Cyber Security Lab Assignment

profilejedt61z5
lab_2.docx

Lab #2

Student

Teacher

Class

Introduction

This document provides a brief step by step procedure for Windows 8.1 antimalware protection tools which will always secure your system from malware. The document will count three main antimalware tools namely Windows Defender, Windows Firewall and Microsoft Baseline Security Analyzer (MBSA).

All of the three tools come shipped in the Windows 8.1 operating system to help monitor the computer system by preventing malware from affecting the Windows operating system.

First I will discuss the configuration of Windows defender and write guidelines on how it monitors malware.

Windows Defender

Windows Defender came in with later version of Windows operating system from Windows 8.1 and sooner Windows operating system. It came to replace Microsoft security essentials which has been used in older version of Windows for malware protection as a standalone antivirus program than the later embedded windows defender which comes with windows 8.1 and new version of windows.

Launching windows defender

By using Windows key + S will help you type in the name of the Windows Defender. Once done in typing the name of the search, we can select Windows Defender and run the application program. Because the Windows Defender is not activated by default, we need to have a well working internet services to activate the application for its functionality. We can also opt for option two to make use of offline installer for Windows Defender which we can run without need of internet services. Once installed, we will always be needing internet connection to allow our Windows Defender to check and download the latest virus updates and spyware definitions always.

Updating Windows Defender

Keeping Windows Defender up to date will always make malware detection and protection very active. Expired Windows Defender definitions will make computer systems vulnerable to malwares. The expired anti malware definition allows new malwares to attack and multiply in your computer system leading program infection and malfunction. The viruses and Trojans become active and cannot be easily controlled. The following diagram illustrations how Windows Defender interface looks like and how to update the Windows Defender to keep it up to date.

For update, Windows Defender will always display a notification message to notify you that your Windows Defender virus and antispyware definitions are up to date and need to be updated as illustrated below.

The figure above is a good example of out of date Windows Defender which requires internet connection fixes so as it can update. By clicking the update button, we allow our Windows Defender to update and the program will check for updates from the internet. If it finds the up to date updates, it will set virus and spyware definitions up to date.

As we can see above, the colour of our frame and error picture symbol is yellow in colour, this means we are operating our PC at a very severe condition which can lead to harmful effects through investments of viruses and spywares.

On clicking update button, the following download progress bar will be seen in the frame shown below indicating that our Windows Defender is trying to search for any available up to date definitions. The figure below shows progress bar of Windows Defender searching for update definitions from online.

If no internet or in case of error in connectivity, the error message will be displayed as shown below.

The image above shows us that there was error in internet connection and that’s what made our Windows Defender not to update.

Else if our Windows Defender finds the internet connection, it downloads the updates, automatically installs the update and sets our pc protection status as protected and we are secure from threats and malware attack.

Figure bellows shows us an up to date Windows Defender.

As we can see above, our PC is fully protected.

Using Windows Defender to scan for malwares

Scanning for Windows against malwares is always recommended. Although Windows Defender can allow us to set for scheduled scans after a set interval of time, it is highly advisable to have continuous daily scan to mitigate our malwares which are inactive from affecting our systems. To perform a scan, we consider using the home tab found in Windows Defender interface as shown below.

Using the interface, we can be able to select which type of scan we want to perform. As shown above, we may opt to use quick scan which only performs shallow scan without getting deeper into system files but only scanning the default suspected directories and computer locations. Custom scan may be used to scan the system locations and directories which user may suspect are infected and not the whole system but only some parts.

Full scan option is used to scan the whole computer system. Scanning all memory locations, hard disks and registry of the computer system. It is always advisable to perform full scan to prevent any chance of having hidden malwares which might attack the PC later.

After scanning the PC, a history of malwares is always displayed indicating the malware type and its level of effects on PC. The levers are either weak, moderate or severe. Whereby a severe malware can destroy the computer files and interfere with it completely if they are not monitored or quarantined. By quarantine the viruses, their risk of effects is minimized. Windows Defender has scan settings which requires user to specify which actions to be done on the malwares. Either be quarantined or removed. But it is highly advised to remove the virus instead of quarantine to prevent future viral effects by those quarantined malwares. The figure below shows malware detected and their effect levels to the system.

The figure above shows worms and Trojan which the risk level is very severe and can damage the operating system applications.

