Guarding a network from malicious code

Guarding a network from malicious code

What are the best strategies and tactics for protecting against the onslaught of malware/Trojan horses on my company's network?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

You need to deploy defenses at two different levels: the server level and the desktop level.

At the server level, widely deploy antivirus tools on your servers and keep them up to date. You need to implement virus scanners on your mail and file servers, at least. Scan all incoming e-mail, as well as internal mail and any shared files for malicious code.

At the desktop level, there are four elements to protecting your systems. First, deploy automatically updating antivirus tools at the desktop and laptop, and make sure your policies prohibit disabling such tools. Increase your awareness program's emphasis on this point. Secondly, deploy a personal firewall on each desktop, such as ZoneAlarm, BlackICE, or Symantec's Personal Firewall. Thirdly, keep your systems patched. Tell employees to periodically visit www.windowsupdate.com or push them updates via a patch management system. You can use Microsoft's own SUS or a third-party tool for such management. And, finally, make sure you keep your browser security settings to at least "medium." If you rely on Internet Explorer, you can use Microsoft's Internet Explorer Administration Kit (IEAK) for enterprise-wide management of IE's security settings. If you've got Active Directory, you can even do this management via group policy.


For more info on this topic, please visit these SearchSecurity.com resources:
  • Best Web Links: Patch management
  • Infosec Bookshelf: Malware: Fighting Malicious Code, Chapter 6 -- Trojan Horses
  • Security Tip: Virus protection -- Prevention, detection, response

    This was first published in January 2004