* Dare to Refuse Unwanted Malware
endif; ?>The threat of malware is getting scarier by the day. You know it’s bad when one of the leading security experts at Microsoft says there might be no other way to recover from a malware attack than to “nuke” the system and start over from scratch.
At a recent security event in Florida, Mike Danseglio, program manager in the Security Solutions group at Microsoft, told the audience, “When you are dealing with rootkits and some advanced spyware programs, the only solution is to rebuild from scratch. In some cases, there really is no way to recover without nuking the systems from orbit.”
In a frank discussion with security practitioners, Danseglio conceded that malware developers are getting smarter and using more sophisticated, often very targeted, methods. Calling the attacks “stealthy and effective,” he points to profit as the main motive for malware today.
Danseglio also calls “human stupidity” the weakest link in our defense against malware. He says we are very susceptible to the social engineering aspect of malware. That is, we often receive viruses and other problem programs from sources that we trust, such as coworkers and friends. In an extreme form of social engineering, the perpetrators even make it appear that the malware-laden message is coming from our own IT departments (and we all know that users NEVER ignore messages from IT).
Anti-virus software and other preventative measures are certainly important, but they are only one part of the one-two punch you need to keep your organization safe. The second part is user awareness. Are you doing enough to reduce the “human stupidity” aspect of malware transmission? Are you getting in your users’ faces about being smart about they way the use their computers, at home as well as at work?
My son just completed his school-sponsored DARE (Drug Abuse and Resistance Education) Program. This program hammers at the grade school kids week after week about the dangers of drug and alcohol abuse. Hopefully it gives them the knowledge to act responsibly as they go through life. I think that IT professionals need to mimic this program to make sure their users are “scared straight” about malware. Let’s start the DRUM Program: Dare to Refuse Unwanted Malware.
The intent of DRUM is to make users very aware of how they can pick up and transmit malware so that they are more cautious in their actions. No more casual cruising of dubious Web sites. No more opening e-mail attachments from unknown sources. No more online games at lunchtime. You know – all the things that users do without a thought about what might be happening in the background.
The first DRUM step is training. Every employee of an organization should be required to take some sort of training about the dangers of malware. This could be a Webinar, a lunch-and-learn, or a formal IT course. Attendance should be mandatory for everyone. Further, the article should be required reading for all.
The next phase of DRUM is ongoing awareness. I’ve walked through office buildings where there are posters on the walls reminding people about things like building security or workplace safety. What about malware awareness posters, where a Smokey the Bear-like figure says “Only YOU can prevent malware”? Computer splash screens can remind people daily upon login that they need to think about every action they take on the computer.
Company executives can get into the awareness campaign. A formal message from the CIO or even CEO can help people recognize the seriousness of the situation. If your company or IT department puts out an internal newsletter, there should be frequent reminders about the actions that could invite malware into the network. The more that people understand the relationship of their own actions to the potential consequences, the more likely you are to mold good habits.
And while the subject is serious, you can still have some fun with your prevention campaign. Print up some T-shirts or mouse pads to give to people as they complete their anti-malware training. Call them “DRUM Majors” if you like. The more the message stays in front of people, the more cautious they are likely to be.
Preventing malware requires a one-two punch – both a savvy IT department and an enlightened user base using technology smartly.




