Defensive computing

Defensive computing is a set of practices that computer users can use to reduce their risk of computer security problems. The goal of this method of computing is to anticipate and prepare for potentially problematic situations prior to their occurrence,[1] despite any adverse conditions of a computer system or any mistakes made by other users. This can be achieved through adherence to a variety of general guidelines, as well as the practice of specific computing techniques. Defensive computing includes protecting information privacy.[2] Both defensive computing and cybersecurity awareness are approaches that individual computer users can use to reduce risks.[3]

The term defensive computing is an analogy to defensive driving.[4][5] It was most commonly used in the 2000s and 2010s, before the software industry shifted to building better user protections into software by default, including by applying the concepts of usable security and secure by design.

Strategies

Network security

A commonly recommended defensive computing strategy is to implement firewall software that filters both inbound and outbound traffic,[6] as a network security measure that protects a computer from harmful inbound and outbound traffic on the Internet and reduces the risk of the unauthorized access of computer systems.[7] As of 2023, most operating systems include built-in firewall features.[8]

Anti-malware practices

A core strategy recommended for defensive computing was to install and use antivirus software, especially for Microsoft Windows computers.[9][10][6] However, recommendations related to defensive computing noted the limitations of antivirus software and suggested additional ways of reducing risk, such as using a user account with limited permissions or a Chromebook.[11] Microsoft Windows eventually built in Windows Defender, an antivirus tool.[12]

Other common recommendations include keeping software up to date.[10] In the 2000s, another recommendation was to disable AutoRun feature from USB flash drives, because some viruses, especially worms, could spread automatically through USB flash drives.[13]

Skepticism

An important aspect of defensive computing is for users to be skeptical.[10] Malicious software can exist in a multitude of different forms and many are misleading to general computer users and even some anti-malware software. Defensive users think critically about the information they can access, to reduce their chances of downloading and spreading malicious software. Strategies include scanning email attachments prior to opening them and manually filtering suspicious emails from inboxes.[14] Users should be aware of persuasive subject lines and headings in emails from any address, as they may actually contain malicious software or spam, which can mislead users into false advertisement resulting in identity theft.[6] Defensive users can scan files they download prior to opening them and can also configure their computers to show file extensions, revealing potentially dangerous files that appear harmless.[9] Skepticism can also be applied to the websites visited by users.[6]

Data backups

Despite the efforts of a defensive computer user, the loss of important data can occur due to malware, power outages, equipment failure and general misuse. Although the loss of data cannot be completely prevented, defensive users can take steps to minimize the amount of data lost and restore systems to their previous state by backing up their data.[6]

See also

References

  1. ^ Horowitz, Michael (2007-07-06). "Introducing the defensive computing blog". CNET. Retrieved 2026-08-01.
  2. ^ Loukides, Mike (2017-05-31). "Defensive computing". O’Reilly Media. Retrieved 2026-08-01.
  3. ^ Greene, Thomas (2013-11-09). Computer Security for the Home and Small Office. Apress. pp. xv. ISBN 978-1-4302-0711-5.
  4. ^ Mitnick, Kevin D.; Simon, William L. (2011-08-04). The Art of Deception: Controlling the Human Element of Security. John Wiley & Sons. p. 9. ISBN 978-0-7645-3839-1.
  5. ^ "NYS Senate Public Hearing - Cyber Security: Defending New York from Cyber Attacks" (PDF). The New York State Senate. November 18, 2013. p. 41. Retrieved 2026-08-01.
  6. ^ a b c d e Horowitz, Michael (April 20, 2008). "The pillars of Defensive Computing". CNET. Archived from the original on 2013-09-05. Retrieved 2026-08-01.
  7. ^ http://www.cs.unm.edu/~treport/tr/02-12/firewall.pdf Archived 2017-08-30 at the Wayback Machine, A History and Survey of Network Firewalls
  8. ^ "Understanding Firewalls for Home and Small Office Use". CISA. 2023-02-23. Retrieved 2026-08-01.
  9. ^ a b Mullerworth, Michael (June 2002). "Defensive Computing - How To Protect Yourself From Virus Infection". Melbourne PC User Group. Archived from the original on 2013-05-05. Retrieved 2026-08-01.
  10. ^ a b c Horowitz, Michael (December 19, 2009). "Defensive computing priorities". Computerworld. Retrieved 2026-08-01.
  11. ^ Horowitz, Michael (June 23, 2012). "How useful is antivirus software?". Computerworld. Retrieved 2026-08-01.
  12. ^ "Technology Knowledge Base - Virus and Malware Removal". Kenyon College. Retrieved 2026-08-01.
  13. ^ Horowitz, Michael (August 27, 2008). "Be safer than NASA: Disable autorun". CNET. Archived from the original on 2012-10-25. Retrieved 2026-08-01.
  14. ^ Horowitz, Michael (March 15, 2017). "Defensive Computing for email attachments". Computerworld. Retrieved 2026-08-01.

Content Disclaimer

Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.

  1. The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
  2. There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
  3. It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
  4. Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
  5. Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.