Malicious Software and Malware Protection
Malicious software and malware are an integral and dangerous aspect of Internet threats, targeting end-users and organizations via web browsing, email attachments, 3rd party software, social engineering, network vulnerabilities and other means. They may corrupt systems, capture sensitive data, and spread to other systems. It is best for companies to develop a layered approach to guard against these threats by combining a security baseline of web filtering, antivirus protection, patch management systems, firewalls, strong security policies and employee training, among other controls.
Web filtering/content control software
Content control software is used to filter and restrict material delivered over the Internet via the web, email or other means. It allows a company to block out pages from websites that are likely to include objectionable advertising, pornographic content, spyware, viruses and other objectionable content. To enable access to sites that may have been unintentionally blocked, some products provide soft blocking in which a warning is sent to the user with instructions on how to request an administrator to unblock access to the site.
Whitelisting and blacklisting software are additional ways of preventing potentially harmful content, applications or entities from running on or accessing your devices or network. Whitelisting specifies which are approved to connect to the network or devices. Blacklisting specifies which are not approved to connect to the network or devices. Whitelisting may offer greater protection than blacklisting, but a drawback is that it can also block needed access that was not included on the white list. A challenge with using blacklisting is that it is necessary to continually maintain and update the list due to the rapid pace with which malicious sites come and go.
Antivirus protection
A service contract should be established with an antivirus company to install and continuously update antivirus software on all company computers and mobile devices. Antivirus is a protective software program that is designed to defend your network against malicious software or malware and other codes that can damage, corrupt or steal your data. Viruses and malware can be transmitted over the Internet and also can be downloaded to your network through corrupted computers, software programs, mobile devices and portable media storage devices. When detected, the program takes action to remove or quarantine the virus.
The most common antivirus detection is signature-based. These programs look at the content of each file in your computer, searching for specific patterns that match a profile of something known to be harmful. For each file that matches a signature, the antivirus program typically provides several options on how to respond, such as removing or quarantining the offending patterns or destroying the file.
In order to maintain an effective defense, your antivirus software should run in the background at all times and be continually updated. The antivirus software provider should be responsible for providing antivirus updates as new types of malware are discovered. The ability to quickly install all antivirus updates on all equipment is critical. Your Chief Information Security Officer (CISO) should establish time-based security requirements with your antivirus software provider to implement a process to verify all computers and mobile devices have downloaded the updates within a specified timeframe.
Software security controls
While the business manager is responsible for assigning access privileges and ensuring the appropriate level of security is being maintained (installing upgrades, patches, etc.) for all software within their department, the responsibility for installing these security controls may be delegated to another, such as your in-house CISO or your third-party service providers. Risk management considerations include, but are not limited to:
- Devise a list of authorized software that is required in the enterprise for each type of system, including servers, workstations, and mobile devices.
- Deploy application whitelisting technology that allows systems to run only approved software and prevents execution of all other software on the system.
- Perform regular scanning to identify and alert if unapproved software is installed on a computer. All purchased software should be licensed to your company and employees should be knowledgeable of and in compliance with the licensing requirements.
Patch management system
Patches are additional pieces of code developed to address problems (commonly called “bugs”) in software or to address security flaws within a program. Because unpatched systems are vulnerable to hackers, it is important to establish an automated patch management system for all operating systems and application software on your network.
The CISO should work with the vendors of their operating system, network devices and applications to implement an automated system that can verify all patches are completed in a timely manner and can report any equipment not properly patched within a specified time frame. Risk management considerations include, but are not limited to:
- Prioritize your patch management system.
- All system patches for software that do not handle sensitive data can be updated on a predetermined schedule.
- Those systems or applications that handle data from untrusted sources such as the Internet should be patched more often.
- Critical patches should be applied promptly, whenever they are released.
- Configure computers to automatically download patches.
- If the patches will interfere with business operations, arrange for the patches to be installed at each daily start up.
- For complex patches that may cause unintended changes to your network programs, the patch should be tested on an unconnected processor or directory prior to introducing it into your network.
- Automatically initiate patches for laptops and mobile devices whenever the devices are connected to the network.
Outdated software and applications
Companies have an increased risk of a cyber-attack where legacy devices or databases are still in existence built under outdated security practices that often include weak and/or unencrypted passwords.
- Remove any old software or hardware from your network that is no longer supported by its manufacturer and no longer capable of accepting patches or antivirus software.
- Air gapped systems should be used to isolate and run applications for legacy systems that are required for business operations so they are not able to be directly connected to the network.
Upgrades or revisions to equipment and systems
Inadequate control of changes to network equipment and systems can be a common cause of systems and security failures. Lack of a written procedure creates the risk that changes could be made without proper preparation or testing. It also can result in different departments within the company making various changes without a coordinated approach, resulting in a significant adverse impact to company systems.
- Establish a written procedure that governs and coordinates all changes to existing configurations.
New equipment purchases
A common method for attacking system networks is to search for new systems where the owner did not change the default security settings. Default configurations are often geared to ease-of-deployment and ease-of-use and not security because the manufacturers are not aware of each company’s security needs. The CISO should verify the following steps have been completed:
- Patch and upgrade the operating system as needed.
- Change all default passwords.
- Reduce the attack surface by removing or disabling unnecessary services, software and applications and close unnecessary equipment ports.
- Install antivirus software.
Separation of new or developmental software
Newly purchased or developmental software may cause unintended changes to your network programs.
- Whenever possible, test the software and its security settings on an unconnected processor or directory prior to introducing it into your network.
- Ensure in-house and external software developers are well-versed in secure programming methodologies and testing techniques. All new software must be in compliance with the company security requirements.