What would you recommend SOHO users do to add protection over and above the usual firewall setups? I am a layman in this regard and my understanding is that firewalls typically only close the most commonly known ports that may be left unprotected otherwise. As far as I understand, most other ports higher up in the range remain wide open. Is this correct?
On Win XP, 7 Ultimate and 8, I used Tinywall and also tried Comodo. Not using Windows now so my situation may be different. My life in IT was spent mostly on SOHO/SMME LAN systems that were not connected to the outside world at all. That obviously was long ago. I am now retired and tinker a bit; my son is setting up a new small company and I have been asked to lend a casual hand. The more I read the warier I become.
It seems like a field for experts and then we see how even Ubuntu Forums got hacked. (My PC 2-3 decades ago never got viruses as there was no sneaky networking done by floppy drive.) Internet has changed the landscape dramatically.
hmmm...not entirely clear what you are trying to protect here. You mention windows but also mention "not using windows now". Seems your helping your son - who (taking a guess here) is probably still on windows.
>>It seems like a field for experts and then we see how even Ubuntu Forums got hacked.
No you must keep in mind that its about profile too. Ubuntu forums is a high profile target. Skilled hackers specifically target it for the prestige & "glory". With home use & small businesses the aim of the game is to get the attacker to say "screw this lets find an easier target". Kinda like putting up an electric fence isn't *really* going to deter a thief...but if the thief has a choice between electric fence vs house with no electric fence then yeah.
So assuming windows. Lose the Win XP. Windows 7 is where you want to be. Ultimate is unnecessary...Home premium is sufficient for 99% of the people including me. Not sure whether you can legally use it for a business though...
Generally, you need 3 things:
1) An antivirus. See my posts here:
http://mygaming.co.za/forum/showthread.php/33203-Firewall
...ignore everything I said about HIPS...you don't need it.
2) A mechanism to block incoming connections. Most connectivity (3G, ADSL) does this by default unless you do something funky. (ADSL dialing out from the PC in particular is a risk). Else a firewall like comodo would do the trick (disable everything except the firewall). On the whole you're aiming for "good enough" here...nothing too complicated.
3) Cautious user. This is the most important part...99% of the danger comes from idiots clicking on random attachments in emails and similar crap. No amount software will protect systems from idiots.
>>As far as I understand, most other ports higher up in the range remain wide open. Is this correct?
No. Nothing should show as open. In general all connections are initiated from your side & everything else coming from the internet uninvited is refused. See point 2 above. If stuff is showing as open then something is wrong because your PC is accepting uninvited connections. Either you set up ADSL without NAT or you've got 3G using an open APN. Post more details regarding your connection method & I/someone will help.
As for lending your son a hand. I feel you should rather focus on backups to be honest....the lack of a solid backup solution is much more likely to result in tears than the security situation.