Presentation is loading. Please wait.

Presentation is loading. Please wait.

A virus is software that spreads from program to program, or from disk to disk, and uses each infected program or disk to make copies of itself. Basically.

Similar presentations


Presentation on theme: "A virus is software that spreads from program to program, or from disk to disk, and uses each infected program or disk to make copies of itself. Basically."— Presentation transcript:

1 A virus is software that spreads from program to program, or from disk to disk, and uses each infected program or disk to make copies of itself. Basically computer sabotage. What is a Virus?

2 How does a Virus Spread? First a programmer writes the virus most often being attached to a normal program; unknown to the user, the virus spreads to other software. Then the virus is passed by disk or network to other users who use other computers. The virus then remains dormant as it is passed on.

3 The types of Viruses Viruses are usually categorized as : –the boot virus which infects the boot sector of disk storage –the program virus which infects the executable programs –the multipartite virus which is a combination of the boot and program virus –the stealth virus which is able to avoid detection by a variety of means such as removing itself from the system registry, or masquerading as a system file

4 The types of Viruses Cont.. –the parasitic virus which embeds itself into another file or program such that the original file is still viable –the polymorphic virus which changes its code structure to avoid detection and removal –the macro virus which exploits the macro language of a program like Microsoft Word or Excel.

5 What is AntiVirus Software? Computer programs intended to identify and eliminate computer viruses. Antivirus software is considered to be an aid that detects, fixes and even prevents viruses and worms from spreading to your computer as well as connecting computers.

6 Why is software an issue? some antivirus software can considerably reduce performance there should not be more than one antivirus software installed on a single computer at any given time it’s sometimes necessary to temporarily disable virus protection when installing major updates

7 Types of AntiVirus there are different types of antivirus software for different computers some are designed for personal computers some are for servers and others for enterprises there are mainly two types of antivirus software: specific and generic

8 Specific Scanning specific scanning or signature detection the application scans files to look for known viruses matching definitions in a “virus dictionary” when the antivirus looks at a file it refers to a dictionary of known viruses and matches a piece of code (specific patterns of bytes) from the new file to the dictionary.

9 Specific scanning cont.. after recognizing the malicious software the antivirus software can take one of the following actions: (1): attempt to repair the file by removing the virus itself from the file (2): quarantine the file (3): or delete the file completely

10 Specific Scanning cont… however, specific scanning is not always reliable because virus authors are creating new ways of disguising their viruses so the antivirus software does not match the virus’ signature to the virus dictionary.

11 Generic Scanning generic scanning is also referred to as the suspicious behavior approach. generic Scanning is used when new viruses appear. in this method the software does not look for a specific signature but instead monitors the behavior of all applications.

12 Generic Scanning cont… if anything questionable is found by the software the application is quarantined and a warning is broadcasted to the user about what the program may be trying to do. if the software is found to be a virus the user can send it to a virus vendor.

13 About OfficeScan Trend Micro OfficeScan protects enterprise networks from malware, network viruses, web- based threats, spyware, and mixed threat attacks. An integrated solution, OfficeScan consists of the OfficeScan client program that resides at the endpoint and a server program that manages all clients. The OfficeScan client guards the computer and reports its security status to the server. The server, through the web-based management console, makes it easy to set coordinated security policies and deploy updates to every client.

14 Trend Micro OfficeScan For 64 bits machine - https://10.181.0.10/officescan64.exehttps://10.181.0.10/officescan64.exe For 32 bits machine - https://10.181.0.10/officescan.exehttps://10.181.0.10/officescan.exe

15 What is a Firewall? A choke point of control and monitoring Interconnects networks with differing trust Imposes restrictions on network services – only authorized traffic is allowed Auditing and controlling access – can implement alarms for abnormal behavior Itself immune to penetration Provides perimeter defence

16 Firewalls in Our Network Juniper SRX650 – For LAN Checkpoint 4800 – For Data Centre

17 NETWORK LAYOUT

18 Intrusion prevention systems Intrusion prevention systems are network security devices that monitor network and/or system activities for malicious activity (intrusion) Main functions of Intrusion Prevention System (IPS) are, – Identify intrusion – Log information about intrusion – Attempt to block/stop intrusion and – Report intrusion Intrusion Detection System (IDS) only detect intrusions

19 THANK YOU By : Mengu Kuotsu Security Administrator


Download ppt "A virus is software that spreads from program to program, or from disk to disk, and uses each infected program or disk to make copies of itself. Basically."

Similar presentations


Ads by Google