SlideShare una empresa de Scribd logo
1 de 10
Cover Your Assets: How to Limit the
Risk of Attack on your Windows XP
Assets
Tom D’Aquino – Sr. Security Engineer
ABOUT ALIENVAULT
AlienVault has unified the security products, intelligence and
community essential for mid-sized businesses to defend against
today’s modern threats
THE CHALLENGE
 Windows XP is end of support and subsequently creating risk for your organization:
 What does “end of support” mean?
 How do you find out of date assets?
 Are your out of date assets vulnerable?
 Are your out of date assets being attacked?
 What else can you do to manage the risk created by out of date assets?
 Event correlation rules and reports
END OF SUPPORT DATES
 As reported by Microsoft:
Available at http://windows.microsoft.com/en-us/windows/lifecycle
END OF SUPPORT CLARIFIED
 As reported by Microsoft:
Available at http://windows.microsoft.com/en-us/windows/lifecycle
ATTACK VECTORS TO CONSIDER
Network Exploits – this is our traditional network worm, which is
exploiting a service running on our XP machine. A classic example of this
is the conficker worm that targeted a vulnerability in the server service in
Windows XP.
Browser-based attacks – this is our most common attack, where a user
is targeted as they are browsing the web (or are sent a malicious link in
an email) and an exploit targeting the browser or an enabled browser
plugin is used to compromise the machine.
Malicious Email attachments – another favorite, a malicious attachment
is sent with an email and an exploit targeting the program configured to
read the attachment is used (our most common target here is the PDF
viewer)
IMMEDIATE ACTIONS TO LIMIT YOUR RISK
Limit Inbound Network Access – place the XP machines on a dedicated network
segment and limit access by other machines in your environment. (This mitigates
Network Exploits)
Use a Non-Administrative Account – the majority of exploits targeting desktop
software are mitigated when the user account is a standard user. (This mitigates
Browser-based attacks and malicious email attachments)
Use a browser with a long-term support plan - Google Chrome is extending their
XP support until April 2015. If you do choose to browse, turn off your plugins (This
mitigates Browser-based attacks)
Read your email in your browser – leverage your email server’s web front-end and
be particularly conservative about the attachments you download and open. (This
mitigates Malicious email attachments)
Monitor your systems - The most important thing is catching an incident before it
turns into a problem.
WARNING SIGNS TO WATCH OUT FOR
Command and control traffic
Internal probing
Increased network activity
Connections with known malicious IPs
powered by
AV Labs Threat
Intelligence
USM
ASSET DISCOVERY
• Active Network Scanning
• Passive Network Scanning
• Asset Inventory
• Host-based Software
Inventory
VULNERABILITY ASSESSMENT
• Continuous
Vulnerability Monitoring
• Authenticated /
Unauthenticated Active
Scanning
BEHAVIORAL MONITORING
• Log Collection
• Netflow Analysis
• Service Availability Monitoring
SECURITY INTELLIGENCE
• SIEM Event Correlation
• Incident Response
THREAT DETECTION
• Network IDS
• Host IDS
• Wireless IDS
• File Integrity Monitoring
WHAT TO DO ABOUT OUT OF DATE ASSETS
NOW FOR SOME Q&A…
Test Drive AlienVault USM
Download a Free 30-Day Trial
http://www.alienvault.com/free-trial
Try our Interactive Demo Site
http://www.alienvault.com/live-demo-site
Questions? hello@alienvault.com

Más contenido relacionado

Más de AlienVault

AWS Security Best Practices for Effective Threat Detection & Response
AWS Security Best Practices for Effective Threat Detection & ResponseAWS Security Best Practices for Effective Threat Detection & Response
AWS Security Best Practices for Effective Threat Detection & Response
AlienVault
 

Más de AlienVault (20)

Malware Invaders - Is Your OS at Risk?
Malware Invaders - Is Your OS at Risk?Malware Invaders - Is Your OS at Risk?
Malware Invaders - Is Your OS at Risk?
 
How to Solve Your Top IT Security Reporting Challenges with AlienVault
How to Solve Your Top IT Security Reporting Challenges with AlienVaultHow to Solve Your Top IT Security Reporting Challenges with AlienVault
How to Solve Your Top IT Security Reporting Challenges with AlienVault
 
Simplify PCI DSS Compliance with AlienVault USM
Simplify PCI DSS Compliance with AlienVault USMSimplify PCI DSS Compliance with AlienVault USM
Simplify PCI DSS Compliance with AlienVault USM
 
SIEM for Beginners: Everything You Wanted to Know About Log Management but We...
SIEM for Beginners: Everything You Wanted to Know About Log Management but We...SIEM for Beginners: Everything You Wanted to Know About Log Management but We...
SIEM for Beginners: Everything You Wanted to Know About Log Management but We...
 
