ECE590 Computer and Information Security Fall 2019
Endpoint security
Tyler Bletsch Duke University
Computer and Information Security Fall 2019 Endpoint security - - PowerPoint PPT Presentation
ECE590 Computer and Information Security Fall 2019 Endpoint security Tyler Bletsch Duke University Overview How do you configure endpoints for better security? 1. Updates 2. Correct settings 3. Reduce attack surface 4. Limit privilege 5.
Tyler Bletsch Duke University
2
3
The only reason not to do this is laziness or stupidity.
4
5
6
7
E.g. Docker containers (discussed later)
8
9
1. Record changes to data over time
RESULT: MIRRORING ISN’T BACKUP!!!! 2. Have a copy at a separate physical location
3. Must be automatic ▪ When you get busy, you’ll forget, and busy people make the most important data 4. Require separate credentials to access
then that account is a single point of failure 5. Be unwritable by anyone except the backup software (which ideally should live in the restricted backup environment)
then the same mistake/attack that killed the primary can kill the backup 6. Reliably report on progress and alert on failure
7. Have periodic recovery tests to ensure the right data is being captured
10
* Quoting from New Zealand CERT’s Top 11 Cyber Security tips
11
Symantec/Norton
(link to vulnerability disclosure)
Microsoft Windows Defender
(link to article on useful security enhancement)
12
Further reading on hardening strategies is available from the Australian Cyber Security Centre: Strategies to Mitigate Cyber Security Incidents
13
14
Adapted from “Linux Containers and Docker” by Keke Chen, Wright State University.
15
Adapted from “Linux Containers and Docker” by Keke Chen, Wright State University.
16
Adapted from “Linux Containers and Docker” by Keke Chen, Wright State University.
17
Adapted from “Linux Containers and Docker” by Keke Chen, Wright State University.
18
Linear algebra Networking
Adapted from “Linux Containers and Docker” by Keke Chen, Wright State University.
19
Adapted from “Linux Containers and Docker” by Keke Chen, Wright State University.