Educause Security Discussion mailing list archives

Re: Malware (antivirus) software for Macintosh


From: Justin Azoff <JAzoff () ALBANY EDU>
Date: Thu, 17 May 2012 17:09:52 -0400

On Thu, May 17, 2012 at 08:54:57PM +0000, John Ladwig wrote:
Which “network security mitigation techniques,” didn’t work out for Flashback
at your site?

The majority of flashback infected machines were personal laptops that
were already infected while on an off campus location.  Almost all were
student owned machines, but a few were faculty/staff.

We would see IDS alerts < 10 seconds after the WPA login.

We focused on detection+suspension, we had ~200 infections total.

-- 
-- Justin Azoff
-- Network Security & Performance Analyst


Current thread: