Tuesday, October 22, 2013

Dealing with Cyberbullying

Cyberbullying refers to practice of using technology to harass, or bully, someone else. Bullies used to be restricted to methods such as physical intimidation, postal mail, or the telephone. Now, developments in electronic media offer forums such as email, instant messaging, web pages, and digital photos to add to the arsenal. Computers, cell phones, and PDAs are current tools that are being used to conduct an old practice.

Forms of cyberbullying can range in severity from cruel or embarrassing rumors to threats, harassment, or stalking. It can affect any age group; however, teenagers and young adults are common victims, and cyberbullying is a growing problem in schools.

Why has cyberbullying become such a problem?
The relative anonymity of the internet is appealing for bullies because it enhances the intimidation and makes tracing the activity more difficult. Some bullies also find it easier to be more vicious because there is no personal contact. Unfortunately, the internet and email can also increase the visibility of the activity. Information or pictures posted online or forwarded in mass emails can reach a larger audience faster than more traditional methods, causing more damage to the victims. And because of the amount of personal information available online, bullies may be able to arbitrarily choose their victims.

Cyberbullying may also indicate a tendency toward more serious behavior. While bullying has always been an unfortunate reality, most bullies grow out of it. Cyberbullying has not existed long enough to have solid research, but there is evidence that it may be an early warning for more violent behavior.

How can you protect yourself or your children?
  1. Teach your children good online habits. Explain the risks of technology, and teach children how to be responsible online (see Keeping Children Safe Online for more information). Reduce their risk of becoming cyberbullies by setting guidelines for and monitoring their use of the internet and other electronic media (cell phones, PDAs, etc.).
  2. Keep lines of communication open.  Regularly talk to your children about their online activities so that they feel comfortable telling you if they are being victimized.
  3. Watch for warning signs. If you notice changes in your child's behavior, try to identify the cause as soon as possible. If cyberbullying is involved, acting early can limit the damage.
  4. Limit availability of personal information. Limiting the number of people who have access to contact information or details about interests, habits, or employment reduces exposure to bullies that you or your child do not know. This may limit the risk of becoming a victim and may make it easier to identify the bully if you or your child are victimized.
  5. Avoid escalating the situation.  Responding with hostility is likely to provoke a bully and escalate the situation. Depending on the circumstances, consider ignoring the issue. Often, bullies thrive on the reaction of their victims. Other options include subtle actions. For example, you may be able to block the messages on social networking sites or stop unwanted emails by changing the email address. If you continue to get messages at the new email address, you may have a stronger case for legal action.
  6. Document the activity.  Keep a record of any online activity (emails, web pages, instant messages, etc.), including relevant dates and times. In addition to archiving an electronic version, consider printing a copy.
  7. Report cyberbullying to the appropriate authorities. If you or your child are being harassed or threatened, report the activity. Many schools have instituted bullying programs, so school officials may have established policies for dealing with activity that involves students. If necessary, contact your local law enforcement. Law enforcement agencies have different policies, but your local police department or FBI branch are good starting points. Unfortunately, there is a distinction between free speech and punishable offenses, but the legal implications should be decided by the law enforcement officials and the prosecutors.
 
Additional information:
The following organizations offer additional information about this topic:

National Crime Prevention Council

This information was produced by US-CERT and republished for non-commercial use as outlined in their Privacy & Use policy.

Monday, October 21, 2013

Test Your Phishing Knowledge

We're a little over halfway through National Computer Security Awareness Month, so how about a game to test your knowledge of phishing and other email scams? 

It only takes a couple of minutes and it's lots of fun.  Who knows - you might learning something as well!

Saturday, October 19, 2013

Thursday, October 17, 2013

Most Dangerous Celebrity


Lily Collins, daughter of Genesis musician Phil Collins, and star of movies such as The Mortal Instruments: City of Bones and Mirror, Mirror has the dubious honor of recently being dubbed 2013's Most Dangerous Celebrity. 

This is the seventh year that McAfee has ranked the riskiness of searching for certain celebrities on the web. If you search for Lily, you have a 14.5% chance of landing on a website that will infect your computer with spyware, adware, viruses or other malware that are designed to steal your password, email address or other personal information.  Be careful what you search for!

If you need tool that will help you decide what sites are good or bad, we recommend you consider using McAfee's SiteAdvisor software.  The price can't be beat (it's free) and it works with almost every major browser, including those on mobile devices.  SiteAdvisor works by adding color-coded ratings to your browser search:  green for a good site, yellow for questionable sites, and red for sites known to be malicious.

Wednesday, October 16, 2013

Time for Some Fun!

Can you find all the security-related words below?

Tuesday, October 15, 2013

Avoiding Social Engineering Attacks

What is a social engineering attack?

In a social engineering attack, an attacker uses human interaction (social skills) to obtain or compromise information about an organization or its computer systems. An attacker may seem unassuming and respectable, possibly claiming to be a new employee, repair person, or researcher and even offering credentials to support that identity. However, by asking questions, he or she may be able to piece together enough information to infiltrate an organization's network. If an attacker is not able to gather enough information from one source, he or she may contact another source within the same organization and rely on the information from the first source to add to his or her credibility.

What is a phishing attack?

Phishing is a form of social engineering. Phishing attacks use email or malicious websites to solicit personal information by posing as a trustworthy organization. For example, an attacker may send email seemingly from a reputable credit card company or financial institution that requests account information, often suggesting that there is a problem. When users respond with the requested information, attackers can use it to gain access to the accounts.

Phishing attacks may also appear to come from other types of organizations, such as charities. Attackers often take advantage of current events and certain times of the year, such as
  • natural disasters (e.g., Hurricane Katrina, Indonesian tsunami)
  • epidemics and health scares (e.g., H1N1)
  • economic concerns (e.g., IRS scams)
  • major political elections
  • holidays
How do you avoid being a victim?
  • Protect your password.  At KUMC, Information Resources will never ask for your password and you should never share your password with anyone, including your supervisor.   At home, remember that your bank and other companies that you do business with do NOT need your password for any reason.
  • Be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information. If an unknown individual claims to be from a legitimate organization, try to verify his or her identity.
  • Do not provide personal information or information about your organization, including its structure or networks, unless you are certain of a person's authority to have the information.
  • Do not reveal personal or financial information in email, and do not respond to email solicitations for this information. This includes following links sent in email.
  • Don't send sensitive information over the Internet before checking a website's security (see Protecting Your Privacy for more information).
  • Pay attention to the URL of a website. Malicious websites may look identical to a legitimate site, but the URL may use a variation in spelling or a different domain (e.g., .com vs. .net).
  • If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. Do not use contact information provided on a website connected to the request; instead, check previous statements for contact information. Information about known phishing attacks is also available online from groups such as the Anti-Phishing Working Group.
  • Take advantage of any anti-phishing features offered by your email and web browser software.

What do you do if you think you are a victim?
  • If you believe you might have revealed sensitive information about your organization, report it to the appropriate people within the organization (call (913) 588-7995 at KUMC). They can be alert for any suspicious or unusual activity.
  • If you believe your financial accounts may be compromised, contact your financial institution immediately and close any accounts that may have been compromised. Watch for any unexplainable charges to your account.
  • Immediately change any passwords you might have revealed. If you used the same password for multiple resources, make sure to change it for each account, and do not use that password in the future.
  • Watch for other signs of identity theft (see Preventing and Responding to Identity Theft for more information).
  • Consider reporting the attack to the police, and file a report with the Federal Trade Commission.
This information was adapted from an original production by US-CERT and republished for non-commercial use as outlined in their Privacy & Use policy.