Are my security measures adequate?

Jester45

New member
Member
Local time
8:09 AM
Messages
62
Location
Missouri, USA, Earth
Quick background for me is that im 18, love computer and currently the tech support for my family(close and extended), neighbors, family friends, etc etc. While I dont have the strictest policies I do try to keep my home network along with anyones computer i work on non-infected.

Some of my scheduled task are:
  • Nightly backups to a WHS box.
  • Nightly full system virus scans (Avast! home) on all desktops and the WHS. Laptops dont have scheduled taskes but my WHS warns me if i dont do either after a week.
  • Automatic updates on Avast and Windows/linux(gentoo based so not completely automatic)
And general precautions:
  • My servers(except WHS) are on a different subnet as my desktops.
  • Servers are all linux except 1 and ssh is on non standard port with ssh only via keys
  • Servers also do mail and that is scanned for viruses
  • Router's UPnP is disabled, default password changed
  • Only needed ports are forwarded
  • Wifi clients can't communicate with desktops except for WHS.

I know this isnt completely Win7 related but i do have a few machines running it. i listen to a few security podcasts because they are interesting to me but I don't think im overly paranoid(no pseudo-random 265bit passwords).

Do you guys have any extra suggestions for me to do? Does windows7 introduce any "features" i should be on the lookout for?
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 64bit
CPU
Phenom II 1055T @ 3.1 Ghz (+.3 Ghz OC)
Motherboard
Asus
Memory
8GB
Graphics Card(s)
2x Nvidia GTX 260 core 216
Sound Card
Intergrated 7.1
Monitor(s) Displays
dual 23"
Screen Resolution
3840x1080
Hard Drives
C: 30GB intel ssd
D: 2x 500GB WD black raid 0
NAS: 6TB WB green raid 5
PSU
750w
Case
Black
Cooling
Oxygen, Nitrogen, other various gases.
Keyboard
QWERTY and clicky
Mouse
logitech wireless
Internet Speed
12Mbit down; 4Mbit up | 6Mbit down; 1Mbit up (Both DSL)
Other Info
blue led fans look nice
Your security measures are excellent except that fact that you are using just 1 anti virus. there are many things that antivirus misses during scans. hence you should also use Malwarebytes.org alongwith avast.
 

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
Hi,

your configuration is mainly about Detection (AV) and Cure (backup plan) - it's not bad approach but on these days you should add also Prevention to your security arsenal - already you have FW/Router and you do OS updates.

Under term of Prevention I mean: HIPS softwares, virtualization, sandboxes, policy based-sandoboxes, SRP, LUA, UAC, DEP, and also FW - hardware/software or both.
Of course you don't need all of them, but to make a decision better will be give a try and test which meets your needs.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Windows 7 Home Premium x32 SP1
CPU
x2 2.6 GHz
Motherboard
Asus
Memory
A-Data 2GB DDR2-800
Graphics Card(s)
ATI X1250
Sound Card
SB 5.1 Live!
Hard Drives
WD and Seagate FAP
PSU
Tagan TG-480-U01
Keyboard
BTC 6300
Mouse
Logitech VX Nano
Antivirus
None
while i understand the concepts behind visualization and sandboxes but i dont see the point for the most part. My linux systems have their daemons jailed but i do no sandboxing on Windows.

As for IDS ive heard of snort but is IDS really overkill for a large-ish home network? if a machine goes down not much if affected, backups are there so settings/programs are not lost and media is stored on WHS. If my WHS was lost i would have have a problem but i don't think that will happen as it doesn't connect to the internet except for updates.

UAC is enabled on my win7 machines and for linux boxes im the only person who can access them other than by the services they provide.

I'm not sure what you mean by SRP and LUA.
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 64bit
CPU
Phenom II 1055T @ 3.1 Ghz (+.3 Ghz OC)
Motherboard
Asus
Memory
8GB
Graphics Card(s)
2x Nvidia GTX 260 core 216
Sound Card
Intergrated 7.1
Monitor(s) Displays
dual 23"
Screen Resolution
3840x1080
Hard Drives
C: 30GB intel ssd
D: 2x 500GB WD black raid 0
NAS: 6TB WB green raid 5
PSU
750w
Case
Black
Cooling
Oxygen, Nitrogen, other various gases.
Keyboard
QWERTY and clicky
Mouse
logitech wireless
Internet Speed
12Mbit down; 4Mbit up | 6Mbit down; 1Mbit up (Both DSL)
Other Info
blue led fans look nice
I'm not sure what you mean by SRP and LUA.
SRP = Software Restriction Policy. For more information, click here.
LUA - Limited User Account, a non-admin, non-power user account with limited privileges. Also known as SUA (Standard User Account) in Vista and Win7.
 

My Computer

Computer Manufacturer/Model Number
Self Assembled
OS
Win7 RTM, XP Pro, Arch Linux, Puppy (Quad boot)
CPU
Core i7 920 (OCed @ 3.8Ghz)
Motherboard
ASUS P6T Dlx
Memory
OCZ Gold 6GB DDR3-1600
Graphics Card(s)
Sapphire Radeon HD 5870 1GB (OCed @ 935/1300)
Sound Card
On-board
Monitor(s) Displays
Samsung 24"
Hard Drives
WD Caviar Black 1TB, WD Velociraptor 300GB, Maxtor 250GB
PSU
Corsair HX620W
Case
Antec 1200
Cooling
Noctua U12P
well i do LUA/SUA. along with that all windows based users need a "complex" password enforced by WHS which is 1 CAPTIAL letter, numbers, and >6 characters long. My linux boxes have root but only i have a normal user, and have to su to root.

and ill have to look into the SRP stuff, sounds real nice on the laptops. and SRP on the WHS would be a good thing too as i only use ~15 programs max (including system processes) so i could lock that down pretty tight.
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 64bit
CPU
Phenom II 1055T @ 3.1 Ghz (+.3 Ghz OC)
Motherboard
Asus
Memory
8GB
Graphics Card(s)
2x Nvidia GTX 260 core 216
Sound Card
Intergrated 7.1
Monitor(s) Displays
dual 23"
Screen Resolution
3840x1080
Hard Drives
C: 30GB intel ssd
D: 2x 500GB WD black raid 0
NAS: 6TB WB green raid 5
PSU
750w
Case
Black
Cooling
Oxygen, Nitrogen, other various gases.
Keyboard
QWERTY and clicky
Mouse
logitech wireless
Internet Speed
12Mbit down; 4Mbit up | 6Mbit down; 1Mbit up (Both DSL)
Other Info
blue led fans look nice
well i do LUA/SUA. along with that all windows based users need a "complex" password enforced by WHS which is 1 CAPTIAL letter, numbers, and >6 characters long. My linux boxes have root but only i have a normal user, and have to su to root.

and ill have to look into the SRP stuff, sounds real nice on the laptops. and SRP on the WHS would be a good thing too as i only use ~15 programs max (including system processes) so i could lock that down pretty tight.

Here you find nice software to manage SRP:
http://mrwoojoo.com/PGS/PGS_index.htm
PGS Pretty Good Security by Sully from Wilders.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Windows 7 Home Premium x32 SP1
CPU
x2 2.6 GHz
Motherboard
Asus
Memory
A-Data 2GB DDR2-800
Graphics Card(s)
ATI X1250
Sound Card
SB 5.1 Live!
Hard Drives
WD and Seagate FAP
PSU
Tagan TG-480-U01
Keyboard
BTC 6300
Mouse
Logitech VX Nano
Antivirus
None
Back
Top