Search This Blog

Tuesday, June 21, 2011

Security Concepts in Windows Vista Hardening

Overview:
Windows Vista introduces a user familiarity and is designed to help you feel confident in your ability to view, find, and organize information and to control your computing practice.  Windows Vista has been one of the most secure  version of Windows yet. The new features in Windows Vista help to give you the control and confidence you need to get the most out of your PC. This document in brief discuss some of the security options and these great new features provide  you  by focusing on:
User Account Control:Enabling users to run with Standard User rights.
Parental Controls: Monitoring and managing your children computer privileges.
Bit Locker Drive Encryption: A new data protection feature .
In addition to the feature overviews, we’ll offer some ways you can increase your system security to get even greater protection. Using the information in this document you should be able to configure and manage all of these great security features on your new Windows Vista machine.

1.Turn on Windows Automatic Updating:

Security updates can protect your computer against new and ongoing threats. Follow these steps to  install important updates automatically:
Select Start -->  All Programs --> Windows Update.
In the left pane, click Change settings
 winvista1.jpg
In the Change settings window, select the following options:
  • Install updates automatically (recommended).
  • Install new updates: Everyday.
  • At: choose a time when your machine will be turned on.
  • Recommended updates: select (check) Include recommended updates when downloading, installing, or notifying me about updates.
  • Update service: select Use Microsoft Update.
  • Click OK to save changes.

1.Ensure Windows Firewall is Turned On:

A firewall can help avoid malicious attackers from gaining access to your computer through a network or  Internet. By default, Windows (Vista) Firewall is turned on. When the firewall is on,most programs are blocked from communicating through the firewall. If you want to unblock a program, add it to the list of exceptions. 
Follow these steps to configure Windows Firewall and ensure it is turned on:
  • Select Start --> Control Panel.
  • In the left panel, click Classic View.
  • In the Control Panel window, double-click Windows Firewall.
  • In the Windows Firewall window, ensure Windows Firewall is on. If the firewall is off or you want to unblock a program, click Change settings.
  • If the User Account Control window appears, click Continue.
  • In the Firewall Settings window, select the General tab.
  • Select On.
  • If you are making no further changes, click OK.
To allow a program to communicate through the firewall, continue with the steps below:
  •    Select the Exceptions tab.
  •    Do the following:
   o Uncheck any program or service you DO NOT wish to accept
      incoming network connections.
   o Check any program or service you DO wish to accept incoming
      connections.
   o Check Notify me when Windows Firewall blocks a new program.
  •   Click OK to save your changes.

2.Ensure File Sharing is Off:

File sharing allows users to share folders and may allow malicious attackers to read or write files from your shared folders. By default, file sharing is turned off. If you  decide to share a folder, make sure password protected sharing is turned on.
To ensure file sharing is turned off, follow these steps:
  •  Select Start --> Control Panel.
  • In the left panel, click Classic View.
  • In the Control Panel window, double-click Network and Sharing Center.
  • Under Sharing and Discovery ensure File sharing is Off.
  • To turn file sharing off or on, click the File sharing arrow button.
To enable password protected sharing, click the Password protected sharing arrow button and click Turn on password protected sharing.

3.Secure Your Accounts:

To prevent someone from gaining access to your computer, physically or through the network, each user account must have a strong password. Accounts with weak passwords are an invitation for cyber attackers to enter into your system.
 Set Passwords for User Accounts
  •   Select Start --> Control Panel.
  •   In the left panel, click Classic View.
  •   In the Control Panel window, double-click User Accounts.
  •   In the User Accounts window, click Manage another account.       
  •   If the User Account Control window appears, click Continue.
  •   A password protected account will have Password protected listed under account type.Add a password to accounts that need one by double-clicking the account.
  •  Select Create a password.
  •  In the Create Password window:
  •   In the New password field enter a password.
  •   Retype the password in the Confirm new password field.
  •  Click Create password to save your changes.
  • Delete Unused Accounts
 To delete unused accounts, follow these steps:
  • Select Start --> Control Panel.
  • In the left panel, click Classic View.
  • In the Control Panel window, double-click User Accounts.
  • In the User Accounts window, click Manage another account.
  • Double-click the account you want to remove and choose Delete the account.
Create a Strong Administrator Password
To verify that a strong password is set for the Administrator account, follow these steps:
 Log-in to the computer using the Administrator user id and password.
  •  Select Start --> Control Panel.
  •  In the left panel, click Classic View.
  •  In the Control Panel window, double-click User Accounts.
  •  In the User Accounts window, click Change your password.
  •  In the Change your password window, enter your current password and a new  password.
  •  Click the Change password to save your changes.

3.Enable a Screen Saver Password:

To prevent someone from using your computer when you have move or left for a while, you should enable a screen saver password. Your screen saver password will be your account log-in password.
  1. In the Control Panel window, double-click Personalization. A list of options appears.
  2. Select Screen Saver.
  3. Set the following:
  •    Select a Screen saver from the drop down menu.
  •    Set the Wait time to 10 minutes or less.
  •    Select (check) On resume, display log on screen.
4.Click OK
Configure Local Security Auditing PoliciesWindows Vista has the facility to trace more security events, but the settings are not enabled by default. If your computer becomes compromised, keeping more logging information increases the chances that security experts will be able to  trace how and when the compromise occurred.
Follow these steps to enable additional security event logging:
  • Select Start > Control Panel.
  • In the left panel, click Classic View
  • In the Control Panel window, double-click Administrative Tools and then Local Security Policy.
  • If the User Account Control window appears, click Continue.
  • In the left pane, click the small arrow next to Local Policies and then select Audit Policy.
  • Double-click Audit account log-on events in the right pane.
  • In the Properties window, select the Local Security Settings tab.
  • Under Audit these attempts select (check) Success and Failure.

Additional Security Tips:

Update Software's:

Security vulnerabilities can exist in all software. Keep your software updated. You will find update information, for most software packages, from the Help menu. But before and after download check for the hash function from the downloaded website.

Backup Your Data Periodically:

You Should take backup of your important data regularly and make sure the procedure for restoring it is working properly. You should keep regular backups of your system and files. Use rewritable media such as tapes or disks. The first requirement is to calculate how much data you need to  backup and then select the type of backups. Monitor the backup process. Always keep an eye on the backup process. 
Steps for Backup your data:
  • Select Start --> Control Panel.
  • In the left panel, click Classic View.
  • In the Control Panel window, double-click Backup and Restore Center.
  • To create a backup, do one of the following:
  • Click Back up files to backup files and folders in your Documents folder.
  • Click Back up computer to create a restore image. Microsoft recommends doing this every six months.
  • If the User Account Control window appears, click Continue and follow the onscreen instructions.

Scan Downloaded Files:

Software from unauthorized sources can create many problems. For example: Freeware and low-cost software which are downloaded from  the Internet or can contain viruses that will infect your system and spread to other computers on the network.
Unauthorized software may be poorly written, that can cause crash your computer or send unwanted messages on the network. Unauthorized software may contain spy-ware that will capture information you type and send it to marketers or criminals. To scan a downloaded file, right-click the file and select Scan for Virus.

Disable Unnecessary Services:

You should enable only the services that are required to operate your device. Disabling unnecessary services can help protect your system from potential attacks.
To view and disable the services that are running on your machine, follow these steps:
  • Select Start > Control Panel.
  • In the left panel, click Classic View.
  • In the Control Panel window, double-click Administrative Tools and then Services.
  • If the User Account Control window appears, click Continue.
  • Select the Standard tab and double-click the service
  •  you wish to disable (e.g. Themes). The Properties window for that service appears as shown below

Use Bit-locker Drive Encryption:

BitLocker offers full-disk encryption. This means when BitLocker is enabled, the entire hard disk is encrypted. BitLocker is only available in Windows Vista Ultimate and Enterprise Editions only.

Windows Vista Parental Control:

Computers in today technology represent one of the greatest educational tools in recent times.  Using a computer and the Internet, children are able to research topics, communicate with students in other areas.  Access to those resources brings with it an exposure to risk – one that is copyright. As parents, you are constantly aware of dangers facing your children in the real world and want to keep them safe from online threats as well.
Parental Controls makes managing your children's online and offline activities much more secure and safe and includes easy to use tools to help you keep their computing activities a safe one. 

Add To Google BookmarksStumble ThisFav This With TechnoratiAdd To Del.icio.usDigg ThisAdd To RedditTwit ThisAdd To FacebookAdd To Yahoo

0 comments:

Post a Comment