malware

Learn from a malware analyst and empower your colleagues about security


Here are two very important steps to take to help your colleagues protect themselves

Here are two very important steps to take to help your colleagues act like malware analysts.

1. Start with education.

The first step in setting users up for success is to make sure they are receiving a thorough and ongoing education about what constitutes safer behavior. Start with simple, positive instructions and move to more complex information, so that users are not overwhelmed and feel empowered to take protective actions.

When educating people about how to do something new or potentially confusing, it’s a good idea to tell them what they should do to be successful, rather than what they should not do. For example, if you’re teaching someone to cross the street, it’s better to use statements that positively describe safe action, like “Look both ways before crossing.” This is much clearer than saying “Don’t run into traffic.”

Positive instructions give clear, explicit directions; they do not force listeners to figure out which action to take instead. If people are not experts, they may guess incorrectly and develop unsafe habits.

A group led by the National Cyber Security Alliance and the APWG has created a list of simple, memorable security slogans that educators can use, such as: “Keep a clean machine,” “Share with care,” and “Lock down your login.” These phrases are not intended to fully explain safer behavior, but to provide sticky ways for people to recall a more robust set of instructions.

After introducing these basic security concepts, you can move to more complex and nuanced instructions, including information on what to do if and when they run into situations that preclude the prescribed safer behavior or what to do if accidents occur. Once users understand this, you can begin to introduce them to specialized tools.

2. Use our expertise to enable exploration.

Let’s take a deeper look at the example of what users should do if they get an unsolicited or suspicious attachment or link. Security software is an important level of defense, but it should not be the only protection. Even if a file is scanned without triggering an alert, it may still be wise to approach it with a degree of caution.

If a user finds a suspicious file or message, he or she should delete it without opening it and/or report it to an appropriate person for further examination. They could also contact the sender to ascertain what the file or link is, and whether it was sent intentionally. If they have too many suspicious files for these extra steps to be practical, they could be given a more protected environment—like a malware analyst uses—to inspect it safely.

Malware analysts use a physical or virtual “sacrificial goat” machine that’s totally separated from the rest of the network, or from the Internet at large if that’s appropriate, which they can quickly re-image to a clean state when they’re done. If this is not feasible, you may wish to create separation in your network so that if a security event occurs in one area, it can’t spread to your entire network. You can also create profiles that authorize more lenient permissions for students and staff who need to explore, while locking down more sensitive groups such as payroll, administration, or healthcare.

There are ways to train even the most inexperienced individuals to pilot their way through a high-risk and complex scenario. While it may initially involve more work from security practitioners, helping users explore safely can go a long way towards developing long-lasting and durable trust.

Sign up for our newsletter

Newsletter: Innovations in K12 Education
By submitting your information, you agree to our Terms & Conditions and Privacy Policy.

eSchool Media Contributors