Insider Threat Detection Recommendations
Insider Threat Detection RecommendationsInsider Threat Detection Recommendations
Insider Threat Detection Recommendations
 
Alienvault threat alerts in spiceworks
Alienvault threat alerts in spiceworksAlienvault threat alerts in spiceworks
Alienvault threat alerts in spiceworks
 
Open Source IDS Tools: A Beginner's Guide
Open Source IDS Tools: A Beginner's GuideOpen Source IDS Tools: A Beginner's Guide
Open Source IDS Tools: A Beginner's Guide
 
Malware detection how to spot infections early with alien vault usm
Malware detection how to spot infections early with alien vault usmMalware detection how to spot infections early with alien vault usm
Malware detection how to spot infections early with alien vault usm
 
Security operations center 5 security controls
 Security operations center 5 security controls Security operations center 5 security controls
Security operations center 5 security controls
 
PCI DSS Implementation: A Five Step Guide
PCI DSS Implementation: A Five Step GuidePCI DSS Implementation: A Five Step Guide
PCI DSS Implementation: A Five Step Guide
 
Improve threat detection with hids and alien vault usm
Improve threat detection with hids and alien vault usmImprove threat detection with hids and alien vault usm
Improve threat detection with hids and alien vault usm
 
The State of Incident Response - INFOGRAPHIC
The State of Incident Response - INFOGRAPHICThe State of Incident Response - INFOGRAPHIC
The State of Incident Response - INFOGRAPHIC
 
Incident response live demo slides final
Incident response live demo slides finalIncident response live demo slides final
Incident response live demo slides final
 
Improve Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USMImprove Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USM
 
Improve Security Visibility with AlienVault USM Correlation Directives
Improve Security Visibility with AlienVault USM Correlation DirectivesImprove Security Visibility with AlienVault USM Correlation Directives
Improve Security Visibility with AlienVault USM Correlation Directives
 
How Malware Works
How Malware WorksHow Malware Works
How Malware Works
 
New USM v5.0 - Get Complete Security Visibility Faster & Easier Than Ever
New USM v5.0 - Get Complete Security Visibility Faster & Easier Than EverNew USM v5.0 - Get Complete Security Visibility Faster & Easier Than Ever
New USM v5.0 - Get Complete Security Visibility Faster & Easier Than Ever
 
New OSSIM v5.0 - Get Security Visibility Faster & Easier Than Ever
 New OSSIM v5.0 - Get Security Visibility Faster & Easier Than Ever New OSSIM v5.0 - Get Security Visibility Faster & Easier Than Ever
New OSSIM v5.0 - Get Security Visibility Faster & Easier Than Ever
 
AWS Security Best Practices for Effective Threat Detection & Response
AWS Security Best Practices for Effective Threat Detection & ResponseAWS Security Best Practices for Effective Threat Detection & Response
AWS Security Best Practices for Effective Threat Detection & Response
 
Improve Threat Detection with OSSEC and AlienVault USM
Improve Threat Detection with OSSEC and AlienVault USMImprove Threat Detection with OSSEC and AlienVault USM
Improve Threat Detection with OSSEC and AlienVault USM
 

Último

Último (20)

Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
 
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya HalderCustom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
 
PLAI - Acceleration Program for Generative A.I. Startups
PLAI - Acceleration Program for Generative A.I. StartupsPLAI - Acceleration Program for Generative A.I. Startups
PLAI - Acceleration Program for Generative A.I. Startups
 
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptxWSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
 
THE BEST IPTV in GERMANY for 2024: IPTVreel
THE BEST IPTV in  GERMANY for 2024: IPTVreelTHE BEST IPTV in  GERMANY for 2024: IPTVreel
THE BEST IPTV in GERMANY for 2024: IPTVreel
 
IESVE for Early Stage Design and Planning
IESVE for Early Stage Design and PlanningIESVE for Early Stage Design and Planning
IESVE for Early Stage Design and Planning
 
AI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří KarpíšekAI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří Karpíšek
 
IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024
 
10 Differences between Sales Cloud and CPQ, Blanka Doktorová
10 Differences between Sales Cloud and CPQ, Blanka Doktorová10 Differences between Sales Cloud and CPQ, Blanka Doktorová
10 Differences between Sales Cloud and CPQ, Blanka Doktorová
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
 
Powerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara LaskowskaPowerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara Laskowska
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
 
Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfThe Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
 
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
 
Agentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdfAgentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdf
 
Buy Epson EcoTank L3210 Colour Printer Online.pdf
Buy Epson EcoTank L3210 Colour Printer Online.pdfBuy Epson EcoTank L3210 Colour Printer Online.pdf
Buy Epson EcoTank L3210 Colour Printer Online.pdf
 
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi IbrahimzadeFree and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
 
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdfSimplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
 
Syngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdfSyngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdf
 

