Tuesday, April 16, 2013

Ransomeware Now #1 MalwareThreat - Learn More Here

I just read an outstanding white paper from a couple of researchers at Sophos Security outlining how Ransomware is passing up FakeAlert malware as the biggest and most serious threat to users of the Internet.  This reinforces our experience in the field.

Ransomware differs from other malware in that it attempts to extort a payment from the infected user by either doing or threatening to do something malicious to their computer (or network) like encrypting all of their files or locking it up.  Most times, even when the ransom is paid, the files never get un-encrypted leaving a disaster behind.  The encryption levels can be sophisticated enough that even advance decryption software can't unscramble the mess. 

Ramsonware can be delivered either by an infected web site or via e-mail.  At last count the number of infected legitimate web sites sat at over 28 million according to some experts. 

There are several ways to reduce your risk of infection: 
  • First and foremost, computer users have to do a better job of keeping all their programs, their browsers, their operating systems (whether it be Windows, MAC OS, Linux or Android) and their support apps like Java, Acrobat, FlashPlayer etc up to date. 
  • Second, keep your A/V programs updating in real-time and set to do Heuristic scanning if it has that capability.  Throw away those "free" A/V programs if your using one of them and buy a real A/V program from one of the top 5 A/V companies.  (Trend Micro, McAfee, Symantec, Kaspersky or Sophos) We also like Viper.
  • Add, off-site e-mail spam scrubbing to your e-mail domain.  It's better to screen your incoming e-mail for problems before it arrives on your computer or network to reduce exposure. 
  • Finally, you should consider adding a perimeter anti-malware component to your network protection strategy.  This reduces the risk of malware from ever getting into your network in the first place and greatly reduces your risk of infection.
No single solution wil be 100% effective.  The malware writers will always find a vulnerability to exploit in time but if you're to stay ahead of them enough to greatly reduce your exposure you need to create a blended approach to security. 

There are also additional steps that can be taken to mitigate the problems caused by all kinds of malware including having a real-time backup solution that improves your ability to recover from an infection. 

Don't forget to secure your portable devices, too! Experts agree that there are vastly more security holes on portables that PCs because so many apps are so poorly written and are full of holes. Lock down your smartphones, tablets and other portables too.

If you're not treating malware as an ever-present real threat to your network, it's inevitable that you're going to get hit.  The only real questions then are "How hard?" and "Will you be able to recover?"

For additional help, you can contact us anytime at ACT Network Solutions at (847) 639-7000.

No comments:

Post a Comment