April 2006

Issue 32

[ Tell a Colleague ]  

 The Weakest Link: Social Engineering - "We've met the enemy, and it is us." (Pogo)

The Malware Evolution: A Change of Intent

How to stay safe in today's world

by Mary Landesman

The summer of 2003 marked a turning point in malicious code. It was a particularly prolific period that debuted the likes of Blaster, Welchi, Dumaru and Sobig.F. It also signaled the end of a threat landscape littered with traditional threats. Unlike previous evolutions, the change was not one of vector or type of threat but rather an evolution of intent.


 

 Editorial Corner

A Darwinian view of malware

Anyone whose job is to protect the network and battle the likes of Blaster and Sobig.F, has seen the changing environment of malware firsthand. Unfortunately, getting hit by more than one malware isn't unusual today. The feature story looks at how malware has evolved and the intent of the people behind it.

Large companies usually have the resources to hire on specialists in different areas of IT and security. Small businesses don't have that luxury. Instead, the IT department could be one person. This person has to keep computers working AND protect them — a tall order for even the most experienced professional. Readers offer suggestions on how to manage security from a generalist perspective.

While big organizations have the luxury of having specialists, they also face communication challenges, especially with multiple offices. As a result, people in headquarters might criss-cross their communications with employees in smaller offices. These debacles are not necessarily anyone's fault and can simply be an oversight from having overwhelming resources. If you've found a way to help all parts of an organization better communicate, we'd love to hear about it. Your response can be anonymous if you prefer.

We enter your name in a drawing for a 256 MP3 player every time you write to answer a reader's question, ask one or simply leave feedback. Let us know if you’re finding what you need. Two resources you might find valuable are the archives of past issues and the forums. Thanks for staying in touch.

Best,

Meryl K. Evans

To unsubscribe instantly or change your preferences, see links at the bottom
 

 Subscription

Privacy Policy
Enter your email address.


Add Remove
 

 Reader Survey

“The Academy” is a Web site supporting the security community with video-based instruction on how to install, configure and troubleshoot some of today's most popular security technologies. Visit the site at: www.theacademy.ca
 

 Spotlight

President and CEO Mark Shavlik's Computer
Security Blog


Kill Two Birds with One Stone: Shavlik NetChk Protect combines the functionality of Shavlik's patching and anti-spyware tools in a single console. Redmond Magazine


Shavlik Technologies Wins Two SC Magazine Readers Trust Awards:
Shavlik HFNetChk
Pro Named Best Vulnerability Assessment and Remediation Solution and Best Patch Management Solution


 

Partners

Shavlik drives patch management solutions for these companies:


 

 Resources

Shavlik Forums

PatchManagement.org

ISSA

SANS

Computer Security Institute
 

 Security Resources

Thinking Like a Hacker

Out-think them by knowing how they work from the inside out (PDF)

by Eric Schultze, Shavlik Technologies
 

 Sponsorship

Shavlik NetChk™ Protect is the first integrated solution that automates the management of critical security patches and spyware from one easy-to-use console. Shavlik Technologies offers the simplest way to secure complex enterprise networks.

NOW AVAILABLE! Shavlik NetChk Protect version 5.6 offers Active Protection, Enhanced Quarantine and Rollback, and Support for Layered Service Providers.

 to learn more.


 

 Announcement

ATTENTION MBSA 1.2.1 USERS!

Microsoft MBSA 1.2.1 will reach end of life soon.
Don't wait,
Shavlik Technologies has an upgrade for you!

From the creators of Microsoft MBSA, comes Shavlik NetChk™ Analyzer!”

Shavlik NetChk™ Analyzer, commandline patch management product, provides a seamless solution for companies that relied upon Microsoft MBSA 1.2.1 as part of their software update process.

Click here to learn more.


 

 What's Your Best Advice?

Last Issue's Security Dilemma:

Securing the small business with limited staffing

IT employees working for a small business almost always do everything, from Exchange Server and SQL queries to network and user management to phone security. What is the best way for a small staff to get everything done? How should you handle security from a generalist point of view?

— Wesley, Tech

Read the best advice from readers of The Remediator Digest
 


This Issue's Security Dilemma:

Earth to headquarters, I'm not hearing you …

How can a middle manager in a regional office convince managers and staff in national headquarters not to circumvent communications protocol? Headquarters tends to bypass the managers and communicate to subordinates. That means I miss out on crucial information. How do you best enforce your company's communications protocol?

— Jane, Regional Manager

Can You Help?

Share your experience.
You could win a 256 MB MP3 Player.

Congratulations to this month's winner of a 256 MB MP3 Player:
R. Spencer Van Pelt, CIO, Republic Mortgage, LLC


 

 The Pointy-Haired Boss

Know how to get what you need:

The Top 10 Information Security Myths

Believing in commonly held beliefs leads to potential disaster
by Joanne VanAuken - Bank Systems & Technology

 

Give RFID a Chance

Looking at the right benefits and problems with the technology
by Jim Flyzik - E-Commerce Times

 

 Stayin' The Alpha Dog

Take charge of your career:

Personal Branding 101 for IT Professionals

Get ahead in IT with skills and your personal brand
by Rajesh Setty - CIO Update

 

Key Steps to a Successful Security Career

It takes more than protocol knowledge
by Sharon Gaudin - Datamation

 

 In Your Down Time

For a well-deserved breather:

This is Your Robot Life

Look out Roomba, here comes Chibi-Robo
by Chris Kohler - Wired News

 

A Brief History of Handheld Video Games

From the LED-based handheld to PDA emulators
by Donald Melanson - Engadget

 

 Archives

Spring 2009
Issue 46
Issue 45
Issue 44
Issue 43

[MORE]
Shavlik Footer
about shavlik / careers / contact us / international     
     INFORMATION RISK MANAGEMENT     SECURITY PRODUCT     SUPPORT     PARTNERS     NEWS
Sponsored by Shavlik Technologies
Copyright © 2006 InternetVIZ, LLC. All rights reserved.
[ Tell a Colleague ]  
Powered by IMN