Setting up Windows Defender

Windows Defender contains settings that allows the user to specify how he wants it to protect his system. The figure below shows all possible options available for settings.

i. Starting from setting number one, we find that we can set our Windows Defender to prevent your PC on real time. Meaning that any harmful software cannot get into our computer from any connection available. The Windows Defender will block the software from installing itself into our computer.

ii. Using Excluded files and locations allows us to exclude some files and locations from scans to speed up the scanning. But this setting makes our computer to be at risk because some harmful software may hide themselves in those locations we did exclude.

iii. This setting allows us to exclude files with certain extensions to speed up the rate of scanning although this makes our computer risky of some left in malwares.

iv. This setting allows us to exclude some processes from scan but the pc will be at risk as some malwares may have infected some the excluded processes.

v. The advanced setting allows us to set more critical settings that can help us secure our computers more securely. The setting includes allowing us be able to set scan for archives, removable disks, create restore points before removing or deleting quarantined items, allow users to view history reports, set quarantine and malware removal interval period and even send files automatically online to Microsoft Support when further operations are required.

Windows Firewall

As well known, the implementation of Windows Firewall is for filtering data packets that are sent and coming down stream in a computer system from internet or any network. It also controls which program to be allowed to communicate with internet or network connections so as no malware penetrates into the computer system.

It prevents attacks from either home, private or public network.

Turning on the Windows Firewall will give chances of malware entering into your system especially when you connect to unsecure networks or internet. The malware will be uploaded into your system computer and cause harmful effects by either acting as spyware, virus, Trojans or even worms which among all will affect your system files.

How it works

Windows Firewall must be turned on for it be fully operating and preventing your system from attacks. The firewall will always block all connections to applications which are not in the list of allowed applications.

In case of any new network connection or any time the PC is connected, the firewall will always notify you and block all possible risks and any new app.

By adding any application to the allowed list applications, you permit that application to communicate with other application from any connection.

Allowing applications and features to communicate through firewall

Any program can be allowed to communicate through firewall to the network connection programs. For instance, MySQL and Apache applications are always to communicate through firewall in case of server services. Only the allowed programs can communicate through the connections available or through connected networks.

To allow any application to communicate through firewall, the following steps are followed.

Launch Windows Firewall through typing Windows Firewall by using Windows key + S for search. Then click the link shown to allow any program communicate through firewall as shown below:

After clicking the highlighted text link, the below window will be displayed to allow you select the program to allow in communication and through which network type should the application communicate through. The network type can be private, guest or public network. Your choice of network will determine how your application communicates with the other applications via the connections.

Advanced settings in firewall for inbound and outbound rules

The inbound rules will always control which other computers are allowed to connect into your computer especially for server cases. For instance, adding MySQL server on port 3306 means that any computer which requires to connect to the server can use that port only. On the other hand, the outbound rules describe which applications are allowed to connect to networks and use internet connections for communication.

When rules are added, they can be disabled or be deleted on users need. Below is an example illustration of inbound rules and outbound rules respectively.

Example of adding new inbound rule

Step 1: click the new rule link shown below

Step 2: Select program

The rule that controls connection for a program as shown below:

Step 3: Click next

Browse to the program path that specifies the program file location and provide the program path.

Step 3: Click next

Select the “allow connection if it is secure” and click next.

Step 4: Select the network profile for which the rule will apply for.

Step 5: Click next and provide the name for your rule and some description about the rule and click finish to complete the rule creation. The figure below shows the naming and description.

Microsoft Baseline Security Analyzer

Introduction

The MBSA was mainly developed to be used in windows server. Its main work is to analyse the system for available updates to the operating environment and scans the computer for wrong configuration settings.

Scanning using MBSA

To scan using the MBSA, we need to provide the IP Address of the computer we want to scan. But for most cases, the scan is all to do with scanning for all possible vulnerabilities in the system. The figure below shows the first phase to start scanning.

The scanning involves scanning for all possible windows administrative vulnerabilities, weak passwords, IIS administrative vulnerabilities, SQL administrative vulnerabilities and the security updates.

While scanning, a progress bar will be shown as given below:

After a scan is complete the following deduction are made. I just scanned my computer only:

The figure below gives warning and the error message the MBSA encountered weak passwords and Guest accounts.

The results indicate that my 3 password usages are weak as used in Internet Explorer. Above that, my passwords are a non-expiring type.

Results of MBSA

The following gives a result of what was scanned in the Guest account.

The following indicates what was scanned in the local account:

The following figures shows possible solution to my weaknesses respectively.

Guest account solution

Local account solution