<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Ellipsis: Inoculation</title>
    <link>http://typo.pburkholder.com/articles/2007/01/26/inoculation</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>...</description>
    <item>
      <title>Inoculation</title>
      <description>&lt;p&gt;Two recent news items in &amp;#8220;SANS NewsBites:http://www.sans.org/newsletters/newsbites/ had me thinking about the fun (and profit) from working to ethically &amp;#8220;inoculate&amp;#8221; one&amp;#8217;s staff against phishing and social engineering attacks.&lt;/p&gt;


	&lt;p&gt;To quote:&lt;/p&gt;


	&lt;blockquote&gt;
		&lt;p&gt; &amp;#8212;NY &amp;#8220;Inoculates&amp;#8221; Employees Against eMail-Borne Malware
(22 January 2007)
Will Pelgrin, New York State&amp;#8217;s chief information security officer
(CISO), worked with AT&amp;#38;T and the &lt;span class="caps"&gt;SANS&lt;/span&gt; Institute to develop an
&amp;#8220;inoculation&amp;#8221; program to protect state agency computer systems from
malware infections.  First, approximately 10,000 state agency employees
received email messages alerting them to ongoing phishing activity and
encouraging them to be aware of the risks of opening email from unknown
users and clicking on links in unsolicited email.  The next month, the
employees were told that in keeping with a tightened security posture,
all employees were required to have passwords.  That was followed by an
email that came from outside the network containing a link that if
clicked on, would prompt users for their user IDs and passwords.  The
email contained some clues that it was not legitimate.  If the users
provided the requested information, they got a pop-up telling them they
had failed the test and then were shown a video and given a 10-question
exam.  Eighty-three percent of the recipients did not fall for the scam.
When a similar test was run two months later, that number rose to 92
percent.
http://www.gcn.com/print/26_2/42983-1.html?topic=security&amp;#38;CMP=OTC-RSS        
[Editor&amp;#8217;s Note (Kreitner): This is an excellent example of good security
management supported by a security metric that quantitatively measures
actual progress toward a specific security goal, in this case a
particular change in human behavior.
(Pescatore): A good effort as long as it is continuous. If they measure
a month later, the number will likely drop quite a bit. If the process
continues, they will likely find that the 11% improvement drops off
quite a bit.]&lt;/p&gt;
	&lt;/blockquote&gt;


	&lt;p&gt;And&lt;/p&gt;


	&lt;blockquote&gt;
		&lt;p&gt;&amp;#8212;Half of Finance Managers Put Unsolicited &lt;span class="caps"&gt;USB&lt;/span&gt; Drive in Computers 
(25 January 2007)
As a research project, a consulting firm sent &lt;span class="caps"&gt;USB&lt;/span&gt; sticks to finance
directors at 500 firms in the UK.  The memory devices purported to be
invitations to &amp;#8220;the Party of a Lifetime&amp;#8221; with an anonymous sender but
were actually part of an experiment.  Nearly half of the finance
directors inserted the stick into company computers.  Media companies
fared the worst in the experiment, with 65 percent putting the memory
stick into computers.  At technology, retail and transportation
companies, the figure was between 38 and 39 percent.  The devices could
be used to plant malware on computer systems.
http://www.vnunet.com/computing/news/2173365/uk-firms-naive-usb-stick
[Editor&amp;#8217;s Note (Liston): While this test seems somewhat contrived, you
really can&amp;#8217;t argue with the results.  Human curiosity is an incredibly
strong motivator that will, more often than not, overwhelm common sense.
If you found a &lt;span class="caps"&gt;USB&lt;/span&gt; key laying in the parking lot outside your workplace,
what would &lt;span class="caps"&gt;YOU&lt;/span&gt; do?  What would the majority of your co-workers do?
(Schultz): The results of this research study further underscore the
great need to reach management in security training and awareness
efforts, something that is much too often completely overlooked.
(Honan): This story illustrates how depending on your perimeter defences
alone are no longer sufficient.  Comprehensive security awareness
programmes coupled with technical controls such as locked down desktops
and &lt;span class="caps"&gt;USB&lt;/span&gt; port management are needed in the battle against ever
increasingly sophisticated attackers.  Using resources such as those
provided by the Centre for Internet Security,
http://www.cisecurity.org/, will help.  For example, a simple registry
entry on Windows machines will disable autoplay from any disk type,
regardless of application
&lt;span class="caps"&gt;HKLM&lt;/span&gt;\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun.]&lt;/p&gt;
	&lt;/blockquote&gt;</description>
      <pubDate>Fri, 26 Jan 2007 23:09:00 -0800</pubDate>
      <guid isPermaLink="false">urn:uuid:05e2bdfe-cada-4784-90d2-7e8a7f87857d</guid>
      <author>Peter Burkholder</author>
      <link>http://typo.pburkholder.com/articles/2007/01/26/inoculation</link>
      <category>Security</category>
      <category>phishing</category>
      <category>training</category>
      <category>security</category>
    </item>
    <item>
      <title>"Inoculation" by grand casino</title>
      <description>Punenet.com präsentiert den brandneuen Grand Casino Test. Lesen Sie Informationen über das Grand Casino und deren Betreiber.</description>
      <pubDate>Sat, 29 Dec 2007 08:47:14 -0800</pubDate>
      <guid isPermaLink="false">urn:uuid:b25d87c9-2c0b-429f-8588-b197c2efaceb</guid>
      <link>http://typo.pburkholder.com/articles/2007/01/26/inoculation#comment-3988</link>
    </item>
    <item>
      <title>"Inoculation" by Online casino</title>
      <description>Spielen Sie Kasino online und amüsieren Sie sich dabei. Spielen Sie nicht zu viel, sonst ist das ganze Geld weg.</description>
      <pubDate>Mon, 24 Dec 2007 07:58:30 -0800</pubDate>
      <guid isPermaLink="false">urn:uuid:18554fdf-7afc-487b-982c-e598a3f108b2</guid>
      <link>http://typo.pburkholder.com/articles/2007/01/26/inoculation#comment-3981</link>
    </item>
    <item>
      <title>"Inoculation" by online casino spiele</title>
      <description>Spielen Sie online casino spiele in sicheren und seriösen Online Casinos, mit der Sicherheit, dass Sie vollen Zugriff auf die wichtigsten Tipps und Tricks aus dem Online Casino Bereich haben. Mit einem Überblick über Casino Bonus und Casino Aktionsangeboten.</description>
      <pubDate>Mon, 03 Dec 2007 21:52:57 -0800</pubDate>
      <guid isPermaLink="false">urn:uuid:9700e1a5-6be2-4020-a080-99813987e5de</guid>
      <link>http://typo.pburkholder.com/articles/2007/01/26/inoculation#comment-3971</link>
    </item>
    <item>
      <title>"Inoculation" by Jennifer Smith</title>
      <description>Hi

Instant messaging security firm IMLogic warned of a new phishing attack making its way through the Yahoo! Messenger network on Monday.

Jusit in case...
Jennifer</description>
      <pubDate>Fri, 02 Feb 2007 07:55:55 -0800</pubDate>
      <guid isPermaLink="false">urn:uuid:5c007f0c-2b24-4244-85a3-6a745445da32</guid>
      <link>http://typo.pburkholder.com/articles/2007/01/26/inoculation#comment-3937</link>
    </item>
  </channel>
</rss>
