There are three basic classes of counter-measures which can be utilized against security attacks. These classes are active, passive and aggressive measures.
Active measures on system level use either heuristic or checksum-based detection to detect unauthorized code/files. Signature-based detection is common on network-based protection, such as IPS systems. Firewalls can perform active protection when used in rate-limit or dynamic blocking fashion. Encryption can also be considered Active measure, as it is used on network medium.
Encryption can also be considered a passive measure. It should be used when storing confidential information. Firewall rulesets and switch and router ACLs can be considered passive protection.
Use of aggressive measures should be limited to research purposes and kept away from production networks. Honeypot-like setups can be used to offer decoy hosts for intruders to attack on, and capture the used malicious code for analysis.
The wikipedia article (https://en.wikipedia.org/wiki/Intrusion_detection_system) is a decent place to start, but basically they boil down to one of two varieties:
Need to update, new recommendations from NIST just dropped (password lenght 15 char, no need to force change password on a schedule just when compromised, etc.)
See https://pages.nist.gov/800-63-3/sp800-63b.html#sec5
Sur le site de l'ANSSI : https://www.ssi.gouv.fr/
Récupérer le PDF : anssi-guide-authentification_multifacteur_et_mots_de_passe.pdf
Name | Link | Multi Platform | Browser | Import | Export | Multi-FA | Secure Sharing | Install |
---|---|---|---|---|---|---|---|---|
Proprietary | ||||||||
LastPass | https://lastpass.com | yes | yes | yes | yes | yes | yes | local+cloud sync |
1Password | https://1password.com | yes | yes | yes | yes | yes | yes | local+cloud sync |
DashLane | https://www.dashlane.com/ | yes[1] | yes | yes | yes | yes | yes | local+cloud sync |
Can self host + open source | ||||||||
BitWarden | https://bitwarden.com/ | yes | yes | yes | yes | yes | yes | local+cloud sync |
KeePass | https://keepass.info/ | yes[2] | yes | yes | yes | yes[3] | yes[4] | local+cloud sync |