Cover your Assets: How to Limit the Risk of Attack on your XP Assets

  • 1. Cover Your Assets: How to Limit the Risk of Attack on your Windows XP Assets Tom D’Aquino – Sr. Security Engineer
  • 2. ABOUT ALIENVAULT AlienVault has unified the security products, intelligence and community essential for mid-sized businesses to defend against today’s modern threats
  • 3. THE CHALLENGE  Windows XP is end of support and subsequently creating risk for your organization:  What does “end of support” mean?  How do you find out of date assets?  Are your out of date assets vulnerable?  Are your out of date assets being attacked?  What else can you do to manage the risk created by out of date assets?  Event correlation rules and reports
  • 4. END OF SUPPORT DATES  As reported by Microsoft: Available at http://windows.microsoft.com/en-us/windows/lifecycle
  • 5. END OF SUPPORT CLARIFIED  As reported by Microsoft: Available at http://windows.microsoft.com/en-us/windows/lifecycle
  • 6. ATTACK VECTORS TO CONSIDER Network Exploits – this is our traditional network worm, which is exploiting a service running on our XP machine. A classic example of this is the conficker worm that targeted a vulnerability in the server service in Windows XP. Browser-based attacks – this is our most common attack, where a user is targeted as they are browsing the web (or are sent a malicious link in an email) and an exploit targeting the browser or an enabled browser plugin is used to compromise the machine. Malicious Email attachments – another favorite, a malicious attachment is sent with an email and an exploit targeting the program configured to read the attachment is used (our most common target here is the PDF viewer)
  • 7. IMMEDIATE ACTIONS TO LIMIT YOUR RISK Limit Inbound Network Access – place the XP machines on a dedicated network segment and limit access by other machines in your environment. (This mitigates Network Exploits) Use a Non-Administrative Account – the majority of exploits targeting desktop software are mitigated when the user account is a standard user. (This mitigates Browser-based attacks and malicious email attachments) Use a browser with a long-term support plan - Google Chrome is extending their XP support until April 2015. If you do choose to browse, turn off your plugins (This mitigates Browser-based attacks) Read your email in your browser – leverage your email server’s web front-end and be particularly conservative about the attachments you download and open. (This mitigates Malicious email attachments) Monitor your systems - The most important thing is catching an incident before it turns into a problem.
  • 8. WARNING SIGNS TO WATCH OUT FOR Command and control traffic Internal probing Increased network activity Connections with known malicious IPs
  • 9. powered by AV Labs Threat Intelligence USM ASSET DISCOVERY • Active Network Scanning • Passive Network Scanning • Asset Inventory • Host-based Software Inventory VULNERABILITY ASSESSMENT • Continuous Vulnerability Monitoring • Authenticated / Unauthenticated Active Scanning BEHAVIORAL MONITORING • Log Collection • Netflow Analysis • Service Availability Monitoring SECURITY INTELLIGENCE • SIEM Event Correlation • Incident Response THREAT DETECTION • Network IDS • Host IDS • Wireless IDS • File Integrity Monitoring WHAT TO DO ABOUT OUT OF DATE ASSETS
  • 10. NOW FOR SOME Q&A… Test Drive AlienVault USM Download a Free 30-Day Trial http://www.alienvault.com/free-trial Try our Interactive Demo Site http://www.alienvault.com/live-demo-site Questions? hello@alienvault.com

Notas del editor

  1. \
  2. Delivers 8 coordinated rulesets, fueled by the collective power of the Open Threat Exchange, to drive the USM security capabilities and identify the latest threats, resulting in the broadest view of attacker techniques and effective defenses.
  3. Delivers 8 coordinated rulesets, fueled by the collective power of the Open Threat Exchange, to drive the USM security capabilities and identify the latest threats, resulting in the broadest view of attacker techniques and effective defenses.
  4. Delivers 8 coordinated rulesets, fueled by the collective power of the Open Threat Exchange, to drive the USM security capabilities and identify the latest threats, resulting in the broadest view of attacker techniques and effective defenses.
  5. Limit Inbound Network Access – place the XP machines on a dedicated network segment and limit access by other machines in your environment. Keeping these machines segmented will minimize the chances for these machines to be targeted and exploited. Limiting network access substantially reduces your chance of being targeted and compromised by network exploits. The assets you most need to be concerned about are running your business systems. The point of sale terminals at Target were running Windows XP embedded - cutting them off from the rest of the network would have done a lot! (This mitigates Network Exploits)Use a Non-Administrative Account – the majority of exploits targeting desktop software (web-browsers, java, adobe flash, adobe reader) are mitigated when the user account is a standard user. It is a disruptive task to try and migrate an existing user to a non-administrative account. Instead, try reducing the privileges of your existing user accounts. (This mitigates Browser-based attacks and malicious email attachments)Use a browser with a long-term support plan – if you can’t stop browsing the web from the Windows XP machine, at least use an up-to-date browser. Google Chrome is extending their support until April 2015. If you do choose to browse, please turn off your plugins This mitigates Browser-based attacksRead your email in your browser – using your up-to-date browser, (you are following recommendation 3 right?) leverage your email server’s web front-end and be particularly conservative about the attachments you download and open. (This mitigates Malicious email attachments)Monitor your systems – always check your work! The most important thing is catching an incident before it turns into a problem. Look out for command and control traffic, internal probing, increased network activity and other signs of an infection. Of course AlienVault USM is an excellent choice for this step! - See more at: https://www.alienvault.com/blogs/industry-insights/a-practical-approach-to-the-windows-xp-security-cliff#sthash.VZrW7Cna.dpuf