Pages

Friday, May 31, 2013

11 steps to make a PC Secure



So you have just bought a new personal computer for your home (rather than for a workplace or as a server) and want to secure it (including protecting it from viruses and spyware). Privacy (including encryption, cryptography and anonymity) is a part of security but broad enough to need covering separately. Think of Privacy as the flipside of the coin. Making backups of data, defragging, system restore points are only indirectly related. Backups can actually make your data easier to steal and retrieve.
This article assumes you wish to use a network (such as the internet), share files on thumbdrives and that your PC might be physically accessible to others. If none of those apply, then your many of these steps may be redundant as your PC will already be quite secure.


---------------------------------------
--------------number=1-------------
--------------------------------------- 

Choose an operating system based on its security and vulnerability (Linux has no known active viruses in the wild, OpenBSD is focused on security). Find out if it uses limited user accounts, file permissions and is regularly updated. Make sure you update your operating system with security updates and update your other software too.
---------------------------------------
--------------number=2-------------
---------------------------------------

Choose a web browser based on its security and vulnerabilities because most malware will come through via your web browser. Disable scripts too (NoScript, Privoxy and Proxomitron can do this). Look at what independent computer security analysts (such as US-CERT[1]) and crackers (similar to hackers) say. Google Chrome[2] is more secure and has a sandbox feature[3] so it would be more difficult to compromise the system and spread the infection.
---------------------------------------
--------------number=3-------------
---------------------------------------

When setting up, use strong passwords in your user account, router account etc. Hackers may use dictionary attacks and brute force attacks.
---------------------------------------
--------------number=4-------------
---------------------------------------

Use trusted sources. When downloading software (including antivirus software), get it from a trusted source (softpedia, download, snapfiles, tucows, fileplanet, betanews, sourceforge) or your repository if you are using Linux.
---------------------------------------
--------------number=5-------------
---------------------------------------

Install good antivirus software (particularly if you use P2P). Antivirus software is designed to deal with modern malware including viruses, trojans, keyloggers, rootkits, and worms. Find out if your antivirus offers real-time scanning, on-access or on-demand. Also find out if it is heuristic. Avast[4] and AVG[5] are very good free editions. Choose one, download and install it and scan regularly. Keep your virus definitions up to date by updating regularly.
---------------------------------------
--------------number=6-------------
---------------------------------------

Download and install software to deal with spyware such as Spybot Search and Destroy[6], HijackThis[7] or Ad-aware[8] and scan regularly. I can't state this enough - you need to run a good anti spyware and anti malware program like Spybot if you search the web at all. Many websites out there exploit weaknesses and holes in the security of Microsoft Explorer and will place malicious code on your computer without you knowing about it until its too late!
---------------------------------------
--------------number=7-------------
---------------------------------------

Download and install a firewall. Either ZoneAlarm[9] or Comodo Firewall[10] (Kerio, WinRoute or Linux comes with iptables). If you use a router, this gives an added layer of security by acting as a hardware firewall.
---------------------------------------
--------------number=8-------------
---------------------------------------

Close all ports. Hackers use port scanning (Ubuntu Linux has all ports closed by default).
---------------------------------------
--------------number=9-------------
---------------------------------------

Perform Penetration Testing. Start with ping, then run a simple nmap scan. Backtrack Linux[11] will also be useful.
---------------------------------------
-------------number=10-------------
---------------------------------------

Consider running intrusion detection software (HIDS) such as ossec, tripwire or rkhunter.
---------------------------------------
-------------number=11-------------
---------------------------------------

Don't forget to think in terms of physical security! Consider something like a Kensington lock (in case of theft/unauthorised access). Also setting a BIOS password and preventing access to your machine or its removable devices (USB, CD drive etc.). Don't use an external hard drive or USB device for important data, these represent another vulnerability, as they are easier to steal/lose.
Encryption can be effective against theft. Encrypt at least your entire user account rather than just a few files. It can affect performance but can prove worth it. Truecrypt works on Windows, OS X, Linux, FreeOTFE works on Windows and Linux. In OS X (10.3 or later) System Preferences Security, click FileVault (this can take minutes to hours). In Linux Ubuntu (9.04 or later) installation Step 5 of 6 choose "Require my password to login and decrypt my home folder". This uses ecryptfs.

No comments:

Post a Comment