Security Incidents mailing list archives

Re: Novarg


From: "Jonathan A. Zdziarski" <jonathan () nuclearelephant com>
Date: Wed, 28 Jan 2004 12:05:26 -0500


Anyone care to contribute their experience?

You can implement all the MTA policies and anti-virus software you want,
but ultimately if you have dumb employees, you will get burned at some
point.  The best defense to viruses like this is user education.  If you
haven't trained your users not to open unknown attachments by now, I
would take the time to revamp whatever training (if any) you provide
your users with.  Part of the new employee handbook should include a
basic tutorial on email security and other related areas such as what
types of passwords to avoid.  Being that you work for a large company, a
regular publication for all employees giving them small updates about
the latest end-user vulnerabilities and tips on improving security of
their laptop, etc., would be very useful.

Finally a means of detection is helpful in spearheading the really daft
ones who don't read what you give them or pay attention in training. 
Setting up detection on port 25 outgoing and other suspicious ports can
tell you who went and opened the attachment.

Jonathan



---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: