Network security error operation inventory easily overlooked by users

Source: Internet
Author: User
Tags ssl certificate

You can install the best firewalls, fix the vulnerabilities in a timely manner, and ensure that antivirus software remains updated, but there is a network risk factor that you will never be able to control: users, users have long been considered the most complex and difficult to control security risks for most businesses.

Many users now surf the web using work equipment in the workplace, which is another headache security risk.

"Enterprise security personnel are responsible for ensuring that users do not perform any actions that pose a security threat to the user, and that end users do not want any problems that affect their normal work." When a security person starts locking and shutting down certain network features (such as turning off IE's Adobe file reading feature), the user name is always unable to operate as required. ”

The following are some of the common security errors that users perform on the Internet, and provide a corresponding workaround.

Install ActiveX controls blindly

When users use IE to browse Web pages, they often need to install ActiveX to view specific information. Pop-up information at the top of the page prompts the user to install the control, and users often blindly install the controls without considering the consequences to view the information they want. But ActiveX controls are just code that runs, and it's easy for hackers to take advantage of malicious attacks.

So how do you get users to understand the downside of ActiveX? You should let users know that ActiveX is a security threat like any other application. The latest version of IE can lock controls on a particular Web site, for example, if a user uses a Google-required control, the control will only be available on the Google site. Administrators should deploy this IE in their Group Policy control to prevent users from creating security threats.

Credulous SSL Certificate

When the user sees the pop-up message "Bad SSL certificate", they tend to click Add exception, and then continue to operate, they do not know the harm. This means that the Web site that users visit is not the site they really want to visit, it may be a phishing site.

Therefore, users should be advised to be extra cautious the next time they see this hint.

Allow unsigned content

We may encounter the situation: When browsing the Web page, the browser prompts the program XYZ to see the information, and then prompts you to download the program from the site, click on the installer, there will be prompted to say "unsigned content", Microsoft can not verify the source of these programs and the operator.

It's a very unsafe practice for users to click OK without warning.

Users can log in to downloads.com, which can be downloaded in a secure way, which helps users scan for viruses and provides a variety of common programs.

Be driven by curiosity

You may have received information such as "Click to view your video", or prompt your bank account to be leaked, and often contain a malicious link that requires you to enter an account number. Why are there still people who have been cheated for so many years? Because of curiosity. Users must be told that all sorts of dubious information and links on the web can pose a security threat.

With an attitude of trying

Everyone is very busy, when encountering a problem, often regardless of 3,721, as long as can help them to complete the work will click any Content and link. Users must consider the various security issues before they click to make a move.

Information provided address: http://www.cnsilab.com Happy hen

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.