Skip to main content

Unit 4 · Topic 4.3

4.3 Protecting Devices

Protecting a device takes rules for people and tools on the device itself. This topic covers the three device policies the course names, how anti-malware software finds and removes threats, why updates and patches matter, and how to set up a host-based firewall, including rules for outbound traffic.

Key terms

  • acceptable use policy
  • software installation policy
  • malware signature
  • patch
  • host-based firewall
  • outbound rule

Managerial controls: device policies

  • An acceptable use policy (AUP) says what users must, may and must not do on organization-owned devices. It might block certain websites (like social media or gaming), require users to keep software updated, allow some peripherals like a mouse or headset, and forbid external drives or media.
  • A password policy sets the rules for passwords: minimum or maximum length, minimum or maximum time before a change, no reuse, construction rules (like no dictionary words, and required character sets), and a suggestion to use a password manager instead of writing passwords down.
  • A software installation policy says what software, if any, users may install. It might ban user installs, set up a request process for software someone needs for their job, and list approved programs.

Anti-malware software

Anti-malware (often called antivirus) software finds, quarantines and removes malware that could corrupt, spy on or destroy a system. Malware contains telltale patterns, called signatures, that make it detectable.

The software keeps a database of known malware signatures. It regularly scans the device's files and checks each one against the database. When a file matches, it's quarantined (locked away where it can't run) and removed. Because new malware appears constantly, the signature database must be kept up to date.

Updates and patches

When a vulnerability is found in an operating system or program, the company or group that maintains it releases a fix in an update. A small update is called a patch.

Once a flaw is public, adversaries can build exploits for it, so a device that hasn't installed the patch is exposed to a known, well-documented attack. Keeping the operating system and every application on the latest version closes those known holes.

Host-based firewalls

A host-based firewall is software that runs on one device and allows or denies traffic into and out of that device. It adds a layer of protection in case the device ends up on a compromised network, like a hotel's Wi-Fi.

It works like a network firewall: an ordered ACL, checked from the top, where the first matching rule wins. Rules can match source or destination port or IP address, service, protocol or application.

A host-based firewall should block every port and service the device doesn't need. It can also block outbound traffic. That matters because an adversary who gets remote access usually wants to send stolen files out. Blocking outbound FTP, for example, stops them from using FTP to exfiltrate files to their own server.

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    Configuring a host-based firewall

    A teacher's laptop needs to browse the web (HTTP and HTTPS out) and receive nothing unrequested from the network. The IT team also wants to block outbound FTP to stop file exfiltration. Write an ordered rule list.

    Show the solution
    1. Step 1: Block exfiltration first, so no later allow rule can match it: Rule 1: Deny outbound TCP 20–21 (FTP) to ALL.
    2. Step 2: Allow needed web traffic: Rule 2: Allow outbound TCP 80 to ALL. Rule 3: Allow outbound TCP 443 to ALL.
    3. Step 3: Block everything inbound that the laptop didn't ask for: Rule 4: Deny inbound ALL from ALL. Host-based firewalls built into operating systems are usually stateful, so replies to the laptop's own web requests are still let back in.
    4. Step 4: Check the order: FTP out hits Rule 1 and is denied; web browsing matches Rules 2 or 3. (A real laptop also needs DNS, port 53 outbound, to look up web addresses. Add it as an allow rule above any outbound deny-all.)

    Answer: 1: Deny outbound TCP 20–21 to ALL. 2: Allow outbound TCP 80 to ALL. 3: Allow outbound TCP 443 to ALL. 4: Deny inbound ALL from ALL (plus an allow for outbound DNS on port 53 if outbound traffic is otherwise restricted).

  2. Example 2

    Which policy?

    Name the policy that each rule belongs in: (a) "Employees may not install browser extensions without IT approval." (b) "Passwords must be at least 14 characters and may not reuse the last 10." (c) "Company laptops may not be used for online gaming."

    Show the solution
    1. Step 1: (a) It's about what software users may install and the approval process: software installation policy.
    2. Step 2: (b) It sets length and reuse rules: password policy.
    3. Step 3: (c) It says what activities are prohibited on organization devices: acceptable use policy.

    Answer: (a) Software installation policy. (b) Password policy. (c) Acceptable use policy.

Common mistakes

  • Thinking anti-malware protects against everything. Signature scanning only catches malware already in its database, so it must be updated and paired with other controls.
  • Forgetting outbound rules. A host-based firewall can stop data from leaving, not just attacks from coming in.
  • Putting a broad allow rule above a specific deny rule. The first match wins, so the deny never runs.
  • Treating patches as optional. Unpatched devices are open to exploits for known, published flaws.

On the exam

  • You may be asked to write or change a host-based firewall rule and explain its effect. State the direction, port or service, and action, and explain what attack or traffic it stops.
  • If asked how an acceptable use policy protects a device, link a specific rule to a specific threat, like banning external drives to stop malware loaded from USB.

Connected topics

Videos

Check yourself: 4.3 Protecting Devices

4 questions on 4.3 Protecting Devices. Pick an answer to see if you got it, and why.

Excerpts from three policies at Oakmont Engineering, an invented company:

Excerpt 1: Employees may not visit social media or gaming websites on company laptops, and they must accept software updates within two days.

Excerpt 2: Passwords must be at least 14 characters long and may not contain dictionary words. Employees should store passwords in the approved password manager instead of writing them down.

Excerpt 3: Employees may not install software. They may request a program from the approved list by submitting a ticket to IT.

Invented policy excerpts

Question 1 of 4

Which policy does Excerpt 1 most likely come from?

Question 2 of 4

How does Excerpt 3 reduce risk to the company's devices?

Question 3 of 4

How does anti-malware software decide whether a file on a device is malicious?

Question 4 of 4

An adversary writes a brand-new piece of malware that has never been seen before. Why might a device's signature-based anti-malware software miss it?

0 of 4 answered