Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Human Nature vs. Security
Daniel Hanson, 2004-03-29

Social engineering in the latest crop of viruses has people jumping through hoops to open malicious attachments. How do we change the pattern?

Comments Mode:
Human Nature vs. Security 2004-03-30
Anonymous
Human Nature vs. Security 2004-03-30
IT Professional (2 replies)
Human Nature vs. Security 2004-03-31
Anonymous
Human Nature vs. Security 2004-04-05
Anonymous (1 replies)
Human Nature vs. Security 2004-04-07
Anonymous
Human Nature vs. Security 2004-03-30
Mene Tekel (1 replies)
Human Nature vs. Security 2004-04-06
Anonymous (1 replies)
Human Nature vs. Security 2004-04-07
Anonymous
Human Nature vs. Security 2004-03-30
Simonis
Human Nature vs. Security 2004-03-30
Anonymous
Human ignorance vs. security 2004-03-30
F. Obfusco
Human Nature vs. Security 2004-03-30
Yvan Boily (1 replies)
Human Nature vs. Security 2004-04-02
Anonymous
Human Nature vs. Security 2004-03-31
jaywalker (3 replies)
Human Nature vs. Security 2004-04-01
Brainclots (1 replies)
Human Nature vs. Security 2004-04-04
Mene Tekel
Human Nature vs. Security 2004-04-01
IT Professional (1 replies)
Human Nature vs. Security 2004-04-02
Anonymous
Human Nature vs. Security 2004-04-01
Anonymous
Human Nature vs. Security 2004-03-31
Anonymous (1 replies)
Human Nature vs. Security 2004-04-01
The Suite (1 replies)
Human Nature vs. Security 2004-04-02
Anonymous
Human Nature vs. Security 2004-04-01
Chris
Human Nature vs. Security 2004-04-01
Educational Netowrk admin
Human Nature vs. Security 2004-04-02
Roy
Releasing an antivirus?? do you not remember the absolute noightmare caused first by blaster, and then by naachi as it searched for blaster to apply a microsoft patch?

What if a home made 'teaching' virus was accidentally escaped the perimiter? you may be liable.

The answer is in the title. we must appeal to human nature at a higher, or lower, level than the virii do.

How about the christmas bonus (remember the good days, huh?) being denied if a virus was introduced?

If an amount was budgeted for cleanup operations at the start of the year, everyone in your business would have a target that is tangible, a reason to not get caught out by the promise of britneys melonious baps.

You could withdraw the bonus at a departmental level, or reduce it per outbreak. appeal to the greed. it would be the last time a virus outbreak started in your sales department ;)

surely the cost of cleansing and/or repairing the damage caused by a virus outbreak would be covered by such a scheme, and if not needed, used to reward good behaviour on the part of your employees.

do you think such a scheme has merit?


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/231/25687#25687
Human Nature vs. Security 2004-04-05
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus