Monday, January 26, 2015

Shoulder surfing

Shoulder surfing is using direct observation techniques, such as looking over someone's shoulder, to get information. Having a strong memory will be useful if you want to try this out !

Shoulder surfing is using direct observation techniques, such as looking over someone's shoulder, to get information. Shoulder surfing is an effective way to get information in crowded places because it's relatively easy to stand next to someone and watch as they fill out a form, enter a PIN number at an ATM machine, or use a calling card at a public pay phone. Shoulder surfing can also be done long distance with the aid of binoculars or other vision-enhancing devices. To prevent shoulder surfing, experts recommend that you shield paperwork or your keypad from view by using your body or cupping your hand. So from now on cover your keyboard while typing your password !


Cryptography.

The art of protecting information by transforming it into an unreadable format, called cipher text. Only those who possess a secret key can decipher the message into plain text. Encrypted messages can sometimes be broken by cryptanalysis, also called codebreaking, although modern cryptography techniques are virtually unbreakable.
As the Internet and other forms of electronic communication become more prevalent, electronic security is becoming increasingly important. Cryptography is used to protect e-mail messages, credit card information, and corporate data. One of the most popular cryptography systems used on the Internet is Pretty Good Privacy because it's effective and free.
Cryptography systems can be broadly classified into symmetric-key systems that use a single key that both the sender and recipient have, and public-key systems that use two keys, a public key known to everyone and a private key that only the recipient of messages uses.




Reference: http://www.webopedia.com/TERM/C/cryptography.html

Ethical hacker definition.

An ethical hacker is a computer and networking expert who systematically attempts to penetrate a computer system or network on behalf of its owners for the purpose of finding security vulnerabilities that a malicious hacker could potentially exploit.
* Ethical hackers use the same methods and techniques to test and bypass a system's defenses as their less-principled counterparts, but rather than taking advantage of any vulnerabilities found, they document them and provide actionable advice on how to fix them so the organization can improve its overall security.
The purpose of ethical hacking is to evaluate the security of a network or system's infrastructure. It entails finding and attempting to exploit any vulnerabilities to determine whether unauthorized access or other malicious activities are possible. Vulnerabilities tend to be found in poor or improper system configuration, known and unknown hardware or software flaws, and operational weaknesses in process or technical countermeasures.

Reference: http://searchsecurity.techtarget.com/definition/ethical-hacker

Port Scanner.

A port is a place where information goes into and out of a computer, port scanning identifies open doors to a computer. Port scanning has legitimate uses in managing networks, but port scanning also can be malicious in nature if someone is looking for a weakened access point to break into your computer.
Types of port scans:
  • vanilla: the scanner attempts to connect to all 65,535 ports
  • strobe: a more focused scan looking only for known services to exploit
  • fragmented packets: the scanner sends packet fragments that get through simple packet filters in a firewall
  • UDP: the scanner looks for open UDP ports
  • sweep: the scanner connects to the same port on more than one machine
  • FTP bounce: the scanner goes through an FTP server in order to disguise the source of the scan
  • stealth scan: the scanner blocks the scanned computer from recording the port scan activities.
Port scanning in and of itself is not a crime. There is no way to stop someone from port scanning your computer while you are on the Internet because accessing an Internet server opens a port, which opens a door to your computer. There are, however, software products that can stop a port scanner from doing any damage to your system.

Reference: http://www.webopedia.com/TERM/P/port_scanning.html

Common Types of Network Attacks

Common Types of Network Attacks: 

Without security measures and controls in place, your data might be subjected to an attack. Some attacks are passive, meaning information is monitored; others are active, meaning the information is altered with intent to corrupt or destroy the data or the network itself. Your networks and data are vulnerable to any of the following types of attacks if you do not have a security plan in place.
1. Identity Spoofing (IP Address Spoofing)
Most networks and operating systems use the IP address of a computer to identify a valid entity. In certain cases, it is possible for an IP address to be falsely assumed— identity spoofing. An attacker might also use special programs to construct IP packets that appear to originate from valid addresses inside the corporate intranet.
After gaining access to the network with a valid IP address, the attacker can modify, reroute, or delete your data. The attacker can also conduct other types of attacks, as described in the following sections.
2. Denial-of-Service Attack
The denial-of-service attack prevents normal use of your computer or network by valid users.
After gaining access to your network, the attacker can do any of the following:
  • Randomize the attention of your internal Information Systems staff so that they do not see the intrusion immediately, which allows the attacker to make more attacks during the diversion.
  • Send invalid data to applications or network services, which causes abnormal termination or behavior of the applications or services.
  • Flood a computer or the entire network with traffic until a shutdown occurs because of the overload.
  • Block traffic, which results in a loss of access to network resources by authorized users.

3. Sniffer Attack
A sniffer is an application or device that can read, monitor, and capture network data exchanges and read network packets. If the packets are not encrypted, a sniffer provides a full view of the data inside the packet. Even encapsulated (tunneled) packets can be broken open and read unless they are encrypted and the attacker does not have access to the key.
Using a sniffer, an attacker can do any of the following:
  • Analyze your network and gain information to eventually cause your network to crash or to become corrupted.
  • Read your communications.
4. Password-Based Attacks
A common denominator of most operating system and network security plans is password-based access control. This means your access rights to a computer and network resources are determined by who you are, that is, your user name and your password. 
Older applications do not always protect identity information as it is passed through the network for validation. This might allow an eavesdropper to gain access to the network by posing as a valid user. 
When an attacker finds a valid user account, the attacker has the same rights as the real user. Therefore, if the user has administrator-level rights, the attacker also can create accounts for subsequent access at a later time.
After gaining access to your network with a valid account, an attacker can do any of the following:
  • Obtain lists of valid user and computer names and network information. 
  • Modify server and network configurations, including access controls and routing tables.
  • Modify, reroute, or delete your data.
Reference: https://technet.microsoft.com/en-us/library/cc959354.aspx#mainSection

Embedded Operating Systems:

An embedded system is a computer that is part of a different kind of machine. Examples include computers in cars, traffic lights, digital televisions, ATMs, airplane controls, point of sale (POS) terminals, digital cameras, GPS navigation systems, elevators, digital media receivers and smart meters, among many other possibilities. 

An embedded operating system is typically quite limited in terms of function – depending on the device in question, the system may only run a single application.  However, that single application is crucial to the device’s operation, so an embedded OS must be reliable and able to run with constraints on memory, size and processing power.


Reference:  http://whatis.techtarget.com/definition/embedded-operating-system

Thursday, January 8, 2015

Top 8 Vulnerable Cyber Security Risks in the today’s era of Digitalization

by Chandana on October 3, 2014 in IT Security Management

top8 vulnerable cyber security

The past decade saw a tremendous increase in internet usage across the world and more and more businesses have an online presence. This impressive increase in both residential and business users means that the present day digital world is far more complex, there is more money invested in large online corporations and consequently, the security risks are more varied and sophisticated. When it comes to the criminal cyber world, the numbers are showing a steady increase in attacks, breaches and successful hacks. Many experts suggest that the eternal arms race between the system security experts versus the ever changing types of cyber attacks will continue and it will involve many professionals during the next years. IT departments and security professionals will continue to be at the top of the fight against cyber attacks and their role will be even more important in today’s era of digitalization.
Here is a list discussing the major security risks that must be taken into consideration when designing a successful and safe computer system:

 1. Social engineering

Social engineering is considered the prime risk because of the newly popular and diverse social media websites. With the advent of Facebook, twitter, Linkedin and numerous other platforms, the hackers have almost endless attack routes to choose from. Social networks connect people, but through a string of similar friends and acquaintances, plus a very convincing profile and an unexpected friend request, they can become the best breeding ground for future hackers. These budding social hackers can grow uncontrollably and with the help of a poor security system, they can bring down even large businesses.

2. Cloud computing services

The new tech trend in computer systems is cloud computing. More companies than ever resort to this efficient computing system and the amount of information hosted on these cloud systems is staggering. Obviously, these systems are some of the more juicier targets for modern day hackers, as even a small breach of security can prove disastrous. To avoid any problems, businesses using this system must constantly discuss and demand the best security systems from their respective cloud service providers.

3. Internal risk factors

Many security experts and professionals know that some of the most dangerous cyber attacks come from the inside. These attacks have a devastating effect, mainly because a privileged user knows which data to use or destroy. Recent studies performed by CERT Insider Threat Center of the Carnegie University Software Engineering Institute and supported by the United States Secret Service have shown that inside malicious users are detected only after 32 months. The most vulnerable areas are the financial institutions, like banks and stock exchanges. Unfortunately, the only way to protect a company from this threat is a careful assessment of their own workforce, which is in itself a notoriously difficult task.

4. HTML security


The recent implementation of the new HTML 5 protocol means that there is a high risk of security breaches in the system. The new protocol allows the connection of various technologies that might not work so safely together, thus allowing hackers to do their dirty work unnoticed. Even though HTML 5 has improved over the last two years, it is still a new protocol, and many developers still make mistakes, and some experts an increase in cyber attacks.

5. APTs

Advanced Persistent Threats (abbreviated as APTs) are directed attacks against businesses or organizations that try to steal and leak information quietly and unnoticed. Typically, with the help of social engineering, they slowly breach the defensive wall of an organization and gain access to the internal network. Good APT attacks are aimed at servers and can be very difficult to detect, mainly because they act slowly and during low work times. Generally, APTs can be detected when an abnormal traffic change is observed in the system, but the digits are hardly noticeable. The attacks are focused on common, rich information files, like Microsoft Word or PDF files. Similarly, other vector might be vulnerable, like embedded systems and mobile devices which are increasingly present in the work environment. This is why even the smaller and the least used digital device must be carefully secured (like tablets, smartphones and mobile hard disk drives).

6. BYODs

BYOD – bring your own device – the all present modern day phenomenon is becoming increasingly difficult to control at the workplace. What it refers to is simple: the work environment has a huge number of new devices that can be connected to the internet. The office is filled with Android devices, iPhones, iPods and a variety of tablets and other gadgets that can act as gateways to savvy hackers. The users of these devices generally do not fully grasp the risks that they are exposed to and also expose the office environment to. These new devices have a variety of apps installed on them, some with poor security settings, that can bring in malicious add on software unnoticed. For instance, every modern smartphone has an incorporated high definition camera, a voice recorder, a sensitive microphone and other unexpected recording applications. The proficient hacker will see these gimmicks as ideal windows in the security system.

7. Malware


Malware has long been a powerful tool used by many expert hackers. But the new danger comes from the precision targeted malware, a special evolved type of malware attack. Their technique is greatly improved, the targets are better determined and they are designed to attack specific computer configurations and components. Vulnerable systems are social media platforms, including their respective accounts and groups, mobile devices and remote servers.

8. Botnets

Botnets, like other cyber weapons, are getting more specialized, targeted and increasingly more dangerous. The cyber criminals know that these tools are their best assets and will continue to invest a lot of time, technology and funds into them. They become more widely available across diverse platforms and are easily distributed in almost every system. Takedowns launched by larger corporations, such as Microsoft or Adobe, work only temporarily, and it’s only a matter of time before the cyber criminals improve their spam and malware tools. Simply put, they are learning from each step and constantly hone their hacking skills.

To know more about IT Security Certification training please visit Simplilearn.