SlideShare una empresa de Scribd logo
1 de 22
Operating System
Security
O Rachel Jeewa
O www.twitter.com/RachelJeewa

1
In Old Days

2
Objective
O Nowadays,

as systems grow powerful , attacks on
system grow more sophisticated.

O Therefore, it is important that the system

users secure the computer from threats.

3
Threats to System Security
O Virus

A virus is a program that replicates by
copying itself to other programs, system
boot sectors or documents or applications.
Some viruses can damage to your files by
deleting or corrupting them. Some may
display rude or strange message on the
screen. Some can allow other people to
access and control your computer.
4
Trojan
O A Trojan is a

program that seems
to legitimate but
acts maliciously
when executed. It
can open direct
entry point for
attacker so attacker
may use system’s
resources such as
hard disk spce.

Spyware
O Spyware includes

Trojans and other
malicious software
that steals personal
information from a
system without
user’s knowledge.

6
Log-in Password Cracking
1.Guessing
Password Guessing is trying different
passwords until one works.
2.Shoulder Surfing
Shoulder Surfing involves watching while
someone types the password.

7
Log-in Password Cracking
3. Social Engineering
Social Engineering is tricking people to reveal
their passwords or other information that can be
used to guess a password.
4.Dictionary Attack
Dictionary attack uses a pre-defined list of
words to recover the password. This is likely to
succeed when the password is short. Several
password cracking programs are available on
the internet.

8
Guidelines for Windows OS
Security
1.Lock the system when not in use
It helps to secure the workstation from an
unauthorized user.
Method_ Selects the Window and L buttons
together on the keyboard to lock the system.
2.Create strong user password
A weak password does not offer an effective
protection .Always use strong password e.g
tEst@5#8*
Method_ Control Panel
User Accounts

9
Guidelines for Windows OS
Security
3.Disable the guest account
Unwanted guest accounts can be exploited
by attackers to gain entry in to the system.
Method_ Click the Start button, right-click
Computer from shortcut menu, and choose
Manage. Go to Local Users and Groups
Users. Double-click on Guest icon. In the
Guest Properties window, check the box
next to Account is disabled and click OK .
10
Guidelines for Windows OS
Security
4.Lock out unwanted guests
Lock out unwanted guests by configuring
the setting of the account lockout policy to
limit the number of login attempts .
Method_ click on Start button, Control
Panel,
And click Administrative Tools. Double
click the Local Security Policy, click
Account Policies, double-click the
Account Lockout Policy, and double click
Account Lockout Threshold. A the prompt,
enter the number of invalid login (e.g 3).
Click OK.

11
Window Update in Window7
For Window OS, enable automatic updates
to ensure that the OS is patched and up-todate.
Method_ click Start , Control Panel and
select System and Security. Select
Windows Update
Change Settings.
Choose how Windows should updates and
click OK.
12
Pointers for Updates
O Always patch the OS and applications to
O
O
O
O

the latest patch levels.
Ensure that patches are downloaded only
from vendor site.
Use patch management tools for easier
updating . Several free tools are available.
Do not send patches through email.
Choose to be notified by the vendor about
vulnerability announcements.
13
Window Firewall
O A firewall is software that guards the

system from unwarranted traffic when
connected to a network. Hackers can try
to take advantage of programs running on
the system and try to execute malicious
code. Hacking tools such as Trojan can
send information from the victim’s
computer to the attacker’s computer. A
firewall can detect this attack and block
certain traffic .
14
Configuring Window Firewall
O Steps to configure window firewall include:

Method_ Start
Control Panel
In the search box, type firewall and click
Windows Firewall.
In the left pane, click Turn Windows
Firewall On or Off.
Check the circles Turn On Windows
Firewall.
Click OK.
15
Using NTFS
O The NTFS file system provides better

performance and security for data on hard
disks and partitions than FAT file system.
You can convert earlier FAT or FAT32 file
system to NTFS by using the covert
command.

16
Using NTFS
O Click Start and type cmd , right click

Command Prompt and then click Run as
Administrator.
O In the Command Prompt, type covert
drive_letter: /fs:ntfs , where drive_letter is
the letter of the drive to be converted to
NTFS. Then press Enter.
O Type the name of the volume you want to
convert and press enter.When the conversion
complete restart the computer.
O Note-Converting to NTFS does not affect the
data.

17
Windows EFS
O Windows encryption file system(EFS) allows

window7 user to encrypt files and folders. But
encryption does not allow encryption on
compressed or zipped files and system files.
O Method_ right click on a file or folder to encrypt,
select Properties on the General tab, and click
the Advanced botton. Select Encrypt contents
to secure data. Click OK to close the dialog box
and click Apply
O The encryption dialog box appears. Check either
18
of the two options and click OK.
Decrypt A File Using EFS
O To decrypt a encrypted folder or file-

Right click on the folder or file to decrypt
and select Properties. On the General tab,
click the Advanced button. The Advanced
Attributes box will appears.
Uncheck Encrypt contents to secure data,
click OK to close the dialog box, apply the
settings and click OK.
19
BitLocker
O BitLocker drive encryption allows the

entire volume of the system to be
secured. Encrypted removable media can
be decrypted and re-encrypted again.
O Method_ click Start and click Computer.

