Final Project: You will assemble your final report as follows:
Running head: INFORMATION SECURITY AND DR APPROACH 1
INFORMATION SECURITY AND DR APPROACH 5
Information Security and DR Approach
Student Name : sunil patel
Institution Affiliation: Iglobal University
MIT 681 : Assignment 5
Recent trends exhibited by data and analytic firms has warrant the adoption of security features to protect their data and set mitigation measures in case of an attack. For instance, such organizations have reduced their investment in support staff, data centers, software, as well as hardware. Besides, cyber-attacks have taken a different path by becoming persistent and using sophisticated technology. The conventional security measures that organizations have been using has therefore become obsolete thus necessitating an overhaul of the cybersecurity strategies (Cardenas et al., 2009). The data analytics firms should therefore adopt the mobile as well as cloud storage services as a model shift in terms of information security from the conventional parameter safeguarding to the monitoring and detection of intrusion events within the network of the corporations. Additionally, the increasing corporation between insiders and outside intruders in breaching the set security measures have further demonstrated that traditional measures to secure information can no longer be relied upon. A data analytic firm is required to set up effective information security measures as well as mitigation policies to recover from a malicious intrusion.
Information security concerns warrant the adoption of the big data analytics which is capable of operating in a real time context. As the data security firms respond to the new set of challenges, there is a new security analytics remedies that has come up in the recent years with the capability of collecting, storing, and analyzing a wide spectrum of security information across the entire organization in real time (Babiceanu & Seker, 2016). Viable approach to information security should therefore incorporate the intelligence from external threat and analyze their data using several correlation algorithms to root out cases of anomalies which will enable them to detect malicious activities. Such interventions utilize the real time operational mode and produce minimal counts of security notifications arranged according to their security using the risk paradigm. As a result, the new tech will enable the data analytics firm to quickly detect and mitigate cases of cyber-attacks.
The use of big data to ensure the security of information of a given organization enables the combination of historical patterns with real time analysis to develop new events with reference to others that have taken place in the past (Babiceanu & Seker, 2016). The approach also combines security input from external sources that have the most updated data concerning current vulnerabilities. This approach thus aids in identifying advanced attacks that is taking place on the network in real time basis. Mitigation and recovery measures provide by bug data analytics encompasses outamic workflows that target the identified threats for instance by disruption of malware intrusion.
Additionally, big data analysis is the best way of detecting advanced persistent threats abbreviated as APT. The ATP is an intrusion that targets either a physical system or an invaluable asset of a firm. Whereas malwares such as Trojans, viruses, and worms operates in high and medium mode, advanced persistent threats use the “low and slow” operandi. The slow mode enables the attack to take a considerable time while the low mode trait enables the attack to embrace a low profile within a network. In order to prevent detection, the advanced persistent threat attackers make use of user credentials falsely acquired as well as zero day activities (Babiceanu & Seker, 2016). As a result, an ATP attack can last for a considerable amount of time without the affected firm becoming aware of a possible case of intrusion. The only challenge in detecting such type of an attack is the large amounts of data that should be sifted through in the event such as anomaly occurs. The information is usually collected from several sources of information that should undergo auditing. Because of the large data volume, the traditional security measures are rendered ineffective. Therefore, a new technique should be adopted. Several organizations obtain information related to the activities of the users as well as the host in a given organization’s system as accessed via web proxies, virtual private network servers, intrusion detection systems, domain controllers, and firewalls. While the firm uses this data to conduct forensic analysis, the same data relay essential information about the patterns of the users a crucial promise for identifying crafty attacks.
Besides, the organization should use large scale distributed technique to identify incidences of advanced persistent threats. Despite the fact that advanced persistent threats do not happen on a large scale, the firm should adopt large scale strategies as well as ‘close to target’ algorithms to monitor potential attacks so ensure the efficacy of such measures (DeYoung et al., 2018). The firm should therefore form an attack pyramid for the APT intrusion detection with the attack aim in perspective for instance sensitive information, data servers, and employees in managerial positions as a representative of the attack environment. The paradigm classified the occurrences registered in an organization relevant to the security of the firm using specific correlation procedures which changes according to the nature of the attack. The paradigm use detection rules for instance policy related, anomaly or signature related by utilizing several algorithms to identify malicious intrusions in a given setting. The framework used by the attack pyramid is the MapReduce model.
It is evident that the piece of information used as pointers to potential intrusion to a firm’s network system is ever changing thus complex to ditect.an APT mitigation approach uses the MapReduce model to ensure it effectively monitors unstructured information constructed by arbitrary formats collected by a variety of sensors such as intrusion detection system, firewall, DNS, and Netflow over a given duration (DeYoung et al., 2018). Besides, the MapReduce paradigm utilizes complicated detection patterns as compared to the conventional SQL detection system. The latter approach is also flexible with the ability of incorporating any applicable detection algorithm. Analysis of large amounts of data collected from several attacks is possible when the large scale distributed networks are used to root out potential threats in a setting that is near to a particular target similar to advanced persistent attacks.
Conclusion
As presented in the above text, the firm should adopt stringent measures to curb the ever evolving forms of attacks that target its network system. Some of the proposed mitigation measures involve the adoption of big data analytics and large scale distributed technique to identify incidences of advanced persistent threats. This new approach is necessitated by the fact that the conventional security measures that organizations have been using has have become obsolete and ineffective over time. The options are potential solutions to information security concerns which incorporates intelligence from external threat and analyze their data using several correlation algorithms to root out cases of anomalies which will enable them to detect malicious activities. Besides, the proposed solutions have the capability of offering real time solutions and change to suit the needs of the user.
References
Babiceanu, R. F., & Seker, R. (2016). Big Data and virtualization for manufacturing cyber-physical systems: A survey of the current status and future outlook. Computers in Industry, 81, 128-137.
Cardenas, A., Amin, S., Sinopoli, B., Giani, A., Perrig, A., & Sastry, S. (2009, July). Challenges for securing cyber physical systems. In Workshop on future directions in cyber-physical systems security (Vol. 5, No. 1).
DeYoung, M. E., Kobezak, P., Raymond, D., Marchany, R., & Tront, J. (2018, January). Privacy preserving network security data analytics: Architectures and system design. In 51st Hawaii International Conference on System Sciences, 2018. University of Hawaii at Manoa.