SlideShare une entreprise Scribd logo
1  sur  22
Operating System
Security
O Rachel Jeewa
O www.twitter.com/RachelJeewa

1
In Old Days

2
Objective
O Nowadays,

as systems grow powerful , attacks on
system grow more sophisticated.

O Therefore, it is important that the system

users secure the computer from threats.

3
Threats to System Security
O Virus

A virus is a program that replicates by
copying itself to other programs, system
boot sectors or documents or applications.
Some viruses can damage to your files by
deleting or corrupting them. Some may
display rude or strange message on the
screen. Some can allow other people to
access and control your computer.
4
Trojan
O A Trojan is a

program that seems
to legitimate but
acts maliciously
when executed. It
can open direct
entry point for
attacker so attacker
may use system’s
resources such as
hard disk spce.

Spyware
O Spyware includes

Trojans and other
malicious software
that steals personal
information from a
system without
user’s knowledge.

6
Log-in Password Cracking
1.Guessing
Password Guessing is trying different
passwords until one works.
2.Shoulder Surfing
Shoulder Surfing involves watching while
someone types the password.

7
Log-in Password Cracking
3. Social Engineering
Social Engineering is tricking people to reveal
their passwords or other information that can be
used to guess a password.
4.Dictionary Attack
Dictionary attack uses a pre-defined list of
words to recover the password. This is likely to
succeed when the password is short. Several
password cracking programs are available on
the internet.

8
Guidelines for Windows OS
Security
1.Lock the system when not in use
It helps to secure the workstation from an
unauthorized user.
Method_ Selects the Window and L buttons
together on the keyboard to lock the system.
2.Create strong user password
A weak password does not offer an effective
protection .Always use strong password e.g
tEst@5#8*
Method_ Control Panel
User Accounts

9
Guidelines for Windows OS
Security
3.Disable the guest account
Unwanted guest accounts can be exploited
by attackers to gain entry in to the system.
Method_ Click the Start button, right-click
Computer from shortcut menu, and choose
Manage. Go to Local Users and Groups
Users. Double-click on Guest icon. In the
Guest Properties window, check the box
next to Account is disabled and click OK .
10
Guidelines for Windows OS
Security
4.Lock out unwanted guests
Lock out unwanted guests by configuring
the setting of the account lockout policy to
limit the number of login attempts .
Method_ click on Start button, Control
Panel,
And click Administrative Tools. Double
click the Local Security Policy, click
Account Policies, double-click the
Account Lockout Policy, and double click
Account Lockout Threshold. A the prompt,
enter the number of invalid login (e.g 3).
Click OK.

11
Window Update in Window7
For Window OS, enable automatic updates
to ensure that the OS is patched and up-todate.
Method_ click Start , Control Panel and
select System and Security. Select
Windows Update
Change Settings.
Choose how Windows should updates and
click OK.
12
Pointers for Updates
O Always patch the OS and applications to
O
O
O
O

the latest patch levels.
Ensure that patches are downloaded only
from vendor site.
Use patch management tools for easier
updating . Several free tools are available.
Do not send patches through email.
Choose to be notified by the vendor about
vulnerability announcements.
13
Window Firewall
O A firewall is software that guards the

system from unwarranted traffic when
connected to a network. Hackers can try
to take advantage of programs running on
the system and try to execute malicious
code. Hacking tools such as Trojan can
send information from the victim’s
computer to the attacker’s computer. A
firewall can detect this attack and block
certain traffic .
14
Configuring Window Firewall
O Steps to configure window firewall include:

Method_ Start
Control Panel
In the search box, type firewall and click
Windows Firewall.
In the left pane, click Turn Windows
Firewall On or Off.
Check the circles Turn On Windows
Firewall.
Click OK.
15
Using NTFS
O The NTFS file system provides better

performance and security for data on hard
disks and partitions than FAT file system.
You can convert earlier FAT or FAT32 file
system to NTFS by using the covert
command.

16
Using NTFS
O Click Start and type cmd , right click

Command Prompt and then click Run as
Administrator.
O In the Command Prompt, type covert
drive_letter: /fs:ntfs , where drive_letter is
the letter of the drive to be converted to
NTFS. Then press Enter.
O Type the name of the volume you want to
convert and press enter.When the conversion
complete restart the computer.
O Note-Converting to NTFS does not affect the
data.

17
Windows EFS
O Windows encryption file system(EFS) allows

window7 user to encrypt files and folders. But
encryption does not allow encryption on
compressed or zipped files and system files.
O Method_ right click on a file or folder to encrypt,
select Properties on the General tab, and click
the Advanced botton. Select Encrypt contents
to secure data. Click OK to close the dialog box
and click Apply
O The encryption dialog box appears. Check either
18
of the two options and click OK.
Decrypt A File Using EFS
O To decrypt a encrypted folder or file-

Right click on the folder or file to decrypt
and select Properties. On the General tab,
click the Advanced button. The Advanced
Attributes box will appears.
Uncheck Encrypt contents to secure data,
click OK to close the dialog box, apply the
settings and click OK.
19
BitLocker
O BitLocker drive encryption allows the

entire volume of the system to be
secured. Encrypted removable media can
be decrypted and re-encrypted again.
O Method_ click Start and click Computer.

Right click on the drive and select the
option Turn On BitLocker…
20
Windows Security Tools
1.Microsoft Security Essentials
http://www.microsoft.com
2.Keepass Password Safe Portable
http://www.portableapps.com
3.Registry Mechanic
http://www.pctools.com
21
Thank You!

22

Contenu connexe

Tendances

Network security
Network securityNetwork security
Network securityfatimasaham
 
Network security - Defense in Depth
Network security - Defense in DepthNetwork security - Defense in Depth
Network security - Defense in DepthDilum Bandara
 
COMPUTER SECURITY AND OPERATING SYSTEM
COMPUTER SECURITY AND OPERATING SYSTEMCOMPUTER SECURITY AND OPERATING SYSTEM
COMPUTER SECURITY AND OPERATING SYSTEMfaraz hussain
 
Network Security Presentation
Network Security PresentationNetwork Security Presentation
Network Security PresentationAllan Pratt MBA
 
Computer security
Computer securityComputer security
Computer securityfiza1975
 
Introduction to Network Security
Introduction to Network SecurityIntroduction to Network Security
Introduction to Network SecurityJohn Ely Masculino
 
Windows Security in Operating System
Windows Security in Operating SystemWindows Security in Operating System
Windows Security in Operating SystemMeghaj Mallick
 
chapter 1. Introduction to Information Security
chapter 1. Introduction to Information Security chapter 1. Introduction to Information Security
chapter 1. Introduction to Information Security elmuhammadmuhammad
 
Network management and security
Network management and securityNetwork management and security
Network management and securityAnkit Bhandari
 
Network Security Fundamentals
Network Security FundamentalsNetwork Security Fundamentals
Network Security FundamentalsRahmat Suhatman
 
Chapter 3 Presentation
Chapter 3 PresentationChapter 3 Presentation
Chapter 3 PresentationAmy McMullin
 
How Computer Viruses Work
How Computer Viruses WorkHow Computer Viruses Work
How Computer Viruses WorkCerise Anderson
 
Web application attacks
Web application attacksWeb application attacks
Web application attackshruth
 
Network forensics and investigating logs
Network forensics and investigating logsNetwork forensics and investigating logs
Network forensics and investigating logsanilinvns
 

Tendances (20)

Chapter 4
Chapter 4Chapter 4
Chapter 4
 
Computer security
Computer securityComputer security
Computer security
 
Computer security
Computer securityComputer security
Computer security
 
Network security
Network securityNetwork security
Network security
 
Computer Security
Computer SecurityComputer Security
Computer Security
 
Network security - Defense in Depth
Network security - Defense in DepthNetwork security - Defense in Depth
Network security - Defense in Depth
 
COMPUTER SECURITY AND OPERATING SYSTEM
COMPUTER SECURITY AND OPERATING SYSTEMCOMPUTER SECURITY AND OPERATING SYSTEM
COMPUTER SECURITY AND OPERATING SYSTEM
 
Network Security Presentation
Network Security PresentationNetwork Security Presentation
Network Security Presentation
 
Computer security
Computer securityComputer security
Computer security
 
Introduction to Network Security
Introduction to Network SecurityIntroduction to Network Security
Introduction to Network Security
 
Windows Security in Operating System
Windows Security in Operating SystemWindows Security in Operating System
Windows Security in Operating System
 
chapter 1. Introduction to Information Security
chapter 1. Introduction to Information Security chapter 1. Introduction to Information Security
chapter 1. Introduction to Information Security
 
Network management and security
Network management and securityNetwork management and security
Network management and security
 
Network Security Fundamentals
Network Security FundamentalsNetwork Security Fundamentals
Network Security Fundamentals
 
Chapter 3 Presentation
Chapter 3 PresentationChapter 3 Presentation
Chapter 3 Presentation
 
How Computer Viruses Work
How Computer Viruses WorkHow Computer Viruses Work
How Computer Viruses Work
 
Computer Security
Computer SecurityComputer Security
Computer Security
 
Web application attacks
Web application attacksWeb application attacks
Web application attacks
 
Lesson 3- Remote Access
Lesson 3- Remote AccessLesson 3- Remote Access
Lesson 3- Remote Access
 
Network forensics and investigating logs
Network forensics and investigating logsNetwork forensics and investigating logs
Network forensics and investigating logs
 

Similaire à Operating system security

18IF004_CNS.docx
18IF004_CNS.docx18IF004_CNS.docx
18IF004_CNS.docxRajAmbere1
 
Operating systems 2
Operating systems 2Operating systems 2
Operating systems 2mariacalji
 
so big 22
so big 22so big 22
so big 22cainem
 
so big ppt
so big pptso big ppt
so big pptcainem
 
so big
so bigso big
so bigcainem
 
Desktop and server securityse
Desktop and server securityseDesktop and server securityse
Desktop and server securityseAppin Ara
 
Fixed: Slow Startup on Windows 10 HP Laptop
Fixed: Slow Startup on Windows 10 HP LaptopFixed: Slow Startup on Windows 10 HP Laptop
Fixed: Slow Startup on Windows 10 HP LaptopDash Milly
 
How to Troubleshoot QuickBooks Error 1303?
How to Troubleshoot QuickBooks Error 1303?How to Troubleshoot QuickBooks Error 1303?
How to Troubleshoot QuickBooks Error 1303?nickmosan
 
Checking Windows for signs of compromise
Checking Windows for signs of compromiseChecking Windows for signs of compromise
Checking Windows for signs of compromiseCal Bryant
 
Operating systems
Operating systemsOperating systems
Operating systemssandrahezro
 
Remove Clickhoofind.com
 Remove Clickhoofind.com Remove Clickhoofind.com
Remove Clickhoofind.comkingh05
 
Cscu module 02 securing operating systems
Cscu module 02 securing operating systemsCscu module 02 securing operating systems
Cscu module 02 securing operating systemsSejahtera Affif
 
Optimize your computer for peak performance
Optimize your computer for peak performanceOptimize your computer for peak performance
Optimize your computer for peak performancepacampbell
 

Similaire à Operating system security (20)

18IF004_CNS.docx
18IF004_CNS.docx18IF004_CNS.docx
18IF004_CNS.docx
 
Operating systems 2
Operating systems 2Operating systems 2
Operating systems 2
 
Windows 0.1
Windows 0.1Windows 0.1
Windows 0.1
 
so big 22
so big 22so big 22
so big 22
 
so big ppt
so big pptso big ppt
so big ppt
 
so big
so bigso big
so big
 
Total Security MAC User Guide
Total Security MAC User GuideTotal Security MAC User Guide
Total Security MAC User Guide
 
LESSON 2.pptx
LESSON 2.pptxLESSON 2.pptx
LESSON 2.pptx
 
Desktop and Server Security
Desktop and Server SecurityDesktop and Server Security
Desktop and Server Security
 
Desktop and server securityse
Desktop and server securityseDesktop and server securityse
Desktop and server securityse
 
Fixed: Slow Startup on Windows 10 HP Laptop
Fixed: Slow Startup on Windows 10 HP LaptopFixed: Slow Startup on Windows 10 HP Laptop
Fixed: Slow Startup on Windows 10 HP Laptop
 
How to Troubleshoot QuickBooks Error 1303?
How to Troubleshoot QuickBooks Error 1303?How to Troubleshoot QuickBooks Error 1303?
How to Troubleshoot QuickBooks Error 1303?
 
Checking Windows for signs of compromise
Checking Windows for signs of compromiseChecking Windows for signs of compromise
Checking Windows for signs of compromise
 
Operating systems
Operating systemsOperating systems
Operating systems
 
Remove Clickhoofind.com
 Remove Clickhoofind.com Remove Clickhoofind.com
Remove Clickhoofind.com
 
Windows Security
Windows Security Windows Security
Windows Security
 
Security
SecuritySecurity
Security
 
Cscu module 02 securing operating systems
Cscu module 02 securing operating systemsCscu module 02 securing operating systems
Cscu module 02 securing operating systems
 
Optimize your computer for peak performance
Optimize your computer for peak performanceOptimize your computer for peak performance
Optimize your computer for peak performance
 
Ransomware
RansomwareRansomware
Ransomware
 

Dernier

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Zilliz
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityWSO2
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard37
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)Samir Dash
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...apidays
 

Dernier (20)

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptx
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 

Operating system security

  • 1. Operating System Security O Rachel Jeewa O www.twitter.com/RachelJeewa 1
  • 3. Objective O Nowadays, as systems grow powerful , attacks on system grow more sophisticated. O Therefore, it is important that the system users secure the computer from threats. 3
  • 4. Threats to System Security O Virus A virus is a program that replicates by copying itself to other programs, system boot sectors or documents or applications. Some viruses can damage to your files by deleting or corrupting them. Some may display rude or strange message on the screen. Some can allow other people to access and control your computer. 4
  • 5.
  • 6. Trojan O A Trojan is a program that seems to legitimate but acts maliciously when executed. It can open direct entry point for attacker so attacker may use system’s resources such as hard disk spce. Spyware O Spyware includes Trojans and other malicious software that steals personal information from a system without user’s knowledge. 6
  • 7. Log-in Password Cracking 1.Guessing Password Guessing is trying different passwords until one works. 2.Shoulder Surfing Shoulder Surfing involves watching while someone types the password. 7
  • 8. Log-in Password Cracking 3. Social Engineering Social Engineering is tricking people to reveal their passwords or other information that can be used to guess a password. 4.Dictionary Attack Dictionary attack uses a pre-defined list of words to recover the password. This is likely to succeed when the password is short. Several password cracking programs are available on the internet. 8
  • 9. Guidelines for Windows OS Security 1.Lock the system when not in use It helps to secure the workstation from an unauthorized user. Method_ Selects the Window and L buttons together on the keyboard to lock the system. 2.Create strong user password A weak password does not offer an effective protection .Always use strong password e.g tEst@5#8* Method_ Control Panel User Accounts 9
  • 10. Guidelines for Windows OS Security 3.Disable the guest account Unwanted guest accounts can be exploited by attackers to gain entry in to the system. Method_ Click the Start button, right-click Computer from shortcut menu, and choose Manage. Go to Local Users and Groups Users. Double-click on Guest icon. In the Guest Properties window, check the box next to Account is disabled and click OK . 10
  • 11. Guidelines for Windows OS Security 4.Lock out unwanted guests Lock out unwanted guests by configuring the setting of the account lockout policy to limit the number of login attempts . Method_ click on Start button, Control Panel, And click Administrative Tools. Double click the Local Security Policy, click Account Policies, double-click the Account Lockout Policy, and double click Account Lockout Threshold. A the prompt, enter the number of invalid login (e.g 3). Click OK. 11
  • 12. Window Update in Window7 For Window OS, enable automatic updates to ensure that the OS is patched and up-todate. Method_ click Start , Control Panel and select System and Security. Select Windows Update Change Settings. Choose how Windows should updates and click OK. 12
  • 13. Pointers for Updates O Always patch the OS and applications to O O O O the latest patch levels. Ensure that patches are downloaded only from vendor site. Use patch management tools for easier updating . Several free tools are available. Do not send patches through email. Choose to be notified by the vendor about vulnerability announcements. 13
  • 14. Window Firewall O A firewall is software that guards the system from unwarranted traffic when connected to a network. Hackers can try to take advantage of programs running on the system and try to execute malicious code. Hacking tools such as Trojan can send information from the victim’s computer to the attacker’s computer. A firewall can detect this attack and block certain traffic . 14
  • 15. Configuring Window Firewall O Steps to configure window firewall include: Method_ Start Control Panel In the search box, type firewall and click Windows Firewall. In the left pane, click Turn Windows Firewall On or Off. Check the circles Turn On Windows Firewall. Click OK. 15
  • 16. Using NTFS O The NTFS file system provides better performance and security for data on hard disks and partitions than FAT file system. You can convert earlier FAT or FAT32 file system to NTFS by using the covert command. 16
  • 17. Using NTFS O Click Start and type cmd , right click Command Prompt and then click Run as Administrator. O In the Command Prompt, type covert drive_letter: /fs:ntfs , where drive_letter is the letter of the drive to be converted to NTFS. Then press Enter. O Type the name of the volume you want to convert and press enter.When the conversion complete restart the computer. O Note-Converting to NTFS does not affect the data. 17
  • 18. Windows EFS O Windows encryption file system(EFS) allows window7 user to encrypt files and folders. But encryption does not allow encryption on compressed or zipped files and system files. O Method_ right click on a file or folder to encrypt, select Properties on the General tab, and click the Advanced botton. Select Encrypt contents to secure data. Click OK to close the dialog box and click Apply O The encryption dialog box appears. Check either 18 of the two options and click OK.
  • 19. Decrypt A File Using EFS O To decrypt a encrypted folder or file- Right click on the folder or file to decrypt and select Properties. On the General tab, click the Advanced button. The Advanced Attributes box will appears. Uncheck Encrypt contents to secure data, click OK to close the dialog box, apply the settings and click OK. 19
  • 20. BitLocker O BitLocker drive encryption allows the entire volume of the system to be secured. Encrypted removable media can be decrypted and re-encrypted again. O Method_ click Start and click Computer. Right click on the drive and select the option Turn On BitLocker… 20
  • 21. Windows Security Tools 1.Microsoft Security Essentials http://www.microsoft.com 2.Keepass Password Safe Portable http://www.portableapps.com 3.Registry Mechanic http://www.pctools.com 21