Top Banner
Keeping You And Your Library Safe and Secure Blake Carver – [email protected] http://lisnews.org/security/ http://security4lib.org/ http://lyrasis.org Intro
58

Keeping you and your library safe and secure

Aug 08, 2015

Download

Technology

LYRASIS
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Keeping you and your library safe and secure

Intro

Keeping You And Your Library Safe and Secure

Blake Carver – [email protected]://lisnews.org/security/

http://security4lib.org/http://lyrasis.org

Page 2: Keeping you and your library safe and secure
Page 3: Keeping you and your library safe and secure

“ Security is two different things: It's a feeling &It's a reality ”

Bruce Schneier – TedxPSU

Page 4: Keeping you and your library safe and secure

Security Frequently Gets In Our Way

Page 5: Keeping you and your library safe and secure

Have A Hacker MindsetThink Like A Bad Guy

Have A Security MindsetThink Defensively

Page 6: Keeping you and your library safe and secure

"None of this is about being "unhackable"; it’s about making

the difficulty of doing so not worth the effort."

Page 7: Keeping you and your library safe and secure

Secure, here, doesn't mean impenetrable

Competent and determined bad guys armed with the right tools can always find a way in

Less talented folks, and many automated tools, however, experience great effort as a deterrent

Page 8: Keeping you and your library safe and secure

Criminals

Activists

Government Agents

Page 9: Keeping you and your library safe and secure

Intro

Where Are They Working?

• Social Networks• Search Engines• Advertising• Email

• Web Sites• Web Servers• Home Computers• Mobile Devices

Page 10: Keeping you and your library safe and secure

Malware Inc.

These are the work of a rogue industry, not a roguish teenager

Page 11: Keeping you and your library safe and secure

Malware Inc.

Fully Automated24/7

Page 12: Keeping you and your library safe and secure

What Are They After?

• PINs• Passwords• Credit Cards• Bank Accounts• Social Media

• Computers• Usernames• Contact Lists• Emails• Phone Numbers

These all have value to someone

Page 13: Keeping you and your library safe and secure

Personal information is the currency of the underground

economy

Page 14: Keeping you and your library safe and secure

Personal information is the currency of the Entire Internet

economy

Page 15: Keeping you and your library safe and secure

We don’t know how our information is used,

stored or shared and for how long.

We don’t know who has access

We don’t know if it’s safe

Page 16: Keeping you and your library safe and secure

On the InterWebs, the companies entrusted to keep our personal

data safe are invariably the ones who have the most to gain from

not doing so.

Robert X. Cringely

Page 17: Keeping you and your library safe and secure

Nobody – nobody – is immune from getting hacked

Page 18: Keeping you and your library safe and secure

http://krebsonsecurity.com/2012/10/the-scrap-value-of-a-hacked-pc-revisited/?utm_source=feedburn

Page 19: Keeping you and your library safe and secure

How Do You Know If You Are Infected?

• Fans Spinning Wildly• Programs start

unexpectedly• Your firewall yells at you• Odd emails FROM you• Freezes• Your browser behaves

funny• Sudden slowness

• Change in behavior• Odd sounds or beeps • Random Popups• Unwelcome images • Disappearing files • Random error messages

Page 20: Keeping you and your library safe and secure

How Do You Know If You Are Infected?

You Don’t

Page 21: Keeping you and your library safe and secure

Your antivirus software is a seat belt – not a force field.

- Alfred Huger

Page 22: Keeping you and your library safe and secure

• Keep everything patched / updated

• Don’t Trust anything–Links / Downloads / Emails

• Backups are critical

Page 23: Keeping you and your library safe and secure

Laptops

• Prey / LoJack• Passwords• Sign Out & Do NOT Save Form Data

Page 24: Keeping you and your library safe and secure

Laptops

Carry A SafeNot A Suitcase

Page 25: Keeping you and your library safe and secure

Never Trust Public Wi-Fi

Page 26: Keeping you and your library safe and secure

Which of your accounts is most valuable?

• Email• Bank• Social Network• Shopping• Gaming• Blogs• Library Account

Page 27: Keeping you and your library safe and secure

Own the Email, Own the Person

Page 28: Keeping you and your library safe and secure

Email

• Don’t trust anything• Don’t leave yourself logged in• 2 Factor Authentication• Passwords

– Unique, Obscure and Looooonnnnnggggg

Page 29: Keeping you and your library safe and secure

Web Browser

The Single Most Important [Online] Security Decision You Make

Page 30: Keeping you and your library safe and secure

Staying Safe Online

Browsers

• Use Two & Keep Updated• Know Your Settings

– Phishing & Malware Detection - Turned ON– Software Security & Auto / Silent Patching -

Turned ON• A Few Security Plugins:

– Something to Limit JavaScript – Something to Force HTTPS– Something to Block Ads

Page 31: Keeping you and your library safe and secure

But The Internet Is Free Because Of Ads...

• Online ads were 182 times more likely to deliver malware than “adult” sites

• Google blocked 524 million 'bad ads' 250,000

• Up 50 percent in 1 year

Page 32: Keeping you and your library safe and secure

Let’s Talk Libraries

Page 33: Keeping you and your library safe and secure

But We’re Just A Library

Page 34: Keeping you and your library safe and secure

83% targets of opportunity

92% of attacks were easy

85% were found by a 3rd party

Verizon Data Breach Investigations Report – Fall 2011

Page 35: Keeping you and your library safe and secure

It’s Easy Being Bad

Page 36: Keeping you and your library safe and secure

Being Good IsHard

Never EndingOverwhelming

Exhausting

Page 37: Keeping you and your library safe and secure

The attacker only needs to succeed once...

Page 38: Keeping you and your library safe and secure

Perfect is not the enemy of good ‘nuff

Page 39: Keeping you and your library safe and secure

Complexity is the Enemy of Security(Bruce Schneier)

• Libraries have no shortage of access points

• We deal with any number of vendors

• Threats come from outside the libraries

• Threats come from inside the libraries

• Our libraries are full of people

Page 40: Keeping you and your library safe and secure

Staying safe takes more than just a firewall...

Page 41: Keeping you and your library safe and secure

Your firewall is a seat belt – not a force field.

Page 42: Keeping you and your library safe and secure

Library Security Requires Layers

• Firewall• VPN• Intrusion Monitoring• Antimalware & Antispam & Antivirus• Planning & Training

Page 43: Keeping you and your library safe and secure

How Can We Make Our Library Secure

• Don’t ignore it

• Prepare

• Train

Page 44: Keeping you and your library safe and secure

Preparation- Practical Policies

• Patching and updates of the OS and applications on a regular basis

• Regular automated checks of public PCs & network

• Check the internets for usernames/passwords for your library (e.g. pastebin)

• Dedicated staff? Someone needs to stay current• Lost USB Drives?• Is your domain name going to expire?

Page 45: Keeping you and your library safe and secure

Training

• Phishing• Privacy• Passwords• Email Attachments• Virus Alerts• How to practice safe social networking• Keeping things updated

Page 46: Keeping you and your library safe and secure

Public Access PCs

Your security software is a seat belt – not a force field.

Page 47: Keeping you and your library safe and secure

Assume the bad thing has happened

Page 48: Keeping you and your library safe and secure

Change your mindset – YOU are the attacker

• What are you library’s most valuable assets?– Where are these assets? – How can they be accessed?

• If you were the attacker how would you spread malware?

• Who are the most ‘vulnerable’ targets in the organization?

Page 49: Keeping you and your library safe and secure

Go on the offensive…

"think evil, do good"

Page 50: Keeping you and your library safe and secure

Turn Your Focus Outside

Page 51: Keeping you and your library safe and secure

Library Security Mantra

• Security• Privacy• Confidentiality• Integrity• Availability• Access

(based on Net Sec 101 Ayre and Lawthers 2001)

Page 52: Keeping you and your library safe and secure

What websites can you trust?

Page 53: Keeping you and your library safe and secure

Can you trust your own website?

Page 54: Keeping you and your library safe and secure

Any Good Web Site Can Go BadAt Any Time

Less that half of website traffic is human

About 30% of all traffic is actively tying to cause trouble

Page 55: Keeping you and your library safe and secure

“ Security is two different things: It's a feeling &It's a reality ”

Bruce Schneier – TedxPSU

Page 56: Keeping you and your library safe and secure

• Keep everything patched & updated always

• Carry A Safe• Don’t Trust anything or anyone

–Links / Downloads / Emails Patrons / Vendors

• Backup your stuff• Prepare And Train

Page 57: Keeping you and your library safe and secure

This IS worth the time, effort and expense.

Page 58: Keeping you and your library safe and secure

Done!!

Stay Safe

Blake Carver – [email protected]://lisnews.org/security/

http://security4lib.org/http://lyrasis.org