.us-cert.gov/cas/tips/ST04-005.html

Friday, June 26, 2009

Spam, Phishing, and Malicious Code Related to Recent Celebrity Deaths

US-CERT is aware of public reports of an increased number of spam
campaigns, phishing attacks, and malicious code targeting the recent
deaths of Michael Jackson and Farrah Fawcett. These email messages may
attempt to gain user information through phishing attacks or by
recording email addresses if the user replies to the message.
Additionally, email messages may contain malicious code or may contain
a link to a seemingly legitimate website containing malicious code.

US-CERT would like to remind users to remain cautious when receiving
unsolicited email. Users are encouraged to take the following measures
to protect themselves from these types of attacks:
* Do not follow unsolicited web links received in email messages.
* Install and maintain up-to-date antivirus software.
* Refer to the Recognizing and Avoiding Email Scams (pdf) document
for more information on avoiding email scams.
* Refer to the Avoiding Social Engineering and Phishing Attacks
document for more information on social engineering attacks.

Relevant URLs:

http://www.us-cert.gov/cas/tips/ST04-014.html

http://www.us-cert.gov/reading_room/emailscams_0905.pdf

Originally posted at:

http://www.us-cert.gov/current/index.html#spam_campaigns_based_on_recent

Wednesday, June 24, 2009

Sharing data on health with patients: An IT policy question

I saw this article about IT policy in the health service delivery. Considering that we are in a health science center, maybe we ought to be aware of some trends in other countries.

Original article follows:
================
A new push for health data rights
by Dana Blankenhorn

A coalition of health IT reformers today offers a Bill of Heath Data Rights aimed at moving the heart of the health IT debate away from doctors and insurance companies, toward patients.

This is the brainchild of former Google Health executive Adam Bosworth and Patientslikeme co-founder James Heywood. My copy was forwarded by David Kibbe.

The actual proposal is postcard simple:

In an era when technology is allowing personal health information to be more easily stored, updated, accessed and exchanged, the following rights should be self-evident and inalienable. All people:

  • Have the right to their own health data.
  • Have the right to know the source of each health data element.
  • Have the right to take possession of a complete copy of their individual health data, without delay, at minimal or no cost. If records exist in computable form, they must be made available in that form, without delay, at minimal or no cost.
  • Have the right to share their health data with others as they see fit.

These principles express basic human rights as well as essential elements of health care that is participatory, appropriate and in the interests of each patient. No law or policy should abridge these rights.

The expected reaction from the industry is “yeah, but.” Yeah, but it’s not that simple. Yeah, but most people don’t care. Yeah, but how do you express that in software.

The hope is that the principles behind HIPAA can be maintained while the costs of HIPAA, and the use of it as a smokescreen for luddism by the health IT industry, can be foregone.

That’s a big hope for such a short document.

I’m afraid that if this became part of some law passed by Congress it certainly would become a new HIPAA law. But if NCHIT David Blumenthal can convince the President to make this part of an executive order, something that exists in spirit and is defined on-the-fly, it might be worthwhile.

Originally posted on: http://healthcare.zdnet.com/?p=2373&tag=nl.e019

Friday, June 5, 2009

Good Security Habits

Cyber Security Tip ST04-003

There are some simple habits you can adopt that, if performed consistently,
may dramatically reduce the chances that the information on your computer
will be lost or corrupted.

How can you minimize the access other people have to your information?

You may be able to easily identify people who could, legitimately or not,
gain physical access to your computer—family members, roommates, co-workers,
members of a cleaning crew, and maybe others. Identifying the people who
could gain remote access to your computer becomes much more difficult. As
long as you have a computer and connect it to a network, you are vulnerable
to someone or something else accessing or corrupting your information;
however, you can develop habits that make it more difficult.
* Lock your computer when you are away from it. Even if you only step away
from your computer for a few minutes, it's enough time for someone else
to destroy or corrupt your information. Locking your computer prevents
another person from being able to simply sit down at your computer and
access all of your information.
* Disconnect your computer from the Internet when you aren't using it. The
development of technologies such as DSL and cable modems have made it
possible for users to be online all the time, but this convenience comes
with risks. The likelihood that attackers or viruses scanning the
network for available computers will target your computer becomes much
higher if your computer is always connected. Depending on what method
you use to connect to the Internet, disconnecting may mean disabling a
wireless connection, turning off your computer or modem, or
disconnecting cables. When you are connected, make sure that you have a
firewall enabled (see Understanding Firewalls for more information).
* Evaluate your security settings. Most software, including browsers and
email programs, offers a variety of features that you can tailor to meet
your needs and requirements. Enabling certain features to increase
convenience or functionality may leave you more vulnerable to being
attacked. It is important to examine the settings, particularly the
security settings, and select options that meet your needs without
putting you at increased risk. If you install a patch or a new version
of the software, or if you hear of something that might affect your
settings, reevaluate your settings to make sure they are still
appropriate (see Understanding Patches, Safeguarding Your Data, and
Evaluating Your Web Browser's Security Settings for more information).

What other steps can you take?

Sometimes the threats to your information aren't from other people but from
natural or technological causes. Although there is no way to control or
prevent these problems, you can prepare for them and try to minimize the
damage.
* Protect your computer against power surges and brief outages. Aside from
providing outlets to plug in your computer and all of its peripherals,
some power strips protect your computer against power surges. Many power
strips now advertise compensation if they do not effectively protect
your computer. Power strips alone will not protect you from power
outages, but there are products that do offer an uninterruptible power
supply when there are power surges or outages. During a lightning storm
or construction work that increases the odds of power surges, consider
shutting your computer down and unplugging it from all power sources.
* Back up all of your data. Whether or not you take steps to protect
yourself, there will always be a possibility that something will happen
to destroy your data. You have probably already experienced this at
least once— losing one or more files due to an accident, a virus or
worm, a natural event, or a problem with your equipment. Regularly
backing up your data on a CD or network reduces the stress and other
negative consequences that result from losing important information (see
Real-World Warnings Keep You Safe Online for more information).
Determining how often to back up your data is a personal decision. If
you are constantly adding or changing data, you may find weekly backups
to be the best alternative; if your content rarely changes, you may
decide that your backups do not need to be as frequent. You don't need
to back up software that you own on CD-ROM or DVD-ROM—you can reinstall
the software from the original media if necessary.
______________________________
___________________________________

Both the National Cyber Security Alliance and US-CERT have
identified this topic as one of the top tips for home users.
_________________________________________________________________

Authors: Mindi McDowell, Allen Householder
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Note: This tip was previously published and is being re-distributed
to increase awareness.

This document can also be found at

http://www.us-cert.gov/cas/tips/ST04-003.html