Security in Computing, Fifth Edition Chapter 1:
GB
Published · 32 slides · 0 views
1 / 1
Description
Security in Computing, Fifth Edition Chapter 1: Introduction 1 About the Module The core book is Security in Computing by Charles Pfleeger and Shari Pfleeger, Pearson COM535 Home page is really Blackboard but also mirrored below:
Related Topics
Share
Embed code
Download this presentation From Below
"Security in Computing, Fifth Edition Chapter 1:" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
01
Security in Computing,Fifth Edition Chapter 1: Introduction 1<br>
02
About the Module The core book is Security in Computing by Charles Pfleeger and Shari Pfleeger, Pearson COM535 Home page is really Blackboard but also mirrored below:
https://kevincurran.org/teaching/systems-security/
Please remember optional means optional.
Practicals:
Placed on Blackboard each week.
Examination:
Coursework 100% - Essay on security topic for week 7 and class test in labs where you will demonstrate aspects of the lab
Core module text on Blackboard<br>
https://kevincurran.org/teaching/systems-security/
Please remember optional means optional.
Practicals:
Placed on Blackboard each week.
Examination:
Coursework 100% - Essay on security topic for week 7 and class test in labs where you will demonstrate aspects of the lab
Core module text on Blackboard<br>
03
Content Covered in labs https://kevincurran.org/com535/LabContents.pdf<br>
04
Objectives for this lecture Define computer security as well as basic computer security terms
Introduce the C-I-A Triad
Introduce basic access control terminology
Explain basic threats, vulnerabilities, and attacks
Show how controls map to threats
Define the Internet of Things and discuss associated emerging security issues
Discuss nascent efforts to financially measure cybersecurity to make sound investment decisions
Explore the evolving field of electronic voting, which has been an important and open security research problem for over a decade
Study potential examples of cyber warfare and their policy implications 4<br>
Introduce the C-I-A Triad
Introduce basic access control terminology
Explain basic threats, vulnerabilities, and attacks
Show how controls map to threats
Define the Internet of Things and discuss associated emerging security issues
Discuss nascent efforts to financially measure cybersecurity to make sound investment decisions
Explore the evolving field of electronic voting, which has been an important and open security research problem for over a decade
Study potential examples of cyber warfare and their policy implications 4<br>
05
What’s in a Tweet?<br>
06
What Is Computer Security? The protection of the assets of a computer system
Hardware
Software
Data 6<br>
Hardware
Software
Data 6<br>
07
Assets 7<br>
08
Values of Assets 8<br>
09
Basic Terms Vulnerability
Threat
Attack
Countermeasure or control From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 9<br>
Threat
Attack
Countermeasure or control From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 9<br>
10
Threat and Vulnerability 10<br>
11
Common Threats and Attacks<br>
12
The CIA Triad The National Institute of Standards and technology (NIST) Computer Security Handbook defines the term Computer Security as:
“The protection afforded to an automated information system in order to attain the applicable objectives of preserving the integrity, availability and confidentiality of information system resources” (includes hardware, software, firmware, information/data, and telecommunications).<br>
“The protection afforded to an automated information system in order to attain the applicable objectives of preserving the integrity, availability and confidentiality of information system resources” (includes hardware, software, firmware, information/data, and telecommunications).<br>
13
Access Control From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 13<br>
14
Types of Threats From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 14<br>
15
Advanced Persistent Threat (APT) Organized
Directed
Well financed
Patient
Silent From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 15<br>
Directed
Well financed
Patient
Silent From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 15<br>
16
Types of Attackers From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 16<br>
17
Types of Harm From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 17<br>
18
Method—Opportunity--Motive From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 18<br>
19
Controls/Countermeasures From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 19<br>
20
Different Types of Controls From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved. 20<br>
21
Emerging Topics 21<br>
22
The Internet of Things (IoT) IoT refers to the connection of everyday devices to the Internet, making a world of so-called smart devices
Examples:
Smart appliances, such as refrigerators and dishwashers
Smart home, such as thermostats and alarm systems
Smart health, such as fitness monitors and insulin pumps
Smart transportation, such as driverless cars
Smart entertainment, such as video recorders
Potential downsides:
Loss of privacy
Loss of control of data
Potential for subversion
Mistaken identification
Uncontrolled access 22<br>
Examples:
Smart appliances, such as refrigerators and dishwashers
Smart home, such as thermostats and alarm systems
Smart health, such as fitness monitors and insulin pumps
Smart transportation, such as driverless cars
Smart entertainment, such as video recorders
Potential downsides:
Loss of privacy
Loss of control of data
Potential for subversion
Mistaken identification
Uncontrolled access 22<br>
23
Smartphones Smartphones are the control hub of the IoT
In 2013, Kaspersky Labs identified 143,211 distinct new forms of malware against mobile devices
98% targeted Android devices, far in excess of its market share
Android, unlike its competitors, does not limit the software users are allowed to install and is thus an easier target
Apple, in contrast, only allows apps from its app store to be installed on its smartphones
All apps go through an approval process, which includes some security review
Once approved, apps are signed, using a certificate approach similar to that described in Chapter 2 23<br>
In 2013, Kaspersky Labs identified 143,211 distinct new forms of malware against mobile devices
98% targeted Android devices, far in excess of its market share
Android, unlike its competitors, does not limit the software users are allowed to install and is thus an easier target
Apple, in contrast, only allows apps from its app store to be installed on its smartphones
All apps go through an approval process, which includes some security review
Once approved, apps are signed, using a certificate approach similar to that described in Chapter 2 23<br>
24
Economics Cybersecurity planning includes deciding how to allocate scarce resources for investing in security controls
Making a business case:
A description of the problem or need to be addressed
A list of possible solutions
A list of constraints on solving the problem
A list of underlying assumptions
An analysis of the risks, costs, and benefits of each alternative
A summary of why the proposed investment is a good idea 24<br>
Making a business case:
A description of the problem or need to be addressed
A list of possible solutions
A list of constraints on solving the problem
A list of underlying assumptions
An analysis of the risks, costs, and benefits of each alternative
A summary of why the proposed investment is a good idea 24<br>
25
Influences on Cybersecurity Investment 25<br>
26
Quantifying Security Cybersecurity threats are impossible to accurately quantify and estimate
How do you predict the likelihood that a hacker will attack a network, and how do you know the precise value of the assets the hacker will compromise?
While many industrial surveys collect cybersecurity incident data, they are inconsistent on key issues:
No standards for defining or categorizing security incidents
Disagreements about sources of attack
Selection bias among respondents
Useful data for decision making, such as rates and severity of attacks, cost of damage and recovery, and cost of security measures, are not yet known with any accuracy 26<br>
How do you predict the likelihood that a hacker will attack a network, and how do you know the precise value of the assets the hacker will compromise?
While many industrial surveys collect cybersecurity incident data, they are inconsistent on key issues:
No standards for defining or categorizing security incidents
Disagreements about sources of attack
Selection bias among respondents
Useful data for decision making, such as rates and severity of attacks, cost of damage and recovery, and cost of security measures, are not yet known with any accuracy 26<br>
27
Electronic Voting Confidentiality
We want to be able to cast a ballot without revealing our votes to others.
Integrity
We want votes to represent our actual choices and not be changed between the time we mark the ballot and the time our vote is counted. We also want every counted ballot to reflect one single vote of an authorized person. That is, we want to be able to ensure that our votes are authentic and that the reported totals accurately reflect the votes cast.
Availability
Usually, votes are cast during an approved pre-election period or on a designated election day, so we must be able to vote when voting is allowed. If we miss the chance to vote or if voting is suspended during the designated period, we lose the opportunity to cast a vote in the given election. 27<br>
We want to be able to cast a ballot without revealing our votes to others.
Integrity
We want votes to represent our actual choices and not be changed between the time we mark the ballot and the time our vote is counted. We also want every counted ballot to reflect one single vote of an authorized person. That is, we want to be able to ensure that our votes are authentic and that the reported totals accurately reflect the votes cast.
Availability
Usually, votes are cast during an approved pre-election period or on a designated election day, so we must be able to vote when voting is allowed. If we miss the chance to vote or if voting is suspended during the designated period, we lose the opportunity to cast a vote in the given election. 27<br>
28
What Is a Fair Election? Each voter’s choices must be kept secret.
Each voter may vote only once and only for allowed offices.
The voting system must be tamperproof, and the election officials must be prevented from allowing it to be tampered with.
All votes must be reported accurately.
The voting system must be available for use throughout the election period.
An audit trail must be kept to detect irregularities in voting but without disclosing how any individual voted. 28<br>
Each voter may vote only once and only for allowed offices.
The voting system must be tamperproof, and the election officials must be prevented from allowing it to be tampered with.
All votes must be reported accurately.
The voting system must be available for use throughout the election period.
An audit trail must be kept to detect irregularities in voting but without disclosing how any individual voted. 28<br>
29
Cyber Warfare Open questions:
When is an attack on cyber infrastructure considered an act of warfare?
Is cyberspace different enough to be considered a separate domain for war, or is it much like any other domain (e.g., land, sea, or air)?
What are the different ways of thinking about cyber war offense and defense?
What are the benefits and risks of strategic cyber warfare and tactical cyber warfare? 29<br>
When is an attack on cyber infrastructure considered an act of warfare?
Is cyberspace different enough to be considered a separate domain for war, or is it much like any other domain (e.g., land, sea, or air)?
What are the different ways of thinking about cyber war offense and defense?
What are the benefits and risks of strategic cyber warfare and tactical cyber warfare? 29<br>
30
Possible Examples of Cyber Warfare Estonia
Beginning in April 2007, the websites of a variety of Estonian government departments were shut down by multiple DDoS attacks immediately after a political altercation with Russia.
Iran
The Stuxnet worm attacked a particular model of computer used for many production control systems, and all the infections could be traced back to domains within Iran linked to industrial processing.
Israel and Syria
Missiles fired in 2007 by Israeli planes did not show up on Syrian radar screens because software had replaced live images with fake, benign ones.
Canada
In January 2011, the Canadian government revealed that several of its national departments had been the victims of a cyber attack traced back to servers in China.
Russia
According to the New York Times, Russian hackers infiltrated the computers of various national governments, NATO, and the Ukraine. 30<br>
Beginning in April 2007, the websites of a variety of Estonian government departments were shut down by multiple DDoS attacks immediately after a political altercation with Russia.
Iran
The Stuxnet worm attacked a particular model of computer used for many production control systems, and all the infections could be traced back to domains within Iran linked to industrial processing.
Israel and Syria
Missiles fired in 2007 by Israeli planes did not show up on Syrian radar screens because software had replaced live images with fake, benign ones.
Canada
In January 2011, the Canadian government revealed that several of its national departments had been the victims of a cyber attack traced back to servers in China.
Russia
According to the New York Times, Russian hackers infiltrated the computers of various national governments, NATO, and the Ukraine. 30<br>
31
Summary Vulnerabilities are weaknesses in a system; threats exploit those weaknesses; controls protect those weaknesses from exploitation
Confidentiality, integrity, and availability are the three basic security primitives
Different attackers pose different kinds of threats based on their capabilities and motivations
Different controls address different threats; controls come in many flavors and can exist at various points in the system
The IoT has resulted in a flood of new devices connecting our private and personal lives to the Internet but is far from mature from a security and privacy perspective
Cybersecurity investment decision making remains challenged by our inability to accurately measure risk and vulnerability
After over a decade of research and practice, electronic voting remains an unsolved research problem
Cyber warfare continues to lack clear definition and presents critical challenges, including attribution 31<br>
Confidentiality, integrity, and availability are the three basic security primitives
Different attackers pose different kinds of threats based on their capabilities and motivations
Different controls address different threats; controls come in many flavors and can exist at various points in the system
The IoT has resulted in a flood of new devices connecting our private and personal lives to the Internet but is far from mature from a security and privacy perspective
Cybersecurity investment decision making remains challenged by our inability to accurately measure risk and vulnerability
After over a decade of research and practice, electronic voting remains an unsolved research problem
Cyber warfare continues to lack clear definition and presents critical challenges, including attribution 31<br>
32
Todays Lab 1. Linux & Pen Testing Environment Basics
1.1 Finding your way around Kali
1.2 Linux Basic & Linux Services
1.2.1 Linux basic commands
1.2.2 Text viewers and editors for Linux Newbies
1.2.3 SSHD
1.2.4 Apache
1.3 Netcat
1.3.1 Connecting to a TCP/UDP port with Netcat
1.3.2 Listening on a TCP/UDP port with Netcat
1.3.3 Transferring files with Netcat
1.3.4 Remote Administration with Netcat – Bind Shell
1.4 Wireshark for Sniffing Packets
1.4.1 Wireshark & Packet Sniffing Background
1.4.2 Wireshark Step by Step
1.5 Cross-site scripting
1.5.1 A basic example
1.5.2 Stored XSS
1.5.3 Reflected XSS
1.5.4 Preventing XSS Attacks
1.6 Creating a Keylogger to Snoop (on your home PC)<br>
1.1 Finding your way around Kali
1.2 Linux Basic & Linux Services
1.2.1 Linux basic commands
1.2.2 Text viewers and editors for Linux Newbies
1.2.3 SSHD
1.2.4 Apache
1.3 Netcat
1.3.1 Connecting to a TCP/UDP port with Netcat
1.3.2 Listening on a TCP/UDP port with Netcat
1.3.3 Transferring files with Netcat
1.3.4 Remote Administration with Netcat – Bind Shell
1.4 Wireshark for Sniffing Packets
1.4.1 Wireshark & Packet Sniffing Background
1.4.2 Wireshark Step by Step
1.5 Cross-site scripting
1.5.1 A basic example
1.5.2 Stored XSS
1.5.3 Reflected XSS
1.5.4 Preventing XSS Attacks
1.6 Creating a Keylogger to Snoop (on your home PC)<br>