Group PowerPoint Residency - Day 2 Residency Assignment

sri169025
Spring2020_Week13Residency_Day2_Group3_sample11.ppt

002835518 - Chalamalasetty, Srinivas

002826551 - Ganji, Umakumar

002849521 - Karra, Ravi Sastry

002838332 - Kukkala, Indrakaran Reddy

002826761 - Malineni, Srinivas

002837463 - Namburu, Krishna Chaitanya Chowdary

University of the Cumberlands

THREAT MODELING FOR LIBRARY RESOURCE BY GROUP 3

LIBRARIAN CREDENTIALS:

  • Librarian credentials should have the strong passwords polices
  • least minimum length 8 characters and password should contain numerical and special characters, Uppercase and Lowercase letters.
  • Password retention polices
  • Use the password retention for every few months
  • Librarian Username should be more complex logical private identity
  • Last four digits of SSN or DOB or employee Id number
  • Librarian must have more privileges than library user
  • Add or remove inventory and access to write complex quires to filter or search the books
  • Librarian permission create new library user
  • Librarian must have Ability to audit system events
  • who logged in website and what all activities user performed on the library site

USER PERSONAL INFORMATION:

  • User personal information include
  • Name, address, email address, phone number, race, nationality, ethnicity, origin, color, age, sex, identifying number, passcode, fingerprints, and educational details.
  • User data can help to build better products
  • Product design, implementing iterative solutions and resource allocation
  • User personal information Privacy
  • The United States' privacy law
  • User personal data protection
  • Implement strong password policies
  • Password retention
  • Encrypted the data transportation policies
  • Multiple layer application infrastructure to protect from DDoS attacks
  • Implement the web application firewall (WAF)

LIBRARY WEBSITE SYSTEM

  • Scenario
  • Graphical User interface that allows user to login
  • Graphical User interface that allows user to create account
  • Graphical User interface that allows user to access the books and other material from the library database system
  • Threat Model
  • Website outsourced tools and security firewalls are not completely reliable for website development.
  • Encrypt and decrypt the data sent ad received from and to the user.
  • Mitigations
  • Identification
  • Authentication

LIBRARY WEBSITE SYSTEM

LIBRARY DATABASE SYSTEM

  • Scenario
  • Database tool and architecture that allows user to CRUD information
  • Database tool and architecture that allows user to that links between the Graphical User Interface of the website and the database of the library resources
  • Database tool and architecture that allows user to post and administer on a reliable network system
  • Threat Model
  • Modify data over public network like WiFi.
  • Load on the database system for multiple threads of requests.
  • Mitigation
  • Identification and authentication of user.
  • Use approved database tools and reviewed architecture for uninterrupted data flow.

WEB SERVER ATTACKS & COUNTERMEASURES

  • DOS attack
  • Website Defacement
  • Misconfiguration attacks
  • Phishing Attack
  • Vulnerability Scanning

DB SERVER ATTACKS & COUNTERMEASURES

  • Excessive privileges
  • Database injection attacks
  • Storage media exposure
  • Exploitation ofdatabases vulnerable

DFD DIAGRAM FOR WEB/DB SERVER

USER DB READ ACCESS

LIBRARIAN/ADMIN DB READ/WRITE ACCESS

THANK YOU