Friday, 26 December 2014

Trojan Detection and Preventions



Following are the things that need to be checked for Detecting Trojans:
  • ·         Open Ports
  • ·         Running processes
  • ·         Registry Entries
  • ·         Device Driver installed on the system
  • ·         Windows services
  • ·         Start-up programs
  • ·         Suspicious files and folders
  • ·         Suspicious network activities
  • ·         Modifications to Operating System files
Note: Various software tools are available for monitoring each of the above point.



Following are the countermeasure for Trojans:

  • ·         Avoid opening email attachments from the unknown senders.
  • ·         Block all unnecessary attachments received from unknown senders.
  • ·         Avoid accepting the programs transferred by instant messaging.
  • ·         Harden weak, default configuration settings.
  • ·         Disable unused functionality including protocols and services.
  • ·         Monitor the internal network traffic for odd ports or encrypted traffic.
  • ·         Avoid downloading and executing applications from untrusted sources.
  • ·         Install patches and security updates for the operating systems and applications.
  • ·         Scan CDs and floppy disks with antivirus software before using.
  • ·         Avoid typing the commands blindly and implementing pre-fabricated programs or scripts.
  • ·         Manage local workstation file integrity through checksum, auditing, and port scanning.
  • ·         Run local versions of antivirus, firewall, and intrusion detection software on the desktop.