Right click on the drive and select the
option Turn On BitLocker…
20
Windows Security Tools
1.Microsoft Security Essentials
http://www.microsoft.com
2.Keepass Password Safe Portable
http://www.portableapps.com
3.Registry Mechanic
http://www.pctools.com
21
Thank You!

22

Más contenido relacionado

La actualidad más candente

Virus & Computer security threats
Virus & Computer security threatsVirus & Computer security threats
Virus & Computer security threatsAzri Abdin
 
Information Security Lecture #1 ppt
Information Security Lecture #1 pptInformation Security Lecture #1 ppt
Information Security Lecture #1 pptvasanthimuniasamy
 
Web Security Attacks
Web Security AttacksWeb Security Attacks
Web Security AttacksSajid Hasan
 
The CIA triad.pptx
The CIA triad.pptxThe CIA triad.pptx
The CIA triad.pptxGulnurAzat
 
Operating system security
Operating system securityOperating system security
Operating system securityRamesh Ogania
 
Cia security model
Cia security modelCia security model
Cia security modelImran Ahmed
 
Basics of Information System Security
Basics of Information System SecurityBasics of Information System Security
Basics of Information System Securitychauhankapil
 
What is Cryptography and Types of attacks in it
What is Cryptography and Types of attacks in itWhat is Cryptography and Types of attacks in it
What is Cryptography and Types of attacks in itlavakumar Thatisetti
 
Trojan virus & backdoors
Trojan virus & backdoorsTrojan virus & backdoors
Trojan virus & backdoorsShrey Vyas
 
Information Security- Threats and Attacks presentation by DHEERAJ KATARIA
Information Security- Threats and Attacks presentation by DHEERAJ KATARIAInformation Security- Threats and Attacks presentation by DHEERAJ KATARIA
Information Security- Threats and Attacks presentation by DHEERAJ KATARIADheeraj Kataria
 
Network security (vulnerabilities, threats, and attacks)
Network security (vulnerabilities, threats, and attacks)Network security (vulnerabilities, threats, and attacks)
Network security (vulnerabilities, threats, and attacks)Fabiha Shahzad
 
Database Security And Authentication
Database Security And AuthenticationDatabase Security And Authentication
Database Security And AuthenticationSudeb Das
 
Introduction to Network Security
Introduction to Network SecurityIntroduction to Network Security
Introduction to Network SecurityJohn Ely Masculino
 

La actualidad más candente (20)

Computer Security Threats
Computer Security ThreatsComputer Security Threats
Computer Security Threats
 
Software security
Software securitySoftware security
Software security
 
Virus & Computer security threats
Virus & Computer security threatsVirus & Computer security threats
Virus & Computer security threats
 
Information Security Lecture #1 ppt
Information Security Lecture #1 pptInformation Security Lecture #1 ppt
Information Security Lecture #1 ppt
 
Web Security Attacks
Web Security AttacksWeb Security Attacks
Web Security Attacks
 
The CIA triad.pptx
The CIA triad.pptxThe CIA triad.pptx
The CIA triad.pptx
 
Operating system security
Operating system securityOperating system security
Operating system security
 
Cia security model
Cia security modelCia security model
Cia security model
 
03 cia
03 cia03 cia
03 cia
 
system Security
system Security system Security
system Security
 
Basics of Information System Security
Basics of Information System SecurityBasics of Information System Security
Basics of Information System Security
 
What is Cryptography and Types of attacks in it
What is Cryptography and Types of attacks in itWhat is Cryptography and Types of attacks in it
What is Cryptography and Types of attacks in it
 
Trojan virus & backdoors
Trojan virus & backdoorsTrojan virus & backdoors
Trojan virus & backdoors
 
Information Security- Threats and Attacks presentation by DHEERAJ KATARIA
Information Security- Threats and Attacks presentation by DHEERAJ KATARIAInformation Security- Threats and Attacks presentation by DHEERAJ KATARIA
Information Security- Threats and Attacks presentation by DHEERAJ KATARIA
 
Network security (vulnerabilities, threats, and attacks)
Network security (vulnerabilities, threats, and attacks)Network security (vulnerabilities, threats, and attacks)
Network security (vulnerabilities, threats, and attacks)
 
Information security
Information securityInformation security
Information security
 
Malware
MalwareMalware
Malware
 
Database Security And Authentication
Database Security And AuthenticationDatabase Security And Authentication
Database Security And Authentication
 
Introduction to Network Security
Introduction to Network SecurityIntroduction to Network Security
Introduction to Network Security
 
OS Security 2009
OS Security 2009OS Security 2009
OS Security 2009
 

Similar a Operating system security

18IF004_CNS.docx
18IF004_CNS.docx18IF004_CNS.docx
18IF004_CNS.docxRajAmbere1
 
Operating systems 2
Operating systems 2Operating systems 2
Operating systems 2mariacalji
 
so big 22
so big 22so big 22
so big 22cainem
 
so big ppt
so big pptso big ppt
so big pptcainem
 
so big
so bigso big
so bigcainem
 
Desktop and server securityse
Desktop and server securityseDesktop and server securityse
Desktop and server securityseAppin Ara
 
Fixed: Slow Startup on Windows 10 HP Laptop
Fixed: Slow Startup on Windows 10 HP LaptopFixed: Slow Startup on Windows 10 HP Laptop
Fixed: Slow Startup on Windows 10 HP LaptopDash Milly
 
How to Troubleshoot QuickBooks Error 1303?
How to Troubleshoot QuickBooks Error 1303?How to Troubleshoot QuickBooks Error 1303?
How to Troubleshoot QuickBooks Error 1303?nickmosan
 
Checking Windows for signs of compromise
Checking Windows for signs of compromiseChecking Windows for signs of compromise
Checking Windows for signs of compromiseCal Bryant
 
Operating systems
Operating systemsOperating systems
Operating systemssandrahezro
 
Remove Clickhoofind.com
 Remove Clickhoofind.com Remove Clickhoofind.com
Remove Clickhoofind.comkingh05
 
Cscu module 02 securing operating systems
Cscu module 02 securing operating systemsCscu module 02 securing operating systems
Cscu module 02 securing operating systemsSejahtera Affif
 
Optimize your computer for peak performance
Optimize your computer for peak performanceOptimize your computer for peak performance
Optimize your computer for peak performancepacampbell
 

Similar a Operating system security (20)

18IF004_CNS.docx
18IF004_CNS.docx18IF004_CNS.docx
18IF004_CNS.docx
 
Operating systems 2
Operating systems 2Operating systems 2
Operating systems 2
 
Windows 0.1
Windows 0.1Windows 0.1
Windows 0.1
 
so big 22
so big 22so big 22
so big 22
 
so big ppt
so big pptso big ppt
so big ppt
 
so big
so bigso big
so big
 
Total Security MAC User Guide
Total Security MAC User GuideTotal Security MAC User Guide
Total Security MAC User Guide
 
LESSON 2.pptx
LESSON 2.pptxLESSON 2.pptx
LESSON 2.pptx
 
Desktop and server securityse
Desktop and server securityseDesktop and server securityse
Desktop and server securityse
 
Desktop and Server Security
Desktop and Server SecurityDesktop and Server Security
Desktop and Server Security
 
Fixed: Slow Startup on Windows 10 HP Laptop
Fixed: Slow Startup on Windows 10 HP LaptopFixed: Slow Startup on Windows 10 HP Laptop
Fixed: Slow Startup on Windows 10 HP Laptop
 
How to Troubleshoot QuickBooks Error 1303?
How to Troubleshoot QuickBooks Error 1303?How to Troubleshoot QuickBooks Error 1303?
How to Troubleshoot QuickBooks Error 1303?
 
Checking Windows for signs of compromise
Checking Windows for signs of compromiseChecking Windows for signs of compromise
Checking Windows for signs of compromise
 
Operating systems
Operating systemsOperating systems
Operating systems
 
Remove Clickhoofind.com
 Remove Clickhoofind.com Remove Clickhoofind.com
Remove Clickhoofind.com
 
Windows Security
Windows Security Windows Security
Windows Security
 
Security
SecuritySecurity
Security
 
Cscu module 02 securing operating systems
Cscu module 02 securing operating systemsCscu module 02 securing operating systems
Cscu module 02 securing operating systems
 
Optimize your computer for peak performance
Optimize your computer for peak performanceOptimize your computer for peak performance
Optimize your computer for peak performance
 
Ransomware
RansomwareRansomware
Ransomware
 

Último

"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontologyjohnbeverley2021
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityWSO2
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 

Último (20)

"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 

Operating system security

  • 1. Operating System Security O Rachel Jeewa O www.twitter.com/RachelJeewa 1
  • 3. Objective O Nowadays, as systems grow powerful , attacks on system grow more sophisticated. O Therefore, it is important that the system users secure the computer from threats. 3
  • 4. Threats to System Security O Virus A virus is a program that replicates by copying itself to other programs, system boot sectors or documents or applications. Some viruses can damage to your files by deleting or corrupting them. Some may display rude or strange message on the screen. Some can allow other people to access and control your computer. 4
  • 5.
  • 6. Trojan O A Trojan is a program that seems to legitimate but acts maliciously when executed. It can open direct entry point for attacker so attacker may use system’s resources such as hard disk spce. Spyware O Spyware includes Trojans and other malicious software that steals personal information from a system without user’s knowledge. 6
  • 7. Log-in Password Cracking 1.Guessing Password Guessing is trying different passwords until one works. 2.Shoulder Surfing Shoulder Surfing involves watching while someone types the password. 7
  • 8. Log-in Password Cracking 3. Social Engineering Social Engineering is tricking people to reveal their passwords or other information that can be used to guess a password. 4.Dictionary Attack Dictionary attack uses a pre-defined list of words to recover the password. This is likely to succeed when the password is short. Several password cracking programs are available on the internet. 8
  • 9. Guidelines for Windows OS Security 1.Lock the system when not in use It helps to secure the workstation from an unauthorized user. Method_ Selects the Window and L buttons together on the keyboard to lock the system. 2.Create strong user password A weak password does not offer an effective protection .Always use strong password e.g tEst@5#8* Method_ Control Panel User Accounts 9
  • 10. Guidelines for Windows OS Security 3.Disable the guest account Unwanted guest accounts can be exploited by attackers to gain entry in to the system. Method_ Click the Start button, right-click Computer from shortcut menu, and choose Manage. Go to Local Users and Groups Users. Double-click on Guest icon. In the Guest Properties window, check the box next to Account is disabled and click OK . 10
  • 11. Guidelines for Windows OS Security 4.Lock out unwanted guests Lock out unwanted guests by configuring the setting of the account lockout policy to limit the number of login attempts . Method_ click on Start button, Control Panel, And click Administrative Tools. Double click the Local Security Policy, click Account Policies, double-click the Account Lockout Policy, and double click Account Lockout Threshold. A the prompt, enter the number of invalid login (e.g 3). Click OK. 11
  • 12. Window Update in Window7 For Window OS, enable automatic updates to ensure that the OS is patched and up-todate. Method_ click Start , Control Panel and select System and Security. Select Windows Update Change Settings. Choose how Windows should updates and click OK. 12
  • 13. Pointers for Updates O Always patch the OS and applications to O O O O the latest patch levels. Ensure that patches are downloaded only from vendor site. Use patch management tools for easier updating . Several free tools are available. Do not send patches through email. Choose to be notified by the vendor about vulnerability announcements. 13
  • 14. Window Firewall O A firewall is software that guards the system from unwarranted traffic when connected to a network. Hackers can try to take advantage of programs running on the system and try to execute malicious code. Hacking tools such as Trojan can send information from the victim’s computer to the attacker’s computer. A firewall can detect this attack and block certain traffic . 14
  • 15. Configuring Window Firewall O Steps to configure window firewall include: Method_ Start Control Panel In the search box, type firewall and click Windows Firewall. In the left pane, click Turn Windows Firewall On or Off. Check the circles Turn On Windows Firewall. Click OK. 15
  • 16. Using NTFS O The NTFS file system provides better performance and security for data on hard disks and partitions than FAT file system. You can convert earlier FAT or FAT32 file system to NTFS by using the covert command. 16
  • 17. Using NTFS O Click Start and type cmd , right click Command Prompt and then click Run as Administrator. O In the Command Prompt, type covert drive_letter: /fs:ntfs , where drive_letter is the letter of the drive to be converted to NTFS. Then press Enter. O Type the name of the volume you want to convert and press enter.When the conversion complete restart the computer. O Note-Converting to NTFS does not affect the data. 17
  • 18. Windows EFS O Windows encryption file system(EFS) allows window7 user to encrypt files and folders. But encryption does not allow encryption on compressed or zipped files and system files. O Method_ right click on a file or folder to encrypt, select Properties on the General tab, and click the Advanced botton. Select Encrypt contents to secure data. Click OK to close the dialog box and click Apply O The encryption dialog box appears. Check either 18 of the two options and click OK.
  • 19. Decrypt A File Using EFS O To decrypt a encrypted folder or file- Right click on the folder or file to decrypt and select Properties. On the General tab, click the Advanced button. The Advanced Attributes box will appears. Uncheck Encrypt contents to secure data, click OK to close the dialog box, apply the settings and click OK. 19
  • 20. BitLocker O BitLocker drive encryption allows the entire volume of the system to be secured. Encrypted removable media can be decrypted and re-encrypted again. O Method_ click Start and click Computer. Right click on the drive and select the option Turn On BitLocker… 20
  • 21. Windows Security Tools 1.Microsoft Security Essentials http://www.microsoft.com 2.Keepass Password Safe Portable http://www.portableapps.com 3.Registry Mechanic http://www.pctools